How is the Applicant's VPN infrastructure hosted (exclusively cloud-based, exclusively on-premises, or hybrid)?
The interesting consequence of this answer is who is responsible for patching the appliance, because that is where recent intrusions have concentrated.
What the carrier is actually asking
The carrier is asking whether remote access infrastructure is cloud-based, on-premises, or a mix. It is a profiling question that sets up the follow-up about which product you use.
Why it is underwritten
On-premises concentrators are your responsibility to patch, and vulnerabilities in them have driven a significant share of recent ransomware intrusions. Cloud-delivered access shifts that burden to the provider. Neither answer is wrong; they carry different responsibilities.
Where the answer lives in Microsoft 365, Entra ID, and Azure
Remote access infrastructure sits outside the cloud tenant unless it is cloud-delivered, so this is largely attested.
| Platform | Where the setting lives | What has to be true |
|---|---|---|
| Network | VPN concentrator location, model, and version | The inventory of remote access infrastructure, including anything left over from a previous design. Attested |
| Azure | VPN gateway or virtual WAN configuration, where cloud-hosted | Cloud gateway configuration, which is measurable and patched by the platform |
| Entra ID | Whether remote access authenticates against the directory | Federated authentication, which brings Conditional Access into the remote access path |
| Vendor | Zero trust network access or cloud-delivered access service, where used | The service and its configuration. Attested |
| Network | Legacy remote access paths still in place | Decommissioned properly rather than left listening, which is a recurring finding |
Organisations migrate to a new remote access solution and leave the previous appliance powered on, unpatched, and reachable. It no longer appears in any process because it is no longer the official solution. It is still an internet-facing service accepting credentials.
What a defensible yes requires
- The full inventory of remote access paths is known, including legacy ones.
- Where infrastructure is on-premises, firmware currency has an owner and a short patch window.
- Authentication federates to the directory so one policy governs.
- Decommissioned solutions are removed from the network rather than disabled in configuration.
- The answer given here is consistent with the remote access multi-factor answer.
How this answer goes wrong
The answer describes the current solution and omits the legacy path that still exists. Or a hybrid estate is described as cloud-based because the new deployment is the one people think about.
Frequently asked
Is cloud-hosted better for underwriting?
Marginally, because patching moves to the provider and appliance vulnerabilities have been a major loss driver. The controls on the access matter more than the hosting model.
What counts as hybrid?
Any estate with more than one remote access path, which is most estates once you count the legacy ones. Disclose it accurately.
Does zero trust network access change the answer?
It usually means cloud-delivered with no inbound listener, which is a strong answer. Describe it rather than forcing it into one of the offered options.
What if we have no VPN?
Say so. A cloud-first estate with no inbound network path is a good position and worth stating explicitly.
Related questions
Stop answering this from memory
Connect Microsoft 365, Entra ID, and Azure read-only. Insurance Posture reads the live configuration behind each application answer and shows you which ones you can prove before you sign.
Assess your posture