Supplier security questionnaire
Northwind Traders has 4 controls not in place.
Judged from Microsoft 365 data collected ; 13 controls need evidence Microsoft 365 can't show.
What changed
Pick a point in time to see which controls passed then and not now, or the other way round: useful before a renewal.
Gaps to close
13 controls-
Anyone, including anonymous links. For example SharePoint and OneDrive: Anyone links are allowed.
Fix: Change SharePoint external sharing to "New and existing guests". See the rows →
-
4 of 36 computers not encrypted. For example DESK-WRIGHT18 (leo.wright@northwindtraders.example): Windows disk isn't encrypted.
Fix: Turn on BitLocker. See the rows →
-
5 of 36 Windows computers past end of support. For example LAPTOP-HUGHES (robert.hughes@northwindtraders.example): Windows 10 stopped getting security updates on 14 Oct 2025. Extended Security Updates or LTSC can cover it; otherwise upgrade.
Fix: Upgrade computers on Windows 10 or an old Windows 11 release to the current Windows 11 release. See the rows →
-
Users can consent to any app. Any user can grant any app access to their mail and files.
Fix: Set user consent to "Allow user consent for apps from verified publishers, for selected permissions" or turn it off and use the admin consent workflow. See the rows →
-
2 admins without a phishing-resistant method. For example ann.patel@northwindtraders.example: Global Administrator; signs in with Authenticator app.
Fix: Have each listed admin register a passkey. See the rows →
-
Partly No weak MFA methods
3 people can only use a text or call as a second factor. For example arthur.evans@northwindtraders.example: Second factor is only Mobile phone (SMS or call).
Fix: Ask these people to set up the Microsoft Authenticator app. See the rows →
-
Partly Separate admin accounts
1 of 2 admin accounts also has a licence or mailbox, so it looks like an everyday account: ann.patel@northwindtraders.example.
Fix: Give each administrator a separate, unlicensed admin account with no mailbox, used only for administration, and take the admin roles off the account they use every day. See the rows →
-
1 guest with admin roles. For example g#EXT#@northwindtraders.example: Guest holding Exchange Administrator.
Fix: Remove admin roles from guest accounts. See the rows →
-
4 accounts inactive for 90+ days or never used. For example hannah.robinson@northwindtraders.example: Licensed member, last signed in 7 Apr 2026.
Fix: Disable accounts that haven't signed in for 90 days, or were created over 30 days ago and never used. See the rows →
-
Data in Microsoft 365 is encrypted at rest by Microsoft (BitLocker and per-file service encryption) and in transit using TLS. Not every company computer is encrypted: 4 of 36 computers not encrypted.
-
Partly SPF, DKIM and DMARC
1 domain with SPF problems. For example parked.example: Doesn't receive mail but has no "v=spf1 -all" record to stop spoofing.
Fix: Publish one SPF record per domain ending in -all. See the rows →
-
4 external forwards. For example ann.patel@northwindtraders.example: Mailbox forwarding to ann.patel@homemail.example (keeps a copy).
Fix: Remove forwarding to outside addresses unless the client has a documented business reason. See the rows →
-
1 of 37 joined computers not in Intune. For example DESK-RECEPTION: Hybrid joined, not managed by Intune.
Fix: Enrol Entra-joined and hybrid-joined computers in Intune. See the rows →
Governance
Your evidenceWritten policies and recognised certifications.
Documented information security policies exist and are reviewed.
Information security policies covering [acceptable use, access control, passwords, data protection and incident response] are approved by [role], reviewed every [12 months] and acknowledged by staff.
What Microsoft 365 can't show: Not something Microsoft 365 shows; answer from the client's own records.
Write this answer for Northwind Traders
Cyber Essentials, CE Plus, ISO 27001 or similar, with dates.
The organisation holds [Cyber Essentials or Cyber Essentials Plus or ISO 27001] certification, number [certificate number], valid until [date].
What Microsoft 365 can't show: Not something Microsoft 365 shows; answer from the client's own records.
Write this answer for Northwind Traders
Access control
PartlyUnique accounts with MFA, phishing-resistant for administrators, separate admin accounts, a password policy, and access removed when people leave.
Multi-factor authentication is required for all users.
- Enforced by Conditional Access ("Require MFA for all users") for everyone except 1 named exclusion: breakglass@northwindtraders.example (break-glass).
- But: 14 users without MFA.
- Users with an MFA method registered
- 62.2% of 37
- Accounts covered by an enforced MFA policy
- 36 of 36
Multi-factor authentication (MFA) is enforced for Microsoft 365 email (including Outlook on the web and mobile) and cloud applications, through Microsoft Entra ID. Enforced by Conditional Access ("Require MFA for all users") for everyone except 1 named exclusion: breakglass@northwindtraders.example (break-glass).
