Which VPN provider/product does the Applicant use for remote connectivity?
This question became sharper after several years in which specific remote access products were exploited at scale.
What the carrier is actually asking
The carrier wants the vendor and product providing remote connectivity, and increasingly the version. Some markets check the named product against known vulnerable versions before quoting.
Why it is underwritten
Several remote access products have had critical, actively exploited vulnerabilities in recent years, and carriers have paid claims that trace directly to unpatched instances. The product name lets an underwriter check whether you are running something currently under active exploitation.
Where the answer lives in Microsoft 365, Entra ID, and Azure
Product and version come from your infrastructure, so this is attested. Currency is the part that matters.
| Platform | Where the setting lives | What has to be true |
|---|---|---|
| Network | Product, version, and last update date | Current version, with the date of the last update. Attested |
| Vendor advisories | Open advisories against your version | No unpatched critical advisories, checked at the time of answering rather than assumed |
| Entra ID | Whether the product federates for authentication | Federated authentication, so multi-factor and Conditional Access apply |
| Network | Management interface exposure | Management not reachable from the internet, which is separate from the service itself being reachable |
| Monitoring | Authentication logs from the product | Logs collected centrally, since these devices are frequently the first compromised and the last examined |
If your product has an open critical advisory and you answer this question without checking, you may be telling the underwriter something they already know from their own monitoring. Checking takes minutes and occasionally changes your renewal timeline.
What a defensible yes requires
- The answer names the product and the version.
- The version is current with respect to security advisories.
- Authentication federates so that multi-factor is enforced by policy.
- Management interfaces are not internet-reachable.
- Authentication logs are collected and retained.
How this answer goes wrong
The product is named and the version is a year behind, with a publicly exploited vulnerability outstanding. The answer is accurate and it discloses an exposure the organisation had not looked at, which is better found now than in a claim.
Frequently asked
Do carriers really check?
Some do, through external attack surface monitoring that identifies the product and version from its response. Assume it is visible.
What if we are behind on patches?
Patch before you submit if you can. If you cannot, disclose it with the compensating controls and the planned date.
Does the vendor choice affect price?
Less than the version currency does. Products with recent exploited vulnerabilities attract more scrutiny, and being current answers most of it.
What if we use several?
Name them all. Multiple remote access products usually means one is legacy, which is worth surfacing internally as well.
Related questions
Stop answering this from memory
Connect Microsoft 365, Entra ID, and Azure read-only. Insurance Posture reads the live configuration behind each application answer and shows you which ones you can prove before you sign.
Assess your posture