12 questions in this section
partialDoes the Applicant utilize a Privileged Access Management (PAM) tool?
partialHow many domain and service accounts are in the Domain Admin Group?
verifiedAre all accounts associated with legitimate processes or current users (no orphaned/stale)?
partialIs access restricted on a least-privilege basis to network, Personal Information, and Critical Information?
verifiedAre administrator privileged access activities audited?
verifiedAre changes to administrator accounts reported automatically?
verifiedAre users able to access email through a non-corporate (BYOD/personal) device?
partialDoes the use and distribution of administrator and privileged access require senior management approval?
attestedAre wireless connections from untrusted devices allowed, and if so, are they on a separate network?
attestedDoes the Applicant use a password manager to maintain master/privileged passwords used to access client systems and IT infrastructure?
attestedAre master/privileged passwords used to access client systems and IT infrastructure unique and not reused?
partialDoes the Applicant enforce a strong password policy (complexity, periodic rotation, and account lockout after repeated failed attempts)?
Stop answering this from memory
Connect Microsoft 365, Entra ID, and Azure read-only. Insurance Posture reads the live configuration behind each application answer and shows you which ones you can prove before you sign.
Assess your posture