What Microsoft 365 can't show: Judged for Microsoft 365 sign-ins only. Add VPNs, remote desktop and other systems.
Change this answer
Every privileged account uses MFA.
- 2 of 3 active admin accounts are required to use MFA by "Require MFA for all users"; the exception is 1 break-glass account: breakglass@northwindtraders.example (excluded from "Require MFA for all users").
- But: 1 admin without MFA, and 1 whose registration isn't known.
- Accounts holding privileged roles
- 4
- Admins with no MFA policy
- 1
- Admins with no MFA method registered
- 2
Multi-factor authentication is enforced for the administrator accounts of Microsoft 365 and Microsoft Entra ID. 2 of 3 active admin accounts are required to use MFA by "Require MFA for all users"; the exception is 1 break-glass account: breakglass@northwindtraders.example (excluded from "Require MFA for all users").
What Microsoft 365 can't show: Judged for Microsoft 365 and Entra ID admin roles.
Change this answer
Administrators sign in with FIDO2 keys, passkeys or Windows Hello for Business, not codes.
- 2 admins without a phishing-resistant method.
- ann.patel@northwindtraders.example: Global Administrator; signs in with Authenticator app
- breakglass@northwindtraders.example: Global Administrator; signs in with no MFA method at all
Fix: Have each listed admin register a passkey (in Microsoft Authenticator or on a security key) or Windows Hello for Business, then require the Phishing-resistant MFA authentication strength for admin roles in Conditional Access. Codes and push approvals can be relayed by a fake sign-in page; these can't. See the rows →
Administrator accounts don't all use phishing-resistant sign-in methods yet. 2 admins without a phishing-resistant method.
What Microsoft 365 can't show: Judged from the sign-in methods admin accounts have registered.
Change this answer
Text-message and voice-call MFA are turned off or being retired.
- 3 people can only use a text or call as a second factor.
- arthur.evans@northwindtraders.example: Second factor is only Mobile phone (SMS or call)
- mia.hughes@northwindtraders.example: Second factor is only Mobile phone (SMS or call)
- zara.jackson@northwindtraders.example: Second factor is only Mobile phone (SMS or call)
Fix: Ask these people to set up the Microsoft Authenticator app (the registration campaign in the authentication methods policy prompts them at sign-in), then turn off text message and voice call sign-in, or keep them only as a backup. Texts and calls can be intercepted or moved to an attacker's SIM. See the rows →
Some users rely on a text message or phone call as their only second factor. 3 people can only use a text or call as a second factor.
What Microsoft 365 can't show: Judged from the authentication methods policy and what people have registered.
Change this answer
Administrative accounts are separate from standard user accounts.
- 1 of 2 admin accounts also has a licence or mailbox, so it looks like an everyday account: ann.patel@northwindtraders.example.
Fix: Give each administrator a separate, unlicensed admin account with no mailbox, used only for administration, and take the admin roles off the account they use every day. See the rows →
Most administrator accounts are separate from day-to-day accounts. There are exceptions. 1 of 2 admin accounts also has a licence or mailbox, so it looks like an everyday account: ann.patel@northwindtraders.example.
What Microsoft 365 can't show: Judged from Microsoft 365 admin role holders: an admin account with a licence or a mailbox looks like an everyday account.
Change this answer
Few named administrators, no guests or apps with admin roles, and the list is reviewed.
- 2 Global Administrators.
- Cloud-only tenant: no accounts are synced from on-premises AD.
- Accounts holding privileged roles
- 4
- Admins with no MFA policy
- 1
- Admins with no MFA method registered
- 2
- 1 guest with admin roles.
- g#EXT#@northwindtraders.example: Guest holding Exchange Administrator
- 1 app with privileged roles.
- Some app: App holding Exchange Administrator
Fix: Remove admin roles from guest accounts. If an external partner needs access, use GDAP or a member account in this tenant protected by MFA. See the rows →
Administrator role assignments in Microsoft 365 are tracked, with gaps. 4 accounts hold privileged admin roles, 2 of them Global Administrator (ann.patel@northwindtraders.example, breakglass@northwindtraders.example). 2 Global Administrators. 1 guest with admin roles. 1 app with privileged roles.
What Microsoft 365 can't show: Microsoft 365 shows who holds admin roles today; describe how the list is reviewed.
Change this answer
Passwords have a minimum length, common ones are banned and repeated failures lock the account.
- Microsoft Entra ID requires passwords of at least 8 characters, blocks commonly used and known compromised passwords (Microsoft's global banned password list) and locks out repeated failed sign-in attempts (smart lockout). These are Microsoft defaults for cloud accounts. Multi-factor authentication is enforced as well (see the MFA answer), so a guessed password alone can't be used to sign in.
