Azure and Entra ID Penetration Testing (Microsoft 365)
Senior ethical hackers perform the Azure penetration test on Microsoft Entra ID, Azure resources and Microsoft 365; Microsoft permits customers to test their own tenant without prior approval.
What is tested and why it matters
From conditional access to mailbox forwarding rules, tested against the CIS Microsoft Azure and Microsoft 365 Foundations Benchmarks.
Microsoft Entra ID is the identity provider for Azure, Microsoft 365 and most SaaS applications an organisation uses. One compromised account with the wrong role, or one conditional access policy with an exclusion, is enough to reach mailboxes, SharePoint sites and subscriptions at the same time. App registrations, guest accounts and legacy authentication settings accumulate over years and are rarely reviewed. A penetration test approaches the tenant the way an attacker does; it starts from a phished user or a leaked credential and follows the attack paths in the MITRE ATT&CK cloud matrix to show how far the identity configuration lets an attacker go.
Who needs this assessment
Organisations that run their identity, mail and collaboration on Microsoft 365 and Azure.
This assessment is designed for organisations that rely on Microsoft Entra ID as their central identity provider and need independent evidence that a single compromised account cannot escalate to tenant-wide access.
Organisations that use Microsoft 365 for mail, documents and collaboration
Companies that host production workloads in Azure subscriptions
Organisations with hybrid identity through Entra Connect and an on-premises Active Directory
Teams that have adopted conditional access, Privileged Identity Management or passwordless sign-in and want the configuration verified
Organisations preparing for ISO 27001 or NIS2 audits with Microsoft 365 inside the audit scope
Healthcare organisations, municipalities and government agencies that store regulated data in SharePoint, OneDrive and Exchange Online
Where these assessments are relevant
- Financial services: customer portals, payment processing, and cloud-hosted transaction infrastructure.
- SaaS and technology: application validation before production deployment or enterprise procurement.
- Healthcare: digital systems handling patient data, clinical records, and connected medical devices.
- Retail and e-commerce: web applications processing transactions, customer accounts, and payment data.
What the assessment produces
The insight and evidence delivered at the conclusion of the assessment.
Every assessment concludes with a structured report covering identity and configuration findings, severity ratings, evidence, and remediation guidance. Reports are delivered through the Pentrox Portal and are available for download at any time.
- A prioritised list of findings mapped to the CIS Microsoft Azure and Microsoft 365 Foundations Benchmark controls
- Demonstrated attack paths from a single user account to Global Administrator, subscription Owner or another user's mailbox
- Validation of conditional access coverage, MFA enforcement, privileged role assignments and PIM activation settings
- Governance recommendations for app consent, guest access, sharing policies and sign-in log retention
- Portal access with real-time findings, retest workflow, and report downloads for the lifetime of the client account
How an assessment runs
- Scope and Intake
- Planning
- Assessment
- Reporting
- Findings & Retest
Retesting of remediated findings is included as standard with every assessment.
Assessment methodology
Five phases from scoping through verified remediation.
Each phase builds on the previous one. Benchmark review surfaces known misconfigurations, manual attack-path testing shows which of them an attacker can chain together, and quality review ensures every reported issue is documented with actionable remediation.
Scoping and access provisioning
The tenant, subscriptions and Microsoft 365 services in scope are confirmed. A tester account with the Global Reader and Security Reader roles in Entra ID and read access to the subscriptions in scope is provisioned, together with one or two standard test users. The starting position (external or assumed breach) is agreed.
Microsoft Cloud penetration testing rules, CIS Benchmarks (Scoping)Entra ID identity and access testing
Conditional access policies, MFA coverage, legacy authentication, privileged roles and PIM settings are tested for gaps. App registrations, service principals, consent grants and guest accounts are enumerated with ROADtools and AzureHound.
CIS Microsoft Azure Foundations Benchmark (Identity), MITRE ATT&CK (Initial Access, Privilege Escalation)Azure resource and RBAC testing
RBAC assignments, managed identities and automation accounts are reviewed for escalation paths to subscription Owner. Storage accounts, key vaults and network security groups are checked for public exposure and missing logging.
CIS Microsoft Azure Foundations Benchmark (Storage, Key Vault, Networking, Logging)Microsoft 365 and hybrid identity testing
Exchange Online transport rules, forwarding and delegation are tested for data exfiltration paths. SharePoint and OneDrive sharing, Teams external access and DLP policies are reviewed. Entra Connect and the on-premises link are checked for credential exposure.
