Is access restricted on a least-privilege basis to network, Personal Information, and Critical Information?
Every organisation answers yes to this. The underwriter knows that, which is why the follow-up questions and the claim review look for the evidence that a yes is real.
What the carrier is actually asking
The carrier is asking whether people have the access their role requires and no more, across three surfaces it names deliberately: the network, systems holding personal information, and whatever you consider critical. It is a question about design and about maintenance, because access granted correctly and never reviewed becomes access granted incorrectly within a year or two.
Why it is underwritten
Least privilege determines blast radius. When a single account is compromised, the difference between a contained incident and a reportable breach of personal data is usually what that one account could reach. Because the answer is nearly always yes, underwriters weigh the supporting evidence: access reviews, role-based structure, and whether data stores are broadly readable.
Where the answer lives in Microsoft 365, Entra ID, and Azure
Parts of this are measurable. Directory and Azure role assignments are enumerable, and Microsoft 365 exposes sharing posture directly. Application-level entitlements inside line-of-business systems are not visible from the tenant.
| Platform | Where the setting lives | What has to be true |
|---|---|---|
| Entra ID | Access reviews for privileged roles and for group membership | Recurring reviews exist and complete, rather than being configured and abandoned |
| Entra ID | Group-based licensing and access, versus direct assignment | Access flows through roles and groups tied to job function, so joiners and leavers change one membership rather than many grants |
| Azure | Role assignments at subscription, resource group, and resource scope | Owner is rare, Contributor is scoped, and assignments are made to groups rather than to individuals |
| Microsoft 365 | SharePoint and OneDrive sharing configuration, anyone-links and company-wide shares | No unrestricted anonymous sharing, and site permissions that do not default to everyone |
| Line-of-business systems | Entitlement reviews inside finance, HR, and clinical or client systems | Evidence from those applications. Insurance Posture does not read them, so this portion is attested |
An estate with immaculate role design and a SharePoint tenant that permits anonymous anyone-links has not restricted access to personal information. Sharing posture is where least privilege is most often undone, and it is fully measurable.
What a defensible yes requires
- Access is granted through roles or groups tied to job function rather than by individual grant.
- Recurring access reviews exist for privileged roles and for the groups guarding sensitive data, and they complete.
- Sharing of files containing personal information is restricted, with anonymous links disabled or tightly limited.
- Azure Owner assignments are rare and scoped, with Contributor used at the narrowest workable scope.
- Role changes inside the organisation trigger revocation of the old access, not only addition of the new.
How this answer goes wrong
The characteristic failure is accumulation. Nobody grants excessive access on day one; people move roles and keep what they had. Two internal moves later, a finance analyst holds the access of three previous positions, and the organisation still answers yes because its provisioning design is sound. The design is not the control; the current entitlement state is.
Frequently asked
Do carriers expect formal access reviews?
Increasingly yes for privileged access, and it is the single most useful piece of evidence behind this answer. A completed quarterly review of privileged roles does more for the answer than a policy document.
Does this include data, or only systems?
Both, and the data half is often weaker. The question names personal information specifically, which points at file shares, collaboration sites, and database access rather than at directory roles.
How does this relate to the least-privilege question about vendors?
It is the same principle applied to a different population, and carriers ask it separately because service-provider access is often broader and less reviewed than employee access.
What if our line-of-business system has no role model?
Say so and describe the compensating control. An honest answer with a named limitation is more defensible than a yes that a claims review can dismantle.
Related questions
Stop answering this from memory
Connect Microsoft 365, Entra ID, and Azure read-only. Insurance Posture reads the live configuration behind each application answer and shows you which ones you can prove before you sign.
Assess your posture