Endpoint protection and patching

Does the Applicant use any operating system, hardware or software that is no longer supported / End-of-Life?

Every estate of any age has some. The question is whether you know where it is and what surrounds it, because carriers will find out either way.

Partly verifiable from your tenant

What the carrier is actually asking

The carrier is asking whether anything in your environment no longer receives security updates from its vendor: operating systems past end of support, database versions out of extended support, appliances the manufacturer has stopped maintaining, and applications whose vendor has disappeared. It usually asks for the detail if you answer yes.

Why it is underwritten

Unsupported software accumulates vulnerabilities permanently. Once a vendor stops issuing fixes, every new flaw is unpatchable, and public exploit code arrives faster than compensating controls get built. Carriers ask because unsupported internet-facing systems are among the strongest predictors of an intrusion they will pay for.

Where the answer lives in Microsoft 365, Entra ID, and Azure

The cloud estate exposes operating system versions and update state directly. On-premises appliances and line-of-business software need their own inventory.

PlatformWhere the setting livesWhat has to be true
AzureVirtual machine operating system versions and update assessment stateA version inventory across subscriptions, with anything past support identified rather than aggregated away
AzureApp Service runtime stacks and their support stateLanguage runtimes and frameworks past end of support, which age out quietly and are internet-facing by default
AzureDatabase engine versions and their support lifecycleManaged database versions approaching or past end of support
Microsoft 365Device compliance policies with minimum operating system versionsA floor enforced by policy, so end-of-life endpoints lose access rather than persisting unnoticed
Asset inventoryAppliances, firmware, and line-of-business applicationsVendor support status per item. Attested, and usually the part that surprises people
Answering yes is normal

A candid yes with an inventory, a segmentation story, and a decommissioning date reads as competence. A no that a scan later contradicts reads as a misrepresentation. Carriers see unsupported systems constantly; what they rarely see is an insured who knows exactly which ones and why.

What a defensible yes requires

  • An inventory exists that maps systems to vendor support status, refreshed rather than compiled once.
  • Anything unsupported is isolated: no internet exposure, restricted network reach, tightened access.
  • Each unsupported item has an owner and a dated plan, whether replacement, upgrade, or extended support purchase.
  • Endpoint policy enforces a minimum operating system version so the workstation fleet does not age past support silently.
  • Extended support arrangements, where purchased, are documented and current.

How this answer goes wrong

The answer is often no in good faith and wrong in fact. Nobody counts the appliance in the comms room whose firmware has not been updated since installation, the virtual machine running a legacy application that finance needs at quarter end, or the framework version underneath a public web application. External scanning finds these, and so does a claims investigation.

Frequently asked

Will answering yes get us declined?

Usually not by itself. It leads to follow-up questions about isolation and timeline. Unsupported systems that are internet-facing are the case where markets do decline.

Does extended support count as supported?

Yes, when it is purchased and current, and it is worth stating explicitly because otherwise the version number tells a different story.

What about firmware on network gear?

It counts, and it is the most commonly missed category. Devices that were fully supported when installed reach end of life quietly, several network refreshes ago.

How do we handle software whose vendor is gone?

Treat it as unsupported permanently and manage it by isolation. State it plainly; carriers understand the situation and respond to how it is contained.

Related questions

Stop answering this from memory

Connect Microsoft 365, Entra ID, and Azure read-only. Insurance Posture reads the live configuration behind each application answer and shows you which ones you can prove before you sign.

Assess your posture