CIS Microsoft 365 Foundations Benchmark (Exchange, SharePoint, Teams), MITRE ATT&CK (Collection, Exfiltration)Reporting and quality review
Each finding is documented with the affected object, the attack path it enables, the violated benchmark control and the remediation. Reports undergo quality review before delivery.
OWASP Risk Rating Methodology (severity rating), CIS Benchmarks (Reporting)Scope and deliverables
What is included, what is excluded, and what is delivered.
The statement of work defines the exact tenant, subscriptions, Microsoft 365 services and starting position before the assessment begins. The lists below reflect the standard scope for an Azure penetration test.
In scope
- Entra ID conditional access, MFA coverage, legacy authentication and password protection settings
- Privileged roles, Privileged Identity Management (PIM) configuration, app registrations, service principals and consent grants
- Guest accounts, external collaboration settings and cross-tenant access
- Azure RBAC, managed identities, automation accounts and subscription-level escalation paths
- Storage accounts, key vaults, network security groups and diagnostic logging
- Exchange Online transport rules, forwarding, delegation and mailbox auditing
- SharePoint, OneDrive and Teams sharing settings and DLP policies
- Hybrid identity through Entra Connect and the on-premises Active Directory link where applicable
Out of scope
- Application-layer testing of custom applications hosted in Azure (covered under Web and API Penetration Testing)
- Penetration testing of Microsoft's own infrastructure or of services outside the client tenant
- Full internal Active Directory assessment (covered under Infrastructure Penetration Testing)
- Licensing advice or migration planning
What you receive
- Executive summary Severity distribution, tenant security posture overview, and remediation priorities written for leadership.
- Detailed findings Each finding documented with the affected object, the CIS Benchmark control it violates, evidence, and remediation steps.
- Technical conclusion Identity attack paths, privilege escalation chains, and structural recommendations beyond individual fixes.
- Scope and strategy description Goals, starting position, test approach, and scope boundaries for audit traceability.
- Portal access Real-time findings, report downloads, retest workflow, and team management through a dedicated platform.
- Findings meeting A scheduled session to align on risks, priorities, and the remediation approach.
- Retest report Verification results after remediation, documenting each finding with its updated status.
Read more
Cloud misconfigurations that keep appearing
The misconfigurations found again and again in AWS, Azure and GCP, and what fixes them.
What a penetration test costs
Indicative prices by service, what moves the number, and what the price includes.
Windows enumeration in 2026: AD and Entra ID
How an attacker maps Active Directory and Entra ID once one account is compromised, and what a defender sees.
When independent assessment is the right step
An independent assessment is required ahead of an audit, a product launch, or a funding round, and the organisation needs documented evidence from a third party.
Digital platforms handle revenue, customer data, or service delivery, and the security of those platforms has not been validated by an external party.
Existing security controls have been implemented but have not been tested from an attacker perspective to confirm they work as intended.
Timeline
Illustrative durations to support planning. Confirmed in the statement of work.
The duration of an Azure penetration test depends on the size of the tenant, the number of subscriptions and whether Microsoft 365 and hybrid identity are included. The calibration bands below are indicative. Exact duration is confirmed in the statement of work.
What determines duration
- Number of users, guest accounts and privileged roles in the tenant
- Number of Azure subscriptions and the resources provisioned in them
- Complexity of conditional access policies, app registrations and consent grants
- Whether Exchange Online, SharePoint, OneDrive and Teams are in scope
- Whether hybrid identity through Entra Connect is in scope
Actual duration is confirmed during scoping and depends on the number of users, subscriptions and Microsoft 365 services in scope. A statement of work confirms the exact scope and timeline before the assessment begins. The final report is delivered within five business days after testing completes.
Why Pentrox
The operational standards behind every Azure penetration test.
These operational standards apply to every Azure penetration test Pentrox delivers, regardless of tenant size or licensing tier.
Identity first
Entra ID tested as the control plane for Azure and Microsoft 365.
Conditional access, privileged roles and app consent are tested by hand, from the position of a compromised standard user. The assessment shows which single misconfiguration turns one account into tenant-wide access.
Attack paths, not only benchmark scores
Findings show how misconfigurations chain together.