Microsoft Entra ID requires passwords of at least 8 characters, blocks commonly used and known compromised passwords (Microsoft's global banned password list) and locks out repeated failed sign-in attempts (smart lockout). These are Microsoft defaults for cloud accounts. Multi-factor authentication is enforced as well (see the MFA answer), so a guessed password alone can't be used to sign in.
What Microsoft 365 can't show: Microsoft Entra ID's defaults (8 characters, a banned password list and smart lockout) aren't read from the tenant. Add other systems that take passwords.
Change this answer
Leavers' accounts are disabled promptly and inactive accounts removed.
- 4 accounts inactive for 90+ days or never used.
- hannah.robinson@northwindtraders.example: Licensed member, last signed in 7 Apr 2026
- sophie.smith@northwindtraders.example: Licensed member, last signed in 21 Jan 2026
- thomas.clarke@northwindtraders.example: Licensed member, last signed in 2 Jun 2026
- g#EXT#@northwindtraders.example: Guest, never signed in, created ?
- 1 disabled account still licensed.
- robert.hughes@northwindtraders.example: Disabled, holding 1 licence
Fix: Disable accounts that haven't signed in for 90 days, or were created over 30 days ago and never used (after checking with the client), then remove their licences. Inactive accounts are a common foothold for attackers. See the rows →
Some inactive accounts in Microsoft Entra ID have not been disabled. 4 accounts inactive for 90+ days or never used. 1 disabled account still licensed.
What Microsoft 365 can't show: Judged from sign-in activity in Microsoft Entra ID. Describe the leavers process in the answer.
Change this answer
Guests and external users are reviewed and pending invitations cleared.
- No stale guest invitations.
- Guests have limited access to directory objects (the default).
Guest and external user accounts are not reviewed regularly. 1 guest account: 1 guest inactive for 90+ days or never signed in (g#EXT#@northwindtraders.example).
What Microsoft 365 can't show: Judged from guest accounts and the external collaboration settings.
Change this answer
Data protection
FailWhere data lives, encryption at rest and in transit, and sharing under control.
The region the tenant's data is held in.
- Email, files and Teams data are held in Microsoft 365, in Microsoft's datacentres.
Email, files and Teams data are held in Microsoft 365, in Microsoft's datacentres.
What Microsoft 365 can't show: Microsoft 365 reports the tenant's data location; add any other systems.
Change this answer
Data is encrypted at rest and in transit.
- Data in Microsoft 365 is encrypted at rest by Microsoft (BitLocker and per-file service encryption) and in transit using TLS. Not every company computer is encrypted: 4 of 36 computers not encrypted.
Data in Microsoft 365 is encrypted at rest by Microsoft (BitLocker and per-file service encryption) and in transit using TLS. Not every company computer is encrypted: 4 of 36 computers not encrypted.
What Microsoft 365 can't show: Microsoft 365 encrypts stored data and connections; add other systems.
Change this answer
Data can't be shared with unauthorised people: sharing settings, anyone links and guest invitations.
- Anyone, including anonymous links.
- SharePoint and OneDrive: Anyone links are allowed
- 3 files and folders shared with anyone.
- Campaign video.mp4 (Marketing / Documents): Anyone can edit
- Brand assets (Marketing / Documents): Anyone can view, link never expires
- holiday.jpg (OneDrive of ann.patel@northwindtraders.example): Anyone can view
- Anyone, including guests, can invite guests.
- Guests can invite other guests
Fix: Change SharePoint external sharing to "New and existing guests" so every external person signs in. If the client relies on Anyone links, set them to expire and to view-only. See the rows →
Sharing with anonymous and external users is not restricted in SharePoint and OneDrive. Anyone, including anonymous links. 3 files and folders shared with anyone. Anyone, including guests, can invite guests.
What Microsoft 365 can't show: Judged from SharePoint and OneDrive sharing settings and links.
Change this answer
Laptops and other portable devices are encrypted.
- 4 of 36 computers not encrypted.
- DESK-WRIGHT18 (leo.wright@northwindtraders.example): Windows disk isn't encrypted
- LAPTOP-HUGHES (robert.hughes@northwindtraders.example): Windows disk isn't encrypted
- LAPTOP-SCOTT29 (olivia.scott@northwindtraders.example): Windows disk isn't encrypted
- LAPTOP-SMITH07 (olivia.smith@northwindtraders.example): Windows disk isn't encrypted
Fix: Turn on BitLocker (Windows) and FileVault (macOS) with an Intune disk encryption policy, with recovery keys escrowed to Entra ID, so a lost or stolen laptop doesn't expose the client's data. See the rows →
Company computers managed in Microsoft Intune are not all encrypted. 4 of 36 computers not encrypted.
What Microsoft 365 can't show: Judged for devices managed by Intune.
Change this answer
Email security
PartlyMail filtered, domains protected against spoofing, no forwarding outside.
