Blog · J.16 · Platform

Microsoft 365 & Entra ID (Azure AD) penetration testing

For most organisations the network is no longer the boundary - identity is. Email, files and apps live in Microsoft 365, and Entra ID (formerly Azure AD) decides who signs in and what they reach. So the user account is now the main thing between an attacker and your data: steal an identity through phishing, token theft or a misconfiguration, and much of the org is reachable without ever touching the internal network. Here's why cloud identity is the new perimeter, the risks that dominate, and what a tenant test covers.

Microsoft 365Entra IDAzure ADConditional AccessToken Theft
M365 / Entra ID: Identity is the New Perimeter · Phishing & Token Theft · Conditional-access Gaps · Consent Abuse · Over-privileged Roles · Legacy Auth M365 / Entra ID: Identity is the New Perimeter · Phishing & Token Theft · Conditional-access Gaps · Consent Abuse · Over-privileged Roles · Legacy Auth
// TL;DR

M365 & Entra ID testing assesses an organisation's cloud identity and productivity platform - Microsoft 365 (email, files, collaboration) and Entra ID (formerly Azure AD), the identity service controlling sign-in and access. Because so much now lives in this one platform and identity is the primary way attackers get in, testing the tenant matters as much as testing the network. The perimeter has moved: obtain a valid identity - via phishing, session-token theft, or a misconfiguration - and an attacker reaches a great deal without touching the internal network. Dominant risks: account compromise via phishing/token theft, conditional-access & MFA gaps, over-privileged users/admin roles, application-consent abuse (a malicious app granted ongoing mailbox/file access), excessive external sharing, and legacy authentication bypassing modern protections. A test reviews identity config (auth/MFA, conditional access, roles, legacy auth, admin protection) and M365 apps (email/anti-phishing, sharing, app permissions), plus escalation and detection - output is prioritised hardening. Related: cloud testing, AD attack paths.

// 01 What M365 & Entra ID testing is

It's a security assessment focused on an organisation's cloud identity and productivity platform - Microsoft 365 for email, files and collaboration, and Entra ID (formerly Azure Active Directory) as the identity service that controls who can sign in and what they can access. The test evaluates how well the tenant is configured and defended: the strength of authentication and multi-factor enforcement, the conditional-access rules that decide when access is allowed, the permissions and roles granted to users and applications, and the exposure of email and file-sharing. Because so much of an organisation now lives in this one platform, and because identity has become the primary way attackers get in, testing the M365 and Entra ID configuration has become as important as testing the traditional network - and complements the on-premises Active Directory picture in hybrid environments.

// 02 Why cloud identity is the new perimeter

For most organisations the network perimeter no longer defines the boundary of their systems, because email, documents and applications are accessed from anywhere through a cloud identity. That means the identity itself - the user account and the controls around signing in - has become the main thing standing between an attacker and the organisation's data. If an attacker can obtain a valid identity - through phishing, stealing a session token, or abusing a misconfiguration - they can often reach a great deal without ever touching the internal network. This is why security effort has shifted toward protecting and testing identity: strong multi-factor authentication, well-designed conditional-access policies, careful management of application permissions, and monitoring for suspicious sign-ins. Testing the identity platform reveals whether those protections actually hold up against realistic attacks - the same “prove it works” logic behind every penetration test.

// 03 The main risks

01

Phishing & token theft

The dominant risk - trick a user into revealing credentials or approving access, or steal a session token to bypass login and operate as them.

02

Conditional-access / MFA gaps

Misconfigurations leaving some sign-ins unprotected, and weak legacy authentication that bypasses modern controls.

03

Over-privileged roles

Excessive user and administrative privileges, and poorly separated admin accounts.

04

Consent abuse & sharing

A user tricked into granting a malicious app ongoing permissions to their mailbox or files; excessive external sharing.

The dominant risk is account compromise through phishing and token theft: an attacker obtains credentials or approval, or steals a token that bypasses the login, then operates as that user. Around it sit conditional-access and MFA gaps, over-privileged users and admin roles, and application-consent abuse - where a user is tricked into granting a malicious application ongoing permissions to their mailbox or files. Excessive external sharing, weak legacy authentication that bypasses modern protections, and poor separation of administrative accounts all add to the exposure. Testing looks for these specific weaknesses because they're the paths attackers actually use against cloud tenants - many beginning with a phishing lure.

// 04 What a test covers & how it's done

A test reviews the configuration and security of the identity and productivity platform end to end. On the identity side: authentication and MFA enforcement, conditional-access policies, the roles and permissions assigned to users and applications, legacy authentication exposure, and how administrative accounts are protected. On the productivity side: email security and anti-phishing controls, external sharing settings for files, and the permissions applications hold over data. It also considers how an attacker who compromised one account could escalate or move to reach more, and whether monitoring would detect them. The assessment is typically conducted with a defined level of access to the tenant so the configuration can be reviewed thoroughly, and its output is a prioritised set of hardening recommendations. It sits alongside cloud penetration testing and follows our methodology, with findings retested to closure.

// 05 Frequently asked questions

What is Microsoft 365 and Entra ID penetration testing?

A security assessment focused on an organisation's cloud identity and productivity platform - Microsoft 365 for email, files and collaboration, and Entra ID (formerly Azure AD) as the identity service controlling who can sign in and what they access. It evaluates how well the tenant is configured and defended: authentication and MFA enforcement, conditional-access rules, the permissions and roles granted to users and applications, and email and file-sharing exposure. Because so much now lives in this platform and identity is the primary way attackers get in, it's as important as testing the traditional network.

Why is cloud identity the new perimeter?

Because the network perimeter no longer defines the boundary - email, documents and apps are accessed from anywhere through a cloud identity. The identity itself, and the controls around signing in, has become the main thing between an attacker and the organisation's data. If an attacker obtains a valid identity through phishing, token theft or a misconfiguration, they can reach a great deal without touching the internal network. So effort has shifted to protecting and testing identity: strong MFA, conditional-access policies, application-permission management and sign-in monitoring. Testing reveals whether those protections hold against realistic attacks.

What are the main risks in M365 and Entra ID?

The dominant risk is account compromise through phishing and token theft - tricking a user into revealing credentials or approving access, or stealing a session token to bypass login and operate as them. Related risks: gaps or misconfigurations in conditional-access and MFA rules, over-privileged users and admin roles, and application-consent abuse, where a user is tricked into granting a malicious app ongoing permissions to their mailbox or files. Excessive external sharing, weak legacy authentication that bypasses modern protections, and poor separation of admin accounts add to the exposure.

What does an M365 and Entra ID test cover?

It reviews the identity and productivity platform end to end. On identity: authentication and MFA enforcement, conditional-access policies, roles and permissions for users and applications, legacy authentication exposure, and how admin accounts are protected. On productivity: email security and anti-phishing controls, external sharing settings, and app permissions over data. It also considers how a compromised account could escalate or move to reach more, and whether monitoring would detect it. It's typically done with a defined level of tenant access so the configuration can be reviewed thoroughly, producing prioritised hardening recommendations.

// 06 Related reading

UG

Usama Gul

Founder & Penetration Testing Lead, CyberFortify

Tests Microsoft 365 and Entra ID tenants across the GCC — conditional-access and MFA gaps, over-privileged roles, consent abuse and legacy auth — treating cloud identity as the perimeter it has become.

Your identity is your perimeter now

We test Microsoft 365 and Entra ID the way attackers hit them — conditional-access and MFA gaps, over-privileged roles, consent abuse, legacy auth — and hand you a prioritised hardening plan.

Scope an M365 / Entra test → Cloud testing service →