A benchmark score lists deviations. The assessment demonstrates the path an attacker follows through them, mapped to the MITRE ATT&CK cloud matrix, so remediation starts with the link that breaks the chain.
Microsoft 365 included
Mail, documents and Teams tested alongside the identity layer.
Exchange Online transport rules, forwarding, SharePoint sharing and Teams external access are reviewed against the CIS Microsoft 365 Foundations Benchmark. Data exfiltration paths are shown with evidence, not assumed.
Direct access to the tester
No account managers between the client and the security expert.
Critical or blocking findings are escalated immediately through the channel agreed at kickoff. Remediation can begin before the final report is delivered.
Portal-delivered results
Findings visible in real time through the Pentrox Portal.
The Pentrox Portal provides remediation tracking, retest requests, report downloads, and team access management. Two-factor authentication and role-based access control are enforced on every account.
Frequently asked questions
Practical answers for security teams and procurement officers.
Is an Azure penetration test allowed by Microsoft?
Yes. Microsoft's penetration testing rules for Microsoft Cloud allow customers to test their own Azure resources, Entra ID tenant and Microsoft 365 environment without prior notification or approval. The rules exclude denial-of-service testing, testing of other customers' tenants and testing of Microsoft's own infrastructure. The assessment stays within these boundaries; the statement of work records the tenant and subscriptions in scope so that every action is traceable to an agreed target.
How does this differ from a cloud security review?
A cloud security review compares the configuration against a benchmark with read-only access and reports every deviation. An Azure penetration test starts from an attacker position, such as a phished standard user, and attempts to reach Global Administrator, subscription Owner or another user's mailbox. Both use the CIS Benchmarks; the penetration test adds proof of which deviations are exploitable and in which order an attacker chains them together.
Is Entra ID tested, or only the Azure resources?
Entra ID is the core of the assessment. Conditional access policies, MFA coverage, legacy authentication, privileged roles, PIM settings, app registrations, service principals, consent grants and guest accounts are all tested. Azure resources such as RBAC assignments, managed identities, storage accounts and key vaults are tested as the second layer, because most escalation paths to a subscription start with an identity weakness. Both layers appear in one report.
Is Microsoft 365 included in the scope?
Yes, when the organisation uses it. Exchange Online is tested for transport rules, automatic forwarding and delegation that allow mail to leave the tenant unnoticed. SharePoint and OneDrive are checked for anonymous and organisation-wide sharing links. Teams external access and DLP policies are reviewed against the CIS Microsoft 365 Foundations Benchmark. The statement of work lists the services in scope; organisations that only use Azure can exclude Microsoft 365.
How long does an Azure penetration test take?
A single tenant with one subscription and cloud-only identity takes 3 to 4 testing days. A tenant with multiple subscriptions, Microsoft 365 services and a full conditional access review takes 4 to 7 testing days. Large hybrid environments start at 7 testing days. The final report is delivered within five business days after testing completes. The statement of work confirms the exact duration before the assessment begins.
What is needed to start?
Three items. A tester account with the Global Reader and Security Reader roles in Entra ID and read access to the subscriptions in scope, which together grant read access to the tenant configuration, the security settings and the Azure resources without write permissions. One or two standard user accounts with a typical licence and group membership, used as the assumed-breach starting position. A named contact who can answer questions about the environment during testing. Any further access is agreed during scoping and listed in the Pentrox Portal before testing starts.
Is production affected?
The assessment runs against the production tenant, because a separate test tenant does not carry the real policies, roles and sharing settings. Testing is read-heavy; the tester enumerates configuration and demonstrates attack paths using the provided test accounts. No conditional access policies are changed, the content of real users' mailboxes and documents is not read, and no denial-of-service techniques are used. Actions that would change the tenant are described in the report rather than performed.
Is a retest included?
Yes. Retesting of remediated findings is included as standard with every assessment, within 90 days after report delivery and at no additional cost. The client flags remediated findings through the Pentrox Portal and submits a retest request. The tester verifies each finding, for example by confirming that a conditional access policy now covers every user, and publishes the updated status and a retest report through the Portal.
Related assessments
Cloud Security Review
Configuration review of AWS, Azure and GCP against the CIS Benchmarks with read-only access.
Infrastructure Penetration Testing
Internal and external network testing, including the on-premises Active Directory behind Entra Connect.
Phishing Simulation
Measures how users respond to the credential phishing that precedes most Microsoft 365 account takeovers.