Identity posture

Entra ID roles, privileged assignments, legacy authentication and conditional access gaps.

Mail and collaboration

Mailbox forwarding and transport rules, sharing settings and externally reachable content.

Framework mapping

Findings map to the 8 compliance reporting frameworks plus CIS Benchmarks.

What is Microsoft 365 security testing?

Microsoft 365 security testing is the assessment of a tenant's configuration and identity layer for weaknesses an attacker could use to read mail, reach files or escalate privilege. It examines how the tenant is configured rather than the security of Microsoft's own infrastructure.

It matters because most intrusions that begin with a person begin here. A mailbox rule that quietly forwards externally, a legacy protocol that bypasses multi-factor authentication, or a guest account with more access than anyone remembers granting are all ordinary findings with serious consequences.

What the audit covers

The Microsoft 365 audit is agentless and read-only, connected with credentials scoped to read configuration. It sits alongside the cloud posture audit for AWS, Azure and GCP within the same 800+ automated checks.

AreaExamples of what is reviewed
Identity and accessPrivileged role assignments, guest access, stale and orphaned accounts
AuthenticationLegacy authentication paths, multi-factor coverage gaps, conditional access rules
Mail flowForwarding and transport rules, external relay, anti-spoofing configuration
Sharing and collaborationTenant-wide sharing settings and externally shared content
Application consentRegistered applications, delegated permissions and consent settings
AuditingWhether the audit log is enabled and retained usefully

Entra ID and hybrid identity

Microsoft Entra ID, formerly Azure AD, is where most organisations now hold the identity that unlocks everything else. If you also run on-premises Active Directory, the synchronisation between them creates paths worth testing in both directions.

PentestOps covers the on-premises side through Active Directory security testing, which runs via the on-premise agent, and the cloud side here. Reviewing them together is the point: a weakness in one is often only serious because of the other.

Where this sits in your plan

The Microsoft 365 and email audits are Enterprise-tier capabilities. Cloud posture auditing for AWS, Azure and GCP is available from the Professional tier. Current tier detail is on the pricing page, and each cloud account counts as one asset.

What this is not

  • It is not an assessment of Microsoft's own infrastructure. It reviews your tenant configuration, which is the part you are responsible for.
  • It is not a replacement for endpoint security. Device-level controls are assessed by the tools that own them.
  • It does not read your mail. The audit reads configuration, not message content.

Frequently Asked Questions

Do you need access to our mailboxes?

No. The audit reads tenant configuration through the Microsoft APIs using read-only credentials. It reviews settings such as forwarding and transport rules, not the content of messages.

Is this the same as the Azure audit?

They overlap but are not identical. Azure penetration testing covers subscription and resource configuration. This page covers the Microsoft 365 tenant and the Entra ID identity layer. Most organisations need both.

Which plan includes it?

The Microsoft 365 and email audits are Enterprise-tier capabilities. Cloud posture auditing for AWS, Azure and GCP starts at Professional. See pricing for current tier detail.

Does it cover hybrid Active Directory?

The on-premises directory is covered by Active Directory security testing through the on-premise agent, and the cloud identity layer is covered here. Running both is how you see the paths that cross between them.

Do we need the on-premise agent for this?

No. The Microsoft 365 audit is agentless. The agent is only needed to test inside a private network, such as on-premises Active Directory or internal network testing.

Is testing Microsoft 365 allowed?

Configuration auditing of your own tenant through the supported APIs is ordinary administrative activity. Microsoft publishes rules for penetration testing of its cloud services, so review the current version, and make sure your Rules of Engagement cover the tenant.

See what your tenant exposes

Connect Microsoft 365 with read-only credentials and review identity, mail flow and sharing exposure alongside the rest of your estate. Talk to our team about Enterprise scope.