Access control and privilege

Is access restricted on a least-privilege basis to network, Personal Information, and Critical Information?

Every organisation answers yes to this. The underwriter knows that, which is why the follow-up questions and the claim review look for the evidence that a yes is real.

Partly verifiable from your tenant

What the carrier is actually asking

The carrier is asking whether people have the access their role requires and no more, across three surfaces it names deliberately: the network, systems holding personal information, and whatever you consider critical. It is a question about design and about maintenance, because access granted correctly and never reviewed becomes access granted incorrectly within a year or two.

Why it is underwritten

Least privilege determines blast radius. When a single account is compromised, the difference between a contained incident and a reportable breach of personal data is usually what that one account could reach. Because the answer is nearly always yes, underwriters weigh the supporting evidence: access reviews, role-based structure, and whether data stores are broadly readable.

Where the answer lives in Microsoft 365, Entra ID, and Azure

Parts of this are measurable. Directory and Azure role assignments are enumerable, and Microsoft 365 exposes sharing posture directly. Application-level entitlements inside line-of-business systems are not visible from the tenant.

PlatformWhere the setting livesWhat has to be true
Entra IDAccess reviews for privileged roles and for group membershipRecurring reviews exist and complete, rather than being configured and abandoned
Entra IDGroup-based licensing and access, versus direct assignmentAccess flows through roles and groups tied to job function, so joiners and leavers change one membership rather than many grants
AzureRole assignments at subscription, resource group, and resource scopeOwner is rare, Contributor is scoped, and assignments are made to groups rather than to individuals
Microsoft 365SharePoint and OneDrive sharing configuration, anyone-links and company-wide sharesNo unrestricted anonymous sharing, and site permissions that do not default to everyone
Line-of-business systemsEntitlement reviews inside finance, HR, and clinical or client systemsEvidence from those applications. Insurance Posture does not read them, so this portion is attested
Anyone-links are the quiet failure

An estate with immaculate role design and a SharePoint tenant that permits anonymous anyone-links has not restricted access to personal information. Sharing posture is where least privilege is most often undone, and it is fully measurable.

What a defensible yes requires

  • Access is granted through roles or groups tied to job function rather than by individual grant.
  • Recurring access reviews exist for privileged roles and for the groups guarding sensitive data, and they complete.
  • Sharing of files containing personal information is restricted, with anonymous links disabled or tightly limited.
  • Azure Owner assignments are rare and scoped, with Contributor used at the narrowest workable scope.
  • Role changes inside the organisation trigger revocation of the old access, not only addition of the new.

How this answer goes wrong

The characteristic failure is accumulation. Nobody grants excessive access on day one; people move roles and keep what they had. Two internal moves later, a finance analyst holds the access of three previous positions, and the organisation still answers yes because its provisioning design is sound. The design is not the control; the current entitlement state is.

Frequently asked

Do carriers expect formal access reviews?

Increasingly yes for privileged access, and it is the single most useful piece of evidence behind this answer. A completed quarterly review of privileged roles does more for the answer than a policy document.

Does this include data, or only systems?

Both, and the data half is often weaker. The question names personal information specifically, which points at file shares, collaboration sites, and database access rather than at directory roles.

How does this relate to the least-privilege question about vendors?

It is the same principle applied to a different population, and carriers ask it separately because service-provider access is often broader and less reviewed than employee access.

What if our line-of-business system has no role model?

Say so and describe the compensating control. An honest answer with a named limitation is more defensible than a yes that a claims review can dismantle.

Related questions

Stop answering this from memory

Connect Microsoft 365, Entra ID, and Azure read-only. Insurance Posture reads the live configuration behind each application answer and shows you which ones you can prove before you sign.

Assess your posture