Infrastructure

Microsoft Cloud

Automated tools check configurations. We simulate real-world attacks and test your Microsoft cloud environment from the perspective of a real attacker—from Entra ID to Azure to Microsoft 365.

Scope of the pentest

In this penetration test, our ethical hackers will examine your Microsoft cloud environment for security vulnerabilities and configuration errors. Our tests are conducted remotely. All we need is a dedicated test account in your Microsoft 365 tenant.

Exemplary test objects:

Entra ID (Azure AD)

Identity and Access Management: Users, Groups, Roles, and Conditional Access Policies

Exchange Online

Mailbox Permissions, Transport Rules, Forwarding, and Delegation

SharePoint & OneDrive

Sharing Structures, Guest Access, and Externally Shared Documents

Microsoft Teams

Team configurations, guest access, app permissions, and shared channels

Azure Resources

VMs, storage accounts, key vaults, automation accounts, and RBAC assignments

Hybrid Identities

Azure AD Connect, ADFS, and Synchronization Between On-Premises AD and Entra ID

80%

According to Microsoft, about 80 percent of all successful cyberattacks exploit identity-based vulnerabilities as their initial attack vector. ¹

A single AiTM campaign in April 2026 reached over 35,000 users in 13,000 organizations within three days.²

59%

MFA was enabled for 59% of the accounts compromised in 2025. In 84% of incident response operations, MFA did not prevent the attack.³

Penetration Test of the Microsoft Cloud Environment

Our approach

The penetration test described here involves a security analysis of your Microsoft cloud environment from an attacker’s perspective. We simulate a real attacker with compromised credentials or a malicious insider and attempt to identify and exploit vulnerabilities such as excessive permissions, misconfigured conditional access policies, or insecure app registrations.

In the first phase, we conduct unauthenticated reconnaissance. During this phase, we identify publicly available information about your tenant, including domain configurations, exposed authentication endpoints, and indications of the services in use. In addition, we assess vulnerability to password spraying and the enforcement of MFA across all authentication flows, including legacy protocols.

In the second phase, we use a low-privilege M365 user account provided by you. As an authenticated attacker, we enumerate your Entra ID environment, including users, groups, roles, administrative units, app registrations, service principals, and conditional access policies. We analyze role inheritance and group memberships to identify attack vectors for privilege escalation.

At the same time, we examine your Azure resources for misconfigurations and insecure RBAC assignments. These include storage accounts with public access, Key Vaults with overly permissive access policies, automation accounts, and Function Apps with managed identities that could be exploited for privilege escalation.

We place special emphasis on hybrid scenarios: Connections between on-premises Active Directory and Entra ID via Azure AD Connect often provide attackers with avenues for privilege escalation in both directions. We examine the configuration of the MSOL account, the ADFS infrastructure, and potential attack vectors such as “pass-the-certificate” or “Golden SAML”.

In the third phase, we document the actual business impact: access to mailboxes, exfiltration of confidential documents from SharePoint, stored credentials in Key Vaults, and the potential for persistent compromise of the tenant.

cloud

For many companies today, Microsoft 365 is the central platform for communication, collaboration, and document management—whether it’s emails via Exchange, files in SharePoint, chats in Teams, or identities in Entra ID. Confidential information such as contracts, personnel data, trade secrets, and customer communications is stored entirely in the cloud.

Testing types

Black-Box

Tests conducted as an external attacker without credentials. Focus on tenant reconnaissance, password spraying, and MFA bypass.

Grey-Box

Tests performed as a low-privileged M365 user. Focus on enumeration, privilege escalation, and lateral movement.

White-Box

Audit as a Global Administrator, including complete tenant documentation and a configuration review.

Standards and Qualifications

We follow recognized international standards for our pentest procedure.

Our penetration testers are highly qualified and certified with several recognized hacking certificates.