Incoming email is filtered for phishing and malware.
- Incoming email for northwindtraders.example is delivered to Microsoft 365 and filtered by Exchange Online Protection (anti-spam, anti-phishing and anti-malware).
Incoming email is filtered for spam, phishing and malware. Incoming email for northwindtraders.example is delivered to Microsoft 365 and filtered by Exchange Online Protection (anti-spam, anti-phishing and anti-malware).
What Microsoft 365 can't show: Microsoft 365 shows which mail gateway the domains route through, not its settings.
Change this answer
Every email domain publishes SPF, signs with DKIM and has a DMARC policy.
- 1 domain with SPF problems.
- parked.example: Doesn't receive mail but has no "v=spf1 -all" record to stop spoofing
- 1 mail domain without DKIM.
- northwindtraders.example: Microsoft 365 DKIM isn't set up (selector2 CNAME missing)
- 2 domains without DMARC enforcement.
- northwindtraders.example: DMARC is monitor-only (p=none); spoofed mail is still delivered
- parked.example: Doesn't receive mail but has no DMARC p=reject record
Fix: Publish one SPF record per domain ending in -all (or ~all while testing), e.g. "v=spf1 include:spf.protection.outlook.com -all". Domains that never send mail should publish "v=spf1 -all". See the rows →
SPF, DKIM and DMARC are not fully configured for the organisation's email domains. 1 domain with SPF problems. 1 mail domain without DKIM. 2 domains without DMARC enforcement.
What Microsoft 365 can't show: Judged from public DNS and Exchange Online for the tenant's domains.
Change this answer
Automatic forwarding of email outside the organisation is blocked.
- The default outbound policy blocks automatic external forwarding.
- 4 external forwards.
- ann.patel@northwindtraders.example: Mailbox forwarding to ann.patel@homemail.example (keeps a copy)
- ann.patel@northwindtraders.example: Inbox rule "Copy to home" forwards to ann.patel.home@homemail.example
- grace.taylor@northwindtraders.example: Mailbox forwarding to grace.taylor@homemail.example (doesn't keep a copy)
- olivia.smith@northwindtraders.example: Inbox rule "Invoices to bookkeeper" forwards to bookkeeping@ledgerline.example
- 1 suspicious inbox rule.
- ann.patel@northwindtraders.example: ".": Moves to RSS Feeds mail mentioning invoice, payment; Rule name '.' looks deliberately blank
Fix: Remove forwarding to outside addresses unless the client has a documented business reason. Forwarding is the most common way attackers keep reading a mailbox after a password reset. See the rows →
Automatic forwarding to external addresses is restricted in Exchange Online, with exceptions. The default outbound policy blocks automatic external forwarding. But 4 external forwards found.
What Microsoft 365 can't show: Judged from the Exchange Online outbound spam policy, mailbox forwarding and inbox rules.
Change this answer
Devices
FailManaged to a baseline, supported, patched quickly and protected by anti-malware.
Devices are centrally managed and must meet a security baseline.
- Computers managed by Intune
- 36
- Of which encrypted
- 32
- Windows computers out of support
- 5
- Reaching end of support within 90 days
- 20
- Not compliant
- 6
- 1 of 37 joined computers not in Intune.
- DESK-RECEPTION: Hybrid joined, not managed by Intune
- 6 of 37 managed devices not compliant.
- DESK-ROBINSON12 (george.robinson@northwindtraders.example): Not compliant
- DESK-WRIGHT18 (leo.wright@northwindtraders.example): Not compliant
- LAPTOP-HUGHES (robert.hughes@northwindtraders.example): Not compliant
- LAPTOP-SCOTT25 (alfie.scott@northwindtraders.example): Not compliant
- LAPTOP-SCOTT29 (olivia.scott@northwindtraders.example): Not compliant
- and 1 more
Fix: Enrol Entra-joined and hybrid-joined computers in Intune (automatic enrolment under Devices > Enrollment > Windows) so compliance, encryption and updates can be enforced on them. See the rows →
Company devices are not all managed centrally. 1 of 37 joined computers not in Intune. 6 of 37 managed devices not compliant.
What Microsoft 365 can't show: Judged from Intune enrolment and compliance for devices joined to Entra ID.
Change this answer
Every operating system is still supported by its vendor.
- 5 of 36 Windows computers past end of support.
- LAPTOP-HUGHES (robert.hughes@northwindtraders.example): Windows 10 stopped getting security updates on 14 Oct 2025. Extended Security Updates or LTSC can cover it; otherwise upgrade.
- LAPTOP-MARTIN22 (maya.martin@northwindtraders.example): Windows 10 stopped getting security updates on 14 Oct 2025. Extended Security Updates or LTSC can cover it; otherwise upgrade.
