Is It Worth Pen Testing Office 365? What to Test Instead First

A customer’s security questionnaire asks when you last had a penetration test. Your business runs almost entirely on Microsoft 365: email, Teams, SharePoint, OneDrive. A testing firm has quoted for “an Office 365 pen test,” and you are not sure what they would actually be testing, whether Microsoft even allows it, or whether the money would be better spent elsewhere.

The direct answer: for most small and mid-sized businesses, a traditional penetration test of Office 365 is not the best first spend. Microsoft secures the platform itself; what attackers exploit is how your tenant is configured and how your users sign in. A Microsoft 365 security configuration review, followed by targeted testing of identity and phishing resistance, usually finds more of the real risk for less money. A penetration test becomes worth it once that baseline is fixed, or when a customer or regulator specifically requires one.

What you can and cannot test

Microsoft publishes Rules of Engagement for penetration testing its cloud services. Testing must stay within your own tenant and assets you are authorised to test. The rules prohibit denial-of-service attacks, attempts to access or test other customers’ tenants, accessing data you do not own, phishing or social engineering aimed at Microsoft employees, and post-exploitation actions against Microsoft’s infrastructure.

In practice, that means nobody you hire is going to find a vulnerability in Exchange Online’s servers and exploit it for your report. They can test your configuration, your identities, your connected apps and your people. Which is fine, because that is where breaches of Microsoft 365 tenants usually start.

How Microsoft 365 tenants actually get compromised

The recurring patterns are unglamorous:

  • Weak or missing multifactor authentication, or MFA that has exceptions nobody remembers creating.
  • Legacy authentication left on. Older protocols cannot do MFA. Microsoft’s own documentation states that, based on its analysis, more than 97% of credential stuffing attacks and more than 99% of password spray attacks use legacy authentication.
  • Phishing that steals session tokens, not just passwords, which can get around weaker forms of MFA.
  • Risky app consent, where a user grants a malicious or over-permissioned third-party app access to mail or files.
  • Too many global administrators, often with everyday accounts doubling as admin accounts.
  • Mailbox forwarding rules quietly sending copies of invoices and payment conversations outside the company.
  • Oversharing in SharePoint and OneDrive, including “anyone with the link” sharing on sensitive folders.

A classic network penetration test is not designed to find most of these. A configuration review is.

Three types of assessment, and what each tells you

AssessmentWhat it checksBest for
Configuration reviewTenant settings against a benchmark such as the CIS Microsoft 365 Foundations Benchmark: MFA and Conditional Access, legacy auth, admin roles, sharing, mail flow rules, app consent, audit loggingAlmost every organisation, as the first step
Identity and phishing simulationWhether real users can be tricked, whether MFA holds up against token theft, and whether alerts fireOrganisations that have fixed the basics and want to test people and detection
Penetration testAn authorised attempt to gain access and move from an initial foothold, within Microsoft’s rules, often including endpoints, VPN and on-premises systems connected to the tenantMature environments, hybrid setups, contractual or compliance requirements

Microsoft Secure Score, available in the Microsoft Defender portal, gives you a free starting view of many configuration items. It is a useful checklist, but it does not weigh your specific business risk and it will not tell you whether a determined attacker could get in.

A worked example

Take a hypothetical 60-person accounting firm on Microsoft 365 Business Premium. A client’s due diligence asks for a pen test. The firm has a few options.

If it buys a penetration test first, the testers may find that MFA is missing on two accounts, legacy authentication is still enabled and there are six global admins. The report is useful, but the firm paid pen-test day rates to find configuration gaps a review would have found faster.

If it starts with a configuration review, those issues get fixed within weeks. A short phishing and identity test then checks whether the fixes hold. By the time the client asks again, the firm can show a remediated baseline and, if still required, a penetration test that focuses on what is left, such as its remote access and the laptops connecting to the tenant.

When a penetration test is worth it

  • A customer contract, cyber insurer or regulator specifically requires a penetration test, not just an assessment.
  • You run a hybrid environment, with on-premises Active Directory synchronised to Entra ID, where compromise can move between the two.
  • You have custom apps registered in your tenant, or public-facing apps using Microsoft sign-in.
  • Your configuration baseline is already solid, and you want to test detection and response against a realistic attack.

If you do commission one, be precise about scope. Ask the firm to state in writing how the test will stay within Microsoft’s Rules of Engagement, what will be tested (identities, endpoints, apps, on-premises links), and whether a configuration review is included. Our guide on how to buy a penetration test and not an automated scan covers the questions that separate real testing from rebadged scanning.

Questions to ask before you pay for anything

  1. Is this a configuration review, a phishing or identity test, a penetration test, or a combination?
  2. Which benchmark will settings be measured against, and will we get the evidence for each finding?
  3. Will you test token theft and MFA bypass, or only password attacks?
  4. Does the scope include app consents, mail flow rules and external sharing?
  5. Do you include a retest after we fix the findings?
  6. What will the report look like for a customer or auditor who asks for it?

Securing the tenant your business runs on

For a Microsoft 365 business, most of the security value is in getting the tenant configuration right and then proving it holds. AB7 Solutions’ cybersecurity team runs Microsoft 365 security configuration reviews, vulnerability assessment and penetration testing (VAPT) scoped to Microsoft’s rules, and phishing and identity testing, with remediation support to close what we find and a retest afterwards. If a configuration review is all you need right now, that is what we will recommend.

Tell us how your Microsoft 365 environment is set up and what your customer or insurer is asking for, and we will suggest the right level of testing.

Email: ab@ab7solutions.com | director@ab7solutions.com
Phone: +91 9878067778 | +1 321 341 7733
Website: www.ab7solutions.com

Sources: Microsoft Cloud Penetration Testing Rules of Engagement; Microsoft Learn, Block legacy authentication; CIS Microsoft 365 Benchmarks.

Related reading

Comments (3)

  1. […] Getting it wrong has a different kind of cost. If you are running on Microsoft 365, our guide on what to test in Office 365 first shows how much of that work is configuration and […]

  2. […] If your environment runs on Microsoft 365, Azure, AWS or Google Cloud, testers must follow those providers’ penetration testing rules as well as your own authorisation. We covered Microsoft’s rules in whether it is worth pen testing Office 365. […]

  3. […] Is It Worth Pen Testing Office 365? What to Test Instead First […]

Leave a Comment

Your email address will not be published. Required fields are marked *