Network, logging and monitoring

Which VPN provider/product does the Applicant use for remote connectivity?

This question became sharper after several years in which specific remote access products were exploited at scale.

Attested, not tenant-verifiable

What the carrier is actually asking

The carrier wants the vendor and product providing remote connectivity, and increasingly the version. Some markets check the named product against known vulnerable versions before quoting.

Why it is underwritten

Several remote access products have had critical, actively exploited vulnerabilities in recent years, and carriers have paid claims that trace directly to unpatched instances. The product name lets an underwriter check whether you are running something currently under active exploitation.

Where the answer lives in Microsoft 365, Entra ID, and Azure

Product and version come from your infrastructure, so this is attested. Currency is the part that matters.

PlatformWhere the setting livesWhat has to be true
NetworkProduct, version, and last update dateCurrent version, with the date of the last update. Attested
Vendor advisoriesOpen advisories against your versionNo unpatched critical advisories, checked at the time of answering rather than assumed
Entra IDWhether the product federates for authenticationFederated authentication, so multi-factor and Conditional Access apply
NetworkManagement interface exposureManagement not reachable from the internet, which is separate from the service itself being reachable
MonitoringAuthentication logs from the productLogs collected centrally, since these devices are frequently the first compromised and the last examined
Check advisories before you answer

If your product has an open critical advisory and you answer this question without checking, you may be telling the underwriter something they already know from their own monitoring. Checking takes minutes and occasionally changes your renewal timeline.

What a defensible yes requires

  • The answer names the product and the version.
  • The version is current with respect to security advisories.
  • Authentication federates so that multi-factor is enforced by policy.
  • Management interfaces are not internet-reachable.
  • Authentication logs are collected and retained.

How this answer goes wrong

The product is named and the version is a year behind, with a publicly exploited vulnerability outstanding. The answer is accurate and it discloses an exposure the organisation had not looked at, which is better found now than in a claim.

Frequently asked

Do carriers really check?

Some do, through external attack surface monitoring that identifies the product and version from its response. Assume it is visible.

What if we are behind on patches?

Patch before you submit if you can. If you cannot, disclose it with the compensating controls and the planned date.

Does the vendor choice affect price?

Less than the version currency does. Products with recent exploited vulnerabilities attract more scrutiny, and being current answers most of it.

What if we use several?

Name them all. Multiple remote access products usually means one is legacy, which is worth surfacing internally as well.

Related questions

Stop answering this from memory

Connect Microsoft 365, Entra ID, and Azure read-only. Insurance Posture reads the live configuration behind each application answer and shows you which ones you can prove before you sign.

Assess your posture