- LAPTOP-PATEL13 (hannah.patel@northwindtraders.example): Windows 10 stopped getting security updates on 14 Oct 2025. Extended Security Updates or LTSC can cover it; otherwise upgrade.
- LAPTOP-ROBERTS31 (george.roberts@northwindtraders.example): Windows 10 stopped getting security updates on 14 Oct 2025. Extended Security Updates or LTSC can cover it; otherwise upgrade.
- LAPTOP-TAYLOR04 (grace.taylor@northwindtraders.example): Windows 10 stopped getting security updates on 14 Oct 2025. Extended Security Updates or LTSC can cover it; otherwise upgrade.
- and 20 more
Fix: Upgrade computers on Windows 10 or an old Windows 11 release to the current Windows 11 release (Intune: Windows feature updates policy). Replace hardware that can't run Windows 11, or buy Extended Security Updates as a stopgap. See the rows →
Managed Windows computers run versions of Windows that no longer receive security updates. 5 of 36 Windows computers past end of support.
What Microsoft 365 can't show: Judged for Windows computers known to Intune or Entra ID.
Change this answer
Security updates are applied within an agreed time, 14 days for critical ones.
- But: 3 devices haven't checked in for 30+ days.
Operating system updates install automatically through [Windows Update for Business, Intune update rings or the RMM tool]. Critical and high-risk updates, including router and firewall firmware, are installed within 14 days of release, and this is checked [weekly] by [IT provider].
What Microsoft 365 can't show: Intune shows when each device last checked in, not when updates were installed.
Write this answer for Northwind Traders
Anti-malware software is installed and kept up to date on all devices.
- But: 6 of 37 managed devices not compliant.
All desktops and laptops run [anti-malware product, for example Microsoft Defender Antivirus], which updates automatically, scans files when they're opened and blocks malicious websites. Tablets and phones only install apps from the official app stores.
What Microsoft 365 can't show: Office Sentry doesn't read Microsoft Defender or anti-malware settings.
Write this answer for Northwind Traders
Logging and monitoring
Not collectedSecurity events logged, suspicious activity watched, vulnerabilities looked for.
Security events are logged and kept.
- Mailbox auditing is on for the organisation.
Mailbox audit logging is enabled in Exchange Online, recording access to and actions on mailboxes. Mailbox auditing is on for the organisation.
What Microsoft 365 can't show: Judged from Exchange Online mailbox auditing and the unified audit log.
Change this answer
Suspicious sign-ins and users are detected and responded to.
- Not checked: no accounts are at risk in Entra ID Protection (Risky users need Entra ID P2).
- Not checked: no risky sign-ins succeeded (Sign-in risk needs Entra ID P2).
Risky users need Entra ID P2.
Sign-ins are monitored for suspicious activity by [tool or service], and alerts are reviewed by [team or provider] [within one working day].
What Microsoft 365 can't show: Judged from Entra ID Protection (needs Entra ID P2 for the full detections).
Write this answer for Northwind Traders
Vulnerability scans or penetration tests are carried out and findings fixed.
External vulnerability scans run [monthly] using [tool or provider]. [A penetration test was last carried out on (date) by (provider).]
What Microsoft 365 can't show: Not something Microsoft 365 shows; answer from the client's own records.
Write this answer for Northwind Traders
Incidents, backups and continuity
Your evidenceA plan for incidents (and telling the client), tested backups, and continuity plans.
An incident response plan exists and clients are told about incidents affecting their data.
A documented incident response plan sets out roles, contacts and the steps to contain and recover from a cyber incident, including notifying [the insurer and IT provider]. It was last reviewed on [date] and tested on [date].
What Microsoft 365 can't show: Not something Microsoft 365 shows; answer from the client's own records.
Write this answer for Northwind Traders
Data is backed up and restores are tested.
Microsoft 365 data (Exchange Online mail, OneDrive, SharePoint and Teams) is backed up [daily] by [backup product or provider] to storage separate from Microsoft 365. Backups are kept for [retention period], are [immutable or offline], and use credentials separate from the Microsoft 365 administrator accounts. Restores were last tested on [date].
What Microsoft 365 can't show: Not something Microsoft 365 shows; answer from the client's own records.
Write this answer for Northwind Traders
Business continuity and disaster recovery plans exist.
A business continuity and disaster recovery plan covers [key systems and services]. Recovery targets are [time to restore] to restore service and no more than [data loss window] of data loss. It was last tested on [date].
What Microsoft 365 can't show: Not something Microsoft 365 shows; answer from the client's own records.
Write this answer for Northwind Traders
Third parties, people and premises
FailApps and sub-processors under control, staff trained and vetted, premises secured, and a firewall with MFA on remote access.
Users can't consent to third-party apps on their own, and apps with risky permissions are known.
- Users can consent to any app.
