Is endpoint detection & response (EDR) deployed with central monitoring?
Two words in this question do the work: deployed, which means everywhere rather than mostly, and monitored, which means someone reads what it produces.
What the carrier is actually asking
The carrier is asking whether endpoints run detection and response tooling that reports to a central console, and whether that console is watched. Endpoint detection and response differs from traditional antivirus in that it records behaviour, allows an analyst to investigate retrospectively, and can isolate a device remotely. Antivirus blocks known bad files. Carriers know the difference and increasingly ask for both by name.
Why it is underwritten
Ransomware deployment is a sequence, not an event: credential theft, lateral movement, defence tampering, staging, then encryption. Endpoint detection and response is the control most likely to interrupt that sequence in the middle, and remote isolation is the control that limits how much of the estate is reached. Carriers that have run the numbers price this heavily, and a growing number treat it as a condition rather than a credit.
Where the answer lives in Microsoft 365, Entra ID, and Azure
Insurance Posture reads the cloud and identity estate rather than an endpoint console, so fleet coverage numbers come from your endpoint tooling. What the tenant can show is whether the Microsoft components are enabled and whether devices are managed at all.
| Platform | Where the setting lives | What has to be true |
|---|---|---|
| Azure | Defender for Servers, and Defender for Endpoint integration | Enabled at subscription scope, so server workloads are covered rather than only user endpoints |
| Azure | Endpoint protection extension state on virtual machines | Installed across the virtual machine estate, including the machines built outside the standard pipeline |
| Microsoft 365 | Intune compliance policies and enrolment coverage | Devices are enrolled and a compliance policy requires the security agent to be present and healthy |
| Entra ID | Conditional Access requiring a compliant device | Non-compliant devices are actually denied, which is what turns a compliance policy from a report into an enforcement |
| Endpoint console | Agent coverage, health, and unmanaged device discovery | A coverage percentage with the denominator explained. Attested, since Insurance Posture does not read the endpoint console |
Ninety-eight percent coverage means nothing until you know what the total was. Consoles report against devices they know about, which excludes exactly the machines an attacker will find first: the unmanaged laptop, the forgotten server, the acquisition that was never onboarded. Discovery of unmanaged devices is the part of this answer worth checking before you sign.
What a defensible yes requires
- The tooling records behaviour and supports retrospective investigation and remote isolation, not only signature blocking.
- Coverage is stated against a discovered denominator rather than against the console inventory alone.
- Servers are covered as well as user endpoints.
- Alerts reach a human on a defined schedule, whether internal or through a managed service.
- Tamper protection is on, so the agent cannot be disabled by the credential that just compromised the device.
How this answer goes wrong
The frequent overstatement is answering yes for a licence that is deployed and unmonitored. Alerts accumulate in a console nobody opens, which is detection without response. The second is server coverage: user endpoints carefully managed while the virtual machine estate runs whatever was in the image. The third is tamper protection left off, which lets an attacker with local administrator quietly stop the agent before doing anything visible.
Frequently asked
Does Microsoft Defender count as EDR?
Defender for Endpoint does, in its plan that includes detection and response. The antivirus component alone does not. Name the specific plan on the application, because the distinction is exactly what the question is probing.
Does a managed detection service satisfy the monitoring half?
Yes, and it is often the strongest answer for organisations without a security operations function. State the provider and the coverage hours.
What coverage percentage do carriers want?
Most look for the high nineties and react more to how the number was produced. A stated ninety-four percent with a plan for the remainder reads better than an unexplained hundred.
What about servers and cloud workloads?
They are in scope and they are where coverage gaps concentrate. Defender for Servers or an equivalent agent on cloud workloads is the part of this answer people forget to describe.
Related questions
Stop answering this from memory
Connect Microsoft 365, Entra ID, and Azure read-only. Insurance Posture reads the live configuration behind each application answer and shows you which ones you can prove before you sign.
Assess your posture