A bigger client, or their insurer, sends over a spreadsheet with sixty questions about your security. The deal waits until you send it back. Most of it is the same eight things asked in different words, and Microsoft 365 already holds the answer to nearly all of them.
The reason these take a fortnight is not that the questions are hard. It is that nobody knows where the evidence lives, so every answer turns into a small investigation, and the ones that cannot be answered get left blank or answered hopefully. A blank is better than a guess. A screenshot is better than either.
The eight things they are really asking
| What they ask | What answers it | Where it lives |
|---|---|---|
| Is multi factor authentication enforced for everyone, including admins and contractors? | The Conditional Access policy itself, its assignment, and the list of anyone excluded | Entra admin centre, Protection, Conditional Access |
| Who holds administrative access? | Role assignments, and whether admins use separate accounts | Entra admin centre, Roles and administrators |
| Are company devices encrypted? | The encryption report, per device, with the method and key escrow state | Intune, Devices, Monitor, Encryption report |
| Are operating systems and applications patched on a schedule? | Update ring configuration, deferral and deadline values, and the per device update report | Intune, Devices, Windows updates |
| Is there endpoint protection, and is somebody watching it? | Defender onboarding state and the antivirus status report | Intune endpoint security, and the Defender portal |
| Can your domain be spoofed? | SPF, DKIM and DMARC records, and the DMARC policy value | Public DNS, and Defender email authentication |
| What happens the day somebody leaves? | A written leaver process, and the audit trail of the last one you ran | Your own runbook, plus the Entra audit log |
| Can you wipe a lost laptop or phone? | The wipe and retire actions, and evidence you have used them | Intune, Devices |
The four that catch people out
Audit log retention. Business Premium keeps unified audit log entries for a limited window by default, and the questionnaire often asks for a year. Know your number before you are asked for it.
Backup. Microsoft protects itself against its own failures. It does not protect you against somebody deleting a SharePoint library and nobody noticing for three months. If you have no third party backup, say so plainly and say what your recovery window actually is.
Data location. Where your Exchange and SharePoint data physically sits is shown in the Microsoft 365 admin centre under your organisation profile. Look it up rather than assuming.
Subprocessors. If you use any IT provider, including us, they are a subprocessor and the questionnaire wants them named. Have the list ready.
How to answer the ones you fail
Do not leave them blank and do not stretch the truth. Write what is true today, then what you are doing about it and by when. A firm that says "not enforced for three contractor accounts, Conditional Access policy going on this month" reads as competent. A firm that says "yes" and gets caught in a follow up call reads as something worse.
Every one of these answers is a screenshot or an export. Collected in order, with the gaps named honestly, the pack is two days of work the first time and twenty minutes every time after.
That is what the $250 Health Check produces, and what hardening to a standard does with the gaps it finds.