- Any user can grant any app access to their mail and files
- 1 app with access to mail, files or the directory.
- Mail Sync Pro: Mail.Read (application permission; unverified publisher)
Fix: Set user consent to "Allow user consent for apps from verified publishers, for selected permissions" or turn it off and use the admin consent workflow. Consent phishing relies on this setting. See the rows →
Third-party application access to Microsoft 365 data is not controlled. Users can consent to any app. 1 app with access to mail, files or the directory.
What Microsoft 365 can't show: Judged from Entra ID consent settings and app permissions.
Change this answer
The cloud services and sub-processors that hold the client's data.
- Microsoft 365 (Microsoft 365 Business Basic, Microsoft 365 Business Premium). Cloud services connected to Microsoft 365 sign-in: Mail Sync Pro, Survey Tool, Zoom.
Microsoft 365 (Microsoft 365 Business Basic, Microsoft 365 Business Premium). Cloud services connected to Microsoft 365 sign-in: Mail Sync Pro, Survey Tool, Zoom.
What Microsoft 365 can't show: Microsoft 365 lists the apps connected to its sign-in; add the rest.
Change this answer
Staff receive security awareness training.
All staff complete security awareness training [when they join and every year], through [training provider or platform]. Simulated phishing exercises run [monthly or quarterly] and the results are reviewed by [role].
What Microsoft 365 can't show: Not something Microsoft 365 shows; answer from the client's own records.
Write this answer for Northwind Traders
Staff are vetted before they're given access.
New staff go through [right-to-work, reference and DBS] checks before they get access, and sign [confidentiality agreements].
What Microsoft 365 can't show: Not something Microsoft 365 shows; answer from the client's own records.
Write this answer for Northwind Traders
Premises and equipment are physically secured.
Offices are protected by [locked doors, access control and alarms]. [Servers and network equipment are kept in a locked room or cabinet.]
What Microsoft 365 can't show: Not something Microsoft 365 shows; answer from the client's own records.
Write this answer for Northwind Traders
The network is protected by firewalls.
A [make and model] firewall protects the internet connection at [site]. Home and remote workers are protected by the software firewall on their company devices.
What Microsoft 365 can't show: Not something Microsoft 365 shows; answer from the client's own records.
Write this answer for Northwind Traders
Remote access is protected by MFA.
Remote access to the network is only possible through [VPN or remote access product], which requires multi-factor authentication. Remote support tools ([product]) also require multi-factor authentication.
What Microsoft 365 can't show: Not something Microsoft 365 shows; answer from the client's own records.
Write this answer for Northwind Traders
Answers for the form
Supplier security questionnaireWhat clients ask in supplier and vendor due-diligence questionnaires. Use the text for the matching question on the client's form.
Governance 2 questions
Information security policies covering [acceptable use, access control, passwords, data protection and incident response] are approved by [role], reviewed every [12 months] and acknowledged by staff.
Why: Microsoft 365 can't show this.
Write this answer for Northwind Traders
The organisation holds [Cyber Essentials or Cyber Essentials Plus or ISO 27001] certification, number [certificate number], valid until [date].
Why: Microsoft 365 can't show this.
Write this answer for Northwind Traders
Access control 10 questions
Multi-factor authentication (MFA) is enforced for Microsoft 365 email (including Outlook on the web and mobile) and cloud applications, through Microsoft Entra ID. Enforced by Conditional Access ("Require MFA for all users") for everyone except 1 named exclusion: breakglass@northwindtraders.example (break-glass).
MFA coverage: accounts with a gap → Microsoft 365 data from 11 Oct 2026.
Still to check: This covers Microsoft 365 sign-ins only. Add VPN, remote desktop and any other system people reach from outside the office.
Change this answer
Multi-factor authentication is enforced for the administrator accounts of Microsoft 365 and Microsoft Entra ID. 2 of 3 active admin accounts are required to use MFA by "Require MFA for all users"; the exception is 1 break-glass account: breakglass@northwindtraders.example (excluded from "Require MFA for all users").
Admins and roles: privileged role holders → Microsoft 365 data from 11 Oct 2026.
Still to check: Covers Microsoft 365 and Entra ID admin roles. Add admin access to servers, firewalls, backup consoles and other cloud services.
Change this answer
Administrator accounts don't all use phishing-resistant sign-in methods yet. 2 admins without a phishing-resistant method.
Passwords and sign-in methods → Microsoft 365 data from 11 Oct 2026.
Change this answer
Some users rely on a text message or phone call as their only second factor. 3 people can only use a text or call as a second factor.
Passwords and sign-in methods → Microsoft 365 data from 11 Oct 2026.
Change this answer
Most administrator accounts are separate from day-to-day accounts. There are exceptions. 1 of 2 admin accounts also has a licence or mailbox, so it looks like an everyday account: ann.patel@northwindtraders.example.
