Control statement
Preserve the insurer's wording. Definitions such as “all users,” “remote access,” “privileged,” or “managed device” can materially change the answer.
Use the renewal process to verify current Microsoft 365 controls, document exceptions, and assign urgent work. Start with the insurer's actual questions—never a guessed universal checklist.
Cyber insurance applications and renewal requests differ by insurer, policy, industry, organization, and year. Obtain the current questionnaire, definitions, requested evidence period, and due date from the broker or insurer before translating a technical result into an answer.
The New York Department of Financial Services' insurer-focused Cyber Insurance Risk Framework says rigorous insured-risk measurement commonly gathers information about governance, vulnerability management, access controls, encryption, endpoint monitoring, boundary defenses, incident response, and third-party security. That breadth is a useful warning: a Microsoft 365 review can support part of the evidence set, not all of it.
For each statement, record the question's exact wording, defined scope, technical owner, current evidence, exceptions, last validation date, planned changes, and final approver.
Preserve the insurer's wording. Definitions such as “all users,” “remote access,” “privileged,” or “managed device” can materially change the answer.
Link a dated export, configuration view, log, test, or approved record to the in-scope tenant and population. Avoid relying on policy intent alone.
Identify excluded accounts, unsupported platforms, legacy workflows, emergency access paths, third-party controls, and evidence that could not be verified.
Distinguish current state from planned work. A ticket, purchase, pilot, or target date is not the same as a deployed and tested control.
Route material discrepancies to technical, risk, legal, and insurance stakeholders rather than letting one portal owner infer the final representation.
Validate changes before the application is approved and retain the evidence used. Record residual gaps instead of silently closing them.
This is a preparation inventory, not a claim that every insurer asks every question or that each item is included in every TenantShield scope.
Current role assignments, standing versus eligible access, separate administrator identities, authentication-method coverage, emergency access, service accounts, workload identities, and stale privilege.
Policy state, target populations, exclusions, application coverage, authentication strength, legacy authentication, device conditions, risk-based controls where licensed, and safe emergency-access treatment. Use the Conditional Access checklist to prepare.
Enrollment coverage, device ownership, compliance, platform gaps, encryption signals, endpoint-security policy, stale devices, app protection, local administration, and remediation workflows. See the Intune checklist.
Exchange Online forwarding and transport rules, accepted domains, mailbox access, email authentication, anti-phishing controls, alert routing, and Defender for Office 365 configuration where licensed.
Enterprise applications, permissions, consent, service-principal credentials, ownership, guest access, Teams, SharePoint and OneDrive sharing, anonymous links, and external-user lifecycle.
Available audit sources, retention, export paths, alert ownership, investigation workflow, tested contacts, administrative recovery, and evidence that material events reach a responsible person.
This example is a planning aid, not a promised assessment or underwriting timeline. Adjust it to the insurer's deadline, the organization's approval process, the technical scope, and the risk of proposed changes.
CISA's voluntary Cross-Sector Cybersecurity Performance Goals prioritize a limited set of high-impact outcomes, while the NIST Cybersecurity Framework 2.0 provides a broader vocabulary for governing, identifying, protecting, detecting, responding, and recovering. Neither replaces the insurer's current questions or the organization's own risk process.
Review the Microsoft 365 Security Assessment, use the assessment planning checklist, compare scope and cost drivers, or inspect the sample assessment.
No. Coverage, pricing, limits, exclusions, and underwriting decisions belong to the insurer and policy process. An assessment can improve Microsoft 365 evidence and identify priorities, but it cannot guarantee an insurance outcome.
Use the current application and broker or insurer instructions whenever possible because definitions, evidence periods, and deadlines vary. Before they arrive, teams can still inventory current controls and exceptions without guessing how a future question will be worded.
No. It may support identity, access, email, collaboration, device, application, logging, and recovery evidence. Network, backup, vulnerability, incident-response, vendor, legal, financial, and other enterprise topics can remain outside scope.
The organization should define that process. Technical owners can validate evidence; the broker, qualified coverage counsel, risk leaders, and authorized signatories should address policy language, disclosure duties, and representations.
These sources explain how insurers are encouraged to measure insured risk and provide broader risk-management outcomes. They do not describe any specific TenantShield customer's application or policy.
Request an assessment with the insurer's deadline and the areas that need validation. Scope and fixed pricing are confirmed before tenant access.