Home/Questions/Access control and privilege/Guest wireless separation
Access control and privilege

Are wireless connections from untrusted devices allowed, and if so, are they on a separate network?

This one lives entirely in your network equipment. No cloud tenant can answer it, and pretending otherwise is how an application answer becomes unsupportable.

Attested, not tenant-verifiable

What the carrier is actually asking

The carrier is asking whether devices the organisation does not control can join a wireless network, and if they can, whether that network is separated from the corporate one. Guest wireless, contractor devices, personal phones, and the increasingly large population of building and operational technology all sit inside this question.

Why it is underwritten

A shared wireless network puts an unmanaged device on the same layer-two segment as corporate systems, which defeats most of the perimeter controls the rest of the application asks about. It is a cheap control to implement and a common finding in incident reviews, so carriers keep asking.

Where the answer lives in Microsoft 365, Entra ID, and Azure

Insurance Posture reads Microsoft 365, Entra ID, Azure, and AWS. Wireless segregation is configured on your access points, switches, and firewall, so this answer is attested and should be supported by evidence from that equipment.

PlatformWhere the setting livesWhat has to be true
Wireless controllerGuest SSID configuration and its VLAN assignmentThe guest network terminates in its own VLAN with no route to corporate segments
FirewallRules between the guest VLAN and internal networksDeny by default, with any exception named and justified
Wireless controllerClient isolation on the guest networkGuest devices cannot see each other, which limits the spread of anything already present
Network access control802.1X or certificate-based admission on the corporate networkOnly enrolled devices join the corporate wireless, so separation depends on admission rather than on a shared passphrase
Entra IDConditional Access as a compensating controlEven where the network is flat, requiring a compliant device for corporate applications limits what an untrusted device can reach
What the tenant can still contribute

Network segregation is not visible from the cloud, but device-based Conditional Access is, and it is the compensating control an underwriter will recognise. Being able to show that an untrusted device on any network still cannot reach corporate applications strengthens a network answer you can only attest.

What a defensible yes requires

  • Guest wireless exists as a separate network with no routed path to corporate segments.
  • The corporate wireless requires enrolled devices, not a shared passphrase distributed by memory.
  • Client isolation is enabled on the guest network.
  • Operational technology and building systems are on their own segment rather than on the guest or corporate network.
  • A dated configuration export supports the answer, since nothing in the cloud tenant can evidence it.

How this answer goes wrong

The usual failure is a corporate wireless network protected by a pre-shared key that has been the same for years and is known to every former employee and visiting contractor. It is technically the corporate network, and functionally an open one. The second failure is guest wireless that is separated at the SSID level and lands in the same VLAN.

Frequently asked

Can Insurance Posture verify this?

No. It reads cloud and identity configuration, not network hardware. This answer is attested, and the honest labelling is part of the value.

Is guest wireless a negative?

Not at all. Having one, properly separated, is better than the alternative where visitors are handed the corporate key.

What about a fully remote organisation?

Answer not applicable and explain that there is no corporate wireless. Remote-first estates should make sure the device management answer carries the weight this question would have.

How does this interact with segmentation questions?

It is the wireless case of the broader segmentation question, and carriers ask both. Consistent answers across the two matter, because a contradiction between them invites scrutiny.

Related questions

Stop answering this from memory

Connect Microsoft 365, Entra ID, and Azure read-only. Insurance Posture reads the live configuration behind each application answer and shows you which ones you can prove before you sign.

Assess your posture