Admins and roles: privileged role holders → Microsoft 365 data from 11 Oct 2026.
Still to check: Covers Microsoft 365 admin roles. Add local administrator, server and domain admin accounts.
Change this answer
Administrator role assignments in Microsoft 365 are tracked, with gaps. 4 accounts hold privileged admin roles, 2 of them Global Administrator (ann.patel@northwindtraders.example, breakglass@northwindtraders.example). 2 Global Administrators. 1 guest with admin roles. 1 app with privileged roles.
Admins and roles → Microsoft 365 data from 11 Oct 2026.
Still to check: Add administrators of servers, firewalls and other systems, and say how the list is kept.
Change this answer
Microsoft Entra ID requires passwords of at least 8 characters, blocks commonly used and known compromised passwords (Microsoft's global banned password list) and locks out repeated failed sign-in attempts (smart lockout). These are Microsoft defaults for cloud accounts. Multi-factor authentication is enforced as well (see the MFA answer), so a guessed password alone can't be used to sign in.
Passwords and sign-in methods → Microsoft 365 data from 11 Oct 2026.
Still to check: The password rules are Microsoft's defaults, not read from the tenant. Add other systems that use passwords (devices, servers, other cloud services).
Change this answer
Some inactive accounts in Microsoft Entra ID have not been disabled. 4 accounts inactive for 90+ days or never used. 1 disabled account still licensed.
Inactive accounts → Microsoft 365 data from 11 Oct 2026.
Still to check: Describe the leavers process: who tells IT, and how quickly accounts are disabled.
Change this answer
Guest and external user accounts are not reviewed regularly. 1 guest account: 1 guest inactive for 90+ days or never signed in (g#EXT#@northwindtraders.example).
Inactive accounts: inactive guests → Microsoft 365 data from 11 Oct 2026.
Still to check: Say how often guest access is reviewed, and by whom.
Change this answer
Data protection 4 questions
Email, files and Teams data are held in Microsoft 365, in Microsoft's datacentres.
Microsoft 365 data from 11 Oct 2026.
Still to check: Confirm the data location in the Microsoft 365 admin centre (Settings > Org settings > Organization profile > Data location), and add data held anywhere else.
Change this answer
Data in Microsoft 365 is encrypted at rest by Microsoft (BitLocker and per-file service encryption) and in transit using TLS. Not every company computer is encrypted: 4 of 36 computers not encrypted.
Devices: managed devices → Microsoft 365 data from 11 Oct 2026.
Still to check: The Microsoft 365 encryption is Microsoft's own, not read from the tenant. Add servers, backups and other systems.
Change this answer
Sharing with anonymous and external users is not restricted in SharePoint and OneDrive. Anyone, including anonymous links. 3 files and folders shared with anyone. Anyone, including guests, can invite guests.
Guests and sharing: external access settings → Microsoft 365 data from 11 Oct 2026.
Change this answer
Company computers managed in Microsoft Intune are not all encrypted. 4 of 36 computers not encrypted.
Devices: managed devices → Microsoft 365 data from 11 Oct 2026.
Still to check: Covers computers managed by Intune. Add any computers that aren't.
Change this answer
Email security 3 questions
Incoming email is filtered for spam, phishing and malware. Incoming email for northwindtraders.example is delivered to Microsoft 365 and filtered by Exchange Online Protection (anti-spam, anti-phishing and anti-malware).
Email domains → Microsoft 365 data from 11 Oct 2026.
Still to check: Office Sentry sees the mail routing and licences, not the filtering policies. Confirm Safe Links and Safe Attachments (or the gateway's equivalent) apply to every user.
Change this answer
SPF, DKIM and DMARC are not fully configured for the organisation's email domains. 1 domain with SPF problems. 1 mail domain without DKIM. 2 domains without DMARC enforcement.
Email domains → Microsoft 365 data from 11 Oct 2026.
Change this answer
Automatic forwarding to external addresses is restricted in Exchange Online, with exceptions. The default outbound policy blocks automatic external forwarding. But 4 external forwards found.
Mail forwarding → Microsoft 365 data from 11 Oct 2026.
Change this answer
Devices 4 questions
Company devices are not all managed centrally. 1 of 37 joined computers not in Intune. 6 of 37 managed devices not compliant.
Devices: managed devices → Microsoft 365 data from 11 Oct 2026.
Still to check: Covers devices joined to Entra ID. Add any company devices that aren't.
Change this answer
Managed Windows computers run versions of Windows that no longer receive security updates. 5 of 36 Windows computers past end of support.
Devices: operating systems → Microsoft 365 data from 11 Oct 2026.
Still to check: Covers Windows computers known to Intune or Entra ID. Add servers, macOS, phones, network devices and other software.
