Endpoint protection and patching

How frequently is software updated, vulnerabilities patched, unnecessary services disabled?

Carriers stopped accepting "regularly" some years ago. This question now wants a cadence, and the next one wants a deadline for critical fixes.

Partly verifiable from your tenant

What the carrier is actually asking

The carrier is asking three things bundled together: how often software is updated, how quickly known vulnerabilities are remediated, and whether unnecessary services are disabled. The third element is about hardening, and it is the one most organisations skip when answering.

Why it is underwritten

Exploitation of known, patched vulnerabilities remains one of the top initial access vectors, which means the loss was preventable with work that had already been published. Carriers price the gap between disclosure and remediation because that window is where their claims originate.

Where the answer lives in Microsoft 365, Entra ID, and Azure

Cloud workload patch state is directly readable. Endpoint patch compliance comes from your management tooling.

PlatformWhere the setting livesWhat has to be true
AzureUpdate assessment and patch compliance across virtual machinesPeriodic assessment enabled, with missing update counts rather than an assumption that automatic updates work
AzureVulnerability assessment on virtual machines and databasesA vulnerability solution deployed and reporting, so remediation has an input
AzureSystem update recommendations in Defender for CloudOutstanding recommendations tracked and closed rather than accumulating
Microsoft 365Update rings and compliance policies for endpointsDeployment rings with deadlines configured, so updates install rather than being deferred indefinitely by users
Microsoft 365Attack surface reduction and baseline configurationThe hardening half of the question: unnecessary features and legacy protocols disabled by policy
Deferral is the invisible failure

Update policies commonly allow users to defer, and a device that has deferred for months looks compliant right up to the point someone checks the installed patch level. Deadlines with enforced restarts are what turn a cadence into a state.

What a defensible yes requires

  • A stated cadence exists per system class, with a shorter path for security updates than for feature updates.
  • Patch compliance is measured against the estate rather than assumed from policy.
  • Vulnerability assessment feeds the remediation process, so patching is driven by findings and not only by vendor release dates.
  • Deferrals have limits and restarts are enforced.
  • Hardening is addressed: unnecessary services, legacy protocols, and default features disabled.

How this answer goes wrong

The gap between policy and state is the recurring theme. Automatic updates are enabled and a third of the fleet has not restarted in two months, so patches are downloaded and not active. The other gap is third-party software: the operating system is current while the browser, the runtime, and the line-of-business application are not, and those are the components with the exploits.

Frequently asked

What cadence do carriers expect?

Monthly for routine updates is the baseline expectation, with a much shorter window for critical severity. The next question on most forms asks for that window specifically.

Does automatic update satisfy this?

Only if you measure the result. Automatic update is a mechanism; patch compliance is the answer, and the two diverge in every real estate.

Does third-party software count?

Very much so. Browsers, runtimes, PDF readers, and remote access tools are frequent exploitation targets and frequent gaps in patch programmes built around operating system updates.

What about the hardening element?

Answer it explicitly. Baselines and attack surface reduction rules are concrete, and mentioning them distinguishes your answer from the majority that address patching only.

Related questions

Stop answering this from memory

Connect Microsoft 365, Entra ID, and Azure read-only. Insurance Posture reads the live configuration behind each application answer and shows you which ones you can prove before you sign.

Assess your posture