Coverage · Cyber insurance

Your renewal asks 141 questions. Verify what we can prove. Attest to the rest.

Carriers stopped taking your word for it — they want proof of MFA, admin controls, logging and backups. Tenant Strike answers every question a 2026 cyber-insurance questionnaire asks: the ones a read-only scan of your tenant can verify, cited with evidence, and the ones only you can speak to, captured as your own dated attestation.

Questions in the pack
141
Verified by your scan
59
Your own attestations
82
Write permissions
0

The problem

Guessing on the form is how coverage gets denied.

Cyber-insurance applications used to be a page of checkboxes. Now they run to a dozen pages of line-by-line control questions, and carriers ask for evidence — a Conditional Access export, sign-in logs, proof that MFA covers everyone and not just most people.

The trap is that the person filling in the form usually cannot check. They tick yes to “MFA is enforced for all users” because it is broadly true, not knowing three service accounts are exempt. Then a claim arrives, the insurer looks, and the answer that was optimistic in March becomes a misrepresentation in November.

You can lose the whole policy over one honest guess.

What you get

Every answer, and where it came from.

Yes

The scan verified it

We read the setting and it is in place. Answer with confidence, and keep the dated pack on file as the evidence you looked.

No · Partial

A real gap, with the fix

The setting is missing or only half in place. You get the exact change to make — so you can fix it before the renewal rather than declare it after.

Cannot attest

The answer nobody else gives you

Some settings genuinely cannot be read with the read-only access we hold — a handful of Exchange and Teams settings, and whether the Purview audit log is ingesting. A tool that quietly scores those as a pass is the thing that gets your claim denied. We say cannot attest, name the one command that answers it, and leave the decision with you. Uncertainty never rounds up.

Customer attestation

What only you can answer

82 questions — training, physical security, incident history, policy — sit outside what any tenant scan can see. You answer these yourself; we date them, label them clearly as your own statement, and print them alongside the verified answers, never blended into a scan finding.

How it works

Connect, scan, download.

  1. 01

    Connect read-only

    Your Microsoft admin approves one consent screen. We never request a single write permission, so nothing in your tenant can change.

  2. 02

    Scan your tenant

    The scan reads your identity, email, device, logging and external-exposure settings, then maps what it found onto the controls your carrier asks about.

  3. 03

    Download the pack

    A dated PDF or Excel workbook, per tenant, question by question — with guidance on everything that isn't already a clean yes. Bring it to your broker.

Coverage

8 sections, 141 questions.

  • Identity & Access
  • Email Protection
  • Endpoints & Devices
  • Data & Backup
  • Cloud Infrastructure
  • External Attack Surface
  • Detection & Response
  • Organization & Governance

These mirror the domains a 2026 SMB cyber questionnaire actually carries. Identity & Access carries the most weight of any section, because that is how carriers weight it — enforced MFA is still a precondition of ransomware cover at almost every carrier writing SMB business. Organization & Governance is the largest section, and the one a tenant scan cannot see at all — every question in it is answered by you, dated and exported alongside the verified evidence.

Managing client tenants?

Renewal season, one console.

Every client gets their own dated pack, and your partner console shows which of them still have questions to fix, verify, or attest to — so you can walk into a renewal conversation with the work already done, and bill for it. Reach out for MSP setup and pricing →

We verify what we can prove. You attest to the rest — we never attest on your behalf. The pack is generated from an automated read-only scan on the date it says. It does not bind us or your insurer, and anything marked partial or cannot-attest must be confirmed independently before you answer. Your own attestations are printed exactly as you entered them, dated, and never blended into a scan finding. That caveat is printed on the document itself — we would rather be useful than sound impressive. How our read-only access is enforced →

Know your answers before your carrier asks.

Connect your tenant and get your dated questionnaire pack in under five minutes. Read-only, no credit card to start.