Change this answer
Operating system updates install automatically through [Windows Update for Business, Intune update rings or the RMM tool]. Critical and high-risk updates, including router and firewall firmware, are installed within 14 days of release, and this is checked [weekly] by [IT provider].
Why: Microsoft 365 can't show this. Intune shows which Windows version each computer runs (see the supported systems answer), not when updates were installed.
Write this answer for Northwind Traders
All desktops and laptops run [anti-malware product, for example Microsoft Defender Antivirus], which updates automatically, scans files when they're opened and blocks malicious websites. Tablets and phones only install apps from the official app stores.
Why: Microsoft 365 can't show this. Office Sentry doesn't read anti-malware settings.
Write this answer for Northwind Traders
Logging and monitoring 3 questions
Mailbox audit logging is enabled in Exchange Online, recording access to and actions on mailboxes. Mailbox auditing is on for the organisation.
Audit logging control → Microsoft 365 data from 11 Oct 2026.
Still to check: How long audit logs are kept depends on the Microsoft 365 licence; confirm the retention period.
Change this answer
Sign-ins are monitored for suspicious activity by [tool or service], and alerts are reviewed by [team or provider] [within one working day].
Why: Sign-in risk needs Entra ID P2.
Write this answer for Northwind Traders
External vulnerability scans run [monthly] using [tool or provider]. [A penetration test was last carried out on (date) by (provider).]
Why: Microsoft 365 can't show this.
Write this answer for Northwind Traders
Incidents, backups and continuity 3 questions
A documented incident response plan sets out roles, contacts and the steps to contain and recover from a cyber incident, including notifying [the insurer and IT provider]. It was last reviewed on [date] and tested on [date].
Why: Microsoft 365 can't show this.
Write this answer for Northwind Traders
Microsoft 365 data (Exchange Online mail, OneDrive, SharePoint and Teams) is backed up [daily] by [backup product or provider] to storage separate from Microsoft 365. Backups are kept for [retention period], are [immutable or offline], and use credentials separate from the Microsoft 365 administrator accounts. Restores were last tested on [date].
Why: Backups aren't visible in Microsoft 365 data. Answer from the backup product's records.
Write this answer for Northwind Traders
A business continuity and disaster recovery plan covers [key systems and services]. Recovery targets are [time to restore] to restore service and no more than [data loss window] of data loss. It was last tested on [date].
Why: Microsoft 365 can't show this.
Write this answer for Northwind Traders
Third parties 2 questions
Third-party application access to Microsoft 365 data is not controlled. Users can consent to any app. 1 app with access to mail, files or the directory.
Apps and consents → Microsoft 365 data from 11 Oct 2026.
Change this answer
Microsoft 365 (Microsoft 365 Business Basic, Microsoft 365 Business Premium). Cloud services connected to Microsoft 365 sign-in: Mail Sync Pro, Survey Tool, Zoom.
Apps and consents → Microsoft 365 data from 11 Oct 2026.
Still to check: Add cloud services people sign in to with separate accounts (accounting, payroll, CRM, file transfer, social media); Microsoft 365 can't see them.
Change this answer
People and premises 3 questions
All staff complete security awareness training [when they join and every year], through [training provider or platform]. Simulated phishing exercises run [monthly or quarterly] and the results are reviewed by [role].
Why: Training isn't visible in Microsoft 365 data. Answer from the training provider's records.
Write this answer for Northwind Traders
New staff go through [right-to-work, reference and DBS] checks before they get access, and sign [confidentiality agreements].
Why: Microsoft 365 can't show this.
Write this answer for Northwind Traders
Offices are protected by [locked doors, access control and alarms]. [Servers and network equipment are kept in a locked room or cabinet.]
Why: Microsoft 365 can't show this.
Write this answer for Northwind Traders
Network 2 questions
A [make and model] firewall protects the internet connection at [site]. Home and remote workers are protected by the software firewall on their company devices.
Why: Microsoft 365 can't show this. Firewalls aren't part of Microsoft 365.
Write this answer for Northwind Traders
Remote access to the network is only possible through [VPN or remote access product], which requires multi-factor authentication. Remote support tools ([product]) also require multi-factor authentication.
Why: Microsoft 365 can't show this. It sees Microsoft 365 sign-ins (see the MFA answer), not VPNs or remote desktop.
Write this answer for Northwind Traders
About this pack
Scope: the client's customer asks about the client's whole business. A Pass here covers Microsoft 365; the answer should say what covers the rest.
Requirements: Supplier and vendor due-diligence questionnaires as commonly worded in 2026. Questions drawn from the supplier security questionnaires UK organisations send their suppliers, in their typical wording; no organisation's form is copied.
Pass and Fail are judged from Microsoft 365 settings and accounts read with read-only access; accepted risks count as documented exceptions. Oldest data used: .