The renewal questionnaire lands in your inbox with a two week deadline and forty questions written by someone who has never seen your environment. You answer yes to MFA because MFA is on. Nine months later a claim gets adjusted, someone pulls the sign-in logs, and it turns out four admin accounts were excluded the whole time.

Most of what a cyber insurance application asks about is a queryable fact in Microsoft 365, Entra ID, and Azure rather than a matter of opinion: MFA enforcement coverage, standing admin counts, storage immutability windows, log retention, and public exposure can all be read directly from the tenant. The failure mode is not lying, it is answering from a policy document instead of from the systems, and never revalidating. For the control requirements themselves, carrier by carrier, see the cyber insurance requirements guide on Insurance Posture.

The Application Is a Legal Document

Your answers become representations the policy relies on. Get one materially wrong and the carrier has grounds to reduce or deny at exactly the moment you need the money. That risk is bigger than the premium, and it is why carriers stopped trusting checkboxes: most now run an external attack surface scan before quoting, and a growing number ask for deployment reports, coverage percentages, and restore test logs instead of a yes.

Where Each Answer Actually Lives

What the carrier asks Where the answer is measurable What counts as proof
MFA on email, VPN, RDP, admins Entra ID Conditional Access policies checked against sign-in logs, including legacy auth paths Coverage percentage per policy target, with named exclusions
Phishing-resistant MFA on privileged accounts Entra authentication methods and authentication strength policies FIDO2 or certificate-based method registration per admin
Standing privileged access Entra role assignments, PIM eligible versus permanent Count of permanent Global Admins and their MFA state
Immutable backups Azure Storage immutability policies, object lock state and window Locked policy with retention window and last restore test date
Backup credential separation Role assignments on backup vaults and storage versus production admins No overlap between the two principal sets
Email security Exchange Online protection settings, DMARC, DKIM, SPF records Policy state plus published DNS records
Logging and retention Diagnostic settings, log retention configuration Retention days per workspace against the answer given

Two questions trip almost everyone. Executive exclusions: somebody exempted the CFO because push prompts annoyed them, and the exemption is still live. Nearly every 2026 form asks directly whether any VIP accounts are excluded. And break-glass accounts, which need documented compensating controls rather than a silent exemption. Token theft and MFA bypass is why carriers started splitting the MFA question into enforcement and phishing resistance in the first place.

The Three Answers That Void Claims

Answering for intent rather than reality, as in "we require MFA" when enforcement covers 87 percent of accounts. Answering once and never revalidating, so a true answer in January is false by September. And answering from a policy document instead of from the systems themselves. A question-by-question walkthrough of a typical carrier application shows what each item is really assessing.

Date the Evidence, Not Just the Answer

The safe habit is to store the artifact behind every answer alongside the application, dated. If a claim gets scrutinized you want to show what was true on the day you signed, not reconstruct it under pressure. That is the same discipline auditors apply to SOC 2 evidence, for the same reason.

SecValley scans Microsoft 365, Entra ID, and Azure read-only and turns those settings into dated findings. Insurance Posture, built on the same scans, maps them to carrier application questions and flags the answers your live environment contradicts.

Start with your last application. Take each yes and go find the control that proves it. The gaps you discover this week are cheaper than the ones your carrier discovers during a claim.

SecValley is a security scanning and compliance platform, not an insurance broker, agent, or carrier. Nothing here is insurance, legal, or coverage advice. Policy wording, application questions, and the consequences of a misstatement vary by carrier, by policy, and by state. Talk to your broker and your counsel about your own program.

Frequently Asked Questions

Can I answer a cyber insurance application from my Microsoft tenant configuration?

Most of it, yes. MFA enforcement, privileged account counts, backup immutability, email authentication, and log retention are all readable from Entra ID, Exchange Online, and Azure configuration. What is not readable that way, such as tabletop exercise dates, employee training completion, and third party contract terms, has to come from records you keep outside the tenant.

How often should application answers be revalidated?

At minimum before every renewal, and in practice quarterly. Conditional Access exclusions, new admin accounts, and changed storage policies all move between renewals, and an answer that was accurate when submitted is still a misstatement if the control lapsed before the loss.

What evidence do carriers accept instead of a yes or no?

Coverage percentages, configuration exports, deployment or agent coverage reports, restore test logs, and dated screenshots of the relevant policy. The common thread is that the artifact shows a state on a date rather than an intention.

Does a wrong answer automatically void the policy?

No, but a material misstatement gives the carrier grounds to rescind or reduce payment, and materiality is judged against whether the carrier would have priced or written the risk differently. Dated evidence collected at submission time is the practical defense.