Are wireless connections from untrusted devices allowed, and if so, are they on a separate network?
This one lives entirely in your network equipment. No cloud tenant can answer it, and pretending otherwise is how an application answer becomes unsupportable.
What the carrier is actually asking
The carrier is asking whether devices the organisation does not control can join a wireless network, and if they can, whether that network is separated from the corporate one. Guest wireless, contractor devices, personal phones, and the increasingly large population of building and operational technology all sit inside this question.
Why it is underwritten
A shared wireless network puts an unmanaged device on the same layer-two segment as corporate systems, which defeats most of the perimeter controls the rest of the application asks about. It is a cheap control to implement and a common finding in incident reviews, so carriers keep asking.
Where the answer lives in Microsoft 365, Entra ID, and Azure
Insurance Posture reads Microsoft 365, Entra ID, Azure, and AWS. Wireless segregation is configured on your access points, switches, and firewall, so this answer is attested and should be supported by evidence from that equipment.
| Platform | Where the setting lives | What has to be true |
|---|---|---|
| Wireless controller | Guest SSID configuration and its VLAN assignment | The guest network terminates in its own VLAN with no route to corporate segments |
| Firewall | Rules between the guest VLAN and internal networks | Deny by default, with any exception named and justified |
| Wireless controller | Client isolation on the guest network | Guest devices cannot see each other, which limits the spread of anything already present |
| Network access control | 802.1X or certificate-based admission on the corporate network | Only enrolled devices join the corporate wireless, so separation depends on admission rather than on a shared passphrase |
| Entra ID | Conditional Access as a compensating control | Even where the network is flat, requiring a compliant device for corporate applications limits what an untrusted device can reach |
Network segregation is not visible from the cloud, but device-based Conditional Access is, and it is the compensating control an underwriter will recognise. Being able to show that an untrusted device on any network still cannot reach corporate applications strengthens a network answer you can only attest.
What a defensible yes requires
- Guest wireless exists as a separate network with no routed path to corporate segments.
- The corporate wireless requires enrolled devices, not a shared passphrase distributed by memory.
- Client isolation is enabled on the guest network.
- Operational technology and building systems are on their own segment rather than on the guest or corporate network.
- A dated configuration export supports the answer, since nothing in the cloud tenant can evidence it.
How this answer goes wrong
The usual failure is a corporate wireless network protected by a pre-shared key that has been the same for years and is known to every former employee and visiting contractor. It is technically the corporate network, and functionally an open one. The second failure is guest wireless that is separated at the SSID level and lands in the same VLAN.
Frequently asked
Can Insurance Posture verify this?
No. It reads cloud and identity configuration, not network hardware. This answer is attested, and the honest labelling is part of the value.
Is guest wireless a negative?
Not at all. Having one, properly separated, is better than the alternative where visitors are handed the corporate key.
What about a fully remote organisation?
Answer not applicable and explain that there is no corporate wireless. Remote-first estates should make sure the device management answer carries the weight this question would have.
How does this interact with segmentation questions?
It is the wireless case of the broader segmentation question, and carriers ask both. Consistent answers across the two matter, because a contradiction between them invites scrutiny.
Related questions
Stop answering this from memory
Connect Microsoft 365, Entra ID, and Azure read-only. Insurance Posture reads the live configuration behind each application answer and shows you which ones you can prove before you sign.
Assess your posture