Skip to content
Halberd Security
Authorised testing only. We test only with the owner's written authorisation, so scope is agreed before testing begins. Unauthorised testing is also illegal under the Computer Fraud and Abuse Act.

Service

Azure penetration testing, with identity at the centre

Azure penetration testing looks at your tenant and subscriptions the way an attacker would. Because Azure and Microsoft 365 share one identity layer, a weak account in one often opens the other.

  • Named tester before day one
  • One retest within 30 days
  • OWASP WSTG and NIST SP 800-115
Azure penetration testing: review entra id, test resources and report paths

What Azure penetration testing covers

Identity is the control plane in Azure. Therefore we start with Entra ID and follow the permissions outwards.

  • Privileged role assignments and who can grant them
  • Service principals, app registrations and their secrets
  • Storage accounts, key vaults and shared access signatures
  • Network security groups and exposed management endpoints
  • Conditional access gaps that let risky sign-ins through

Microsoft's rules for Azure penetration testing

Microsoft allows customers to test their own resources without notice, within its published rules. It forbids denial of service and attacks on other tenants. The Microsoft Cloud penetration testing rules of engagement sets out the details, and we reference them in your authorisation.

Azure penetration testing checklist

Tick what is already true. It tells us how quickly the scope can be fixed.

Your result appears here as you tick, so you can see what is still open.

From one account to the subscription

The question we try to answer is simple: if one user or one app secret leaked, how far could it go? For example, a service principal with contributor rights across subscriptions can often read every key vault. Showing that chain is what makes the report useful to your engineers.

How Azure penetration testing is delivered

We begin with a read-only review using an account you create. Then we test agreed paths actively, inside agreed windows. Each finding is written up with proof and a fix, and one retest inside 30 days is included. You also receive a short attestation letter for customers.

Price range for Azure penetration testing

Azure work sits inside our published cloud range of $10,000 to $50,000. The number of subscriptions and the size of the tenant move it most. A single subscription sits low; however, a large tenant with many app registrations sits higher.

Azure penetration testing questions

Does Azure penetration testing include Microsoft 365?

It can. Because both share Entra ID, many clients scope them together. If you only need one, we scope only that one.

Do we need to notify Microsoft?

Not for testing your own resources within the published rules. We confirm the current rules with you.

Will Azure penetration testing lock out users?

We avoid it. Password attacks are agreed in advance and kept well below lockout thresholds.

Can you test a single subscription?

Yes. Scope can be one subscription, a management group or the whole tenant.

Related guides

Request an Azure penetration testing scope

Tell us the size of the tenant and the number of subscriptions. We reply in writing with scope and fee.

Get my estimate