Cost guide
Microsoft 365 Security Assessment Cost
A Microsoft 365 or Google Workspace security assessment starts at $4,200 for one tenant of up to 250 users, fixed in writing before work begins. That buys a manual review of identity, MFA, mail security, sharing, and OAuth apps, with attack simulation from a compromised user from $6,800 and a free retest of every fix.
Small
One Microsoft 365 or Google Workspace tenant with up to 250 users. A manual configuration review of identity, MFA and Conditional Access, admin roles, mail security, sharing, OAuth apps, and logging.
Medium
The Small review plus attack simulation from a compromised standard user. Also the tier for 251 to 1,000 users, or when a hybrid link to on-premises Active Directory is in scope.
Large
Several tenants or domains, more than 1,000 users, hybrid identity pivots into on-premises Active Directory, or E5 workloads such as Defender, Purview, and Intune reviewed in depth.
What moves the number
What drives the cost of Microsoft 365 security assessment
Number of users and tenants
One tenant of up to 250 users is the Small review. More users, more domains, or several tenants mean more identities, roles, and policies to check, which moves the scope up a tier.
Review or attack simulation
The Small tier checks how the tenant is configured. The Medium tier also attacks it from a compromised standard user: password spraying, token theft, consent phishing, and escalation toward admin roles.
Hybrid identity
A sync link between Entra ID and on-premises Active Directory adds paths in both directions. When that link is in scope, the review moves to the Medium tier. Testing pivots into on-premises Active Directory in depth is Large-tier work.
Licensing and workloads
E5 features such as Defender, Purview data loss prevention, and Intune add policy surface. Reviewing them in depth, rather than confirming they are switched on, is Large-tier work quoted from the scope.
Microsoft 365 or Google Workspace
Both are priced the same. The checks differ by platform, Entra ID and Exchange Online on one side, Google identity and Gmail on the other, but the effort and the tiers match.
In the price
What every Microsoft 365 security assessment price includes
- ✓A manual review of identity, MFA, Conditional Access, admin roles, and legacy authentication, verified by hand rather than exported from a score
- ✓Mail security (SPF, DKIM, DMARC, forwarding rules, anti-phishing), external sharing and guests, OAuth app consent, and audit logging
- ✓Findings mapped to the CIS Microsoft 365 or Google Workspace benchmark, with read-only access for the review and nothing changed in your tenant
- ✓A fixed price agreed in writing before work begins, with no hourly billing
- ✓An executive summary for leadership and a full technical report with a prioritized fix list (see a sample penetration testing report)
- ✓A free retest: we re-run the checks after you fix the findings and update the report to show them closed
- ✓An attestation letter and findings platform access at no extra cost
- ✓Senior in-house testers, no subcontractors or crowdsourced testers
Keep it tight
How to keep the price down
- 01Grant a read-only reviewer role, such as Global Reader, on day one. The review starts the same day, and nobody has to export settings by hand.
- 02Start with the configuration review if the tenant has never been checked. Close the basic gaps first, then add attack simulation when there is something harder to test.
- 03Scope to the production tenant. Leave out dormant trial and test tenants unless they hold real users or data.
- 04Tell us your license level and any existing Conditional Access or sharing policies during scoping. Less discovery means more of the fee goes into testing.
Timeline
Onboarding begins within 24 hours of a signed proposal. The Small review takes 3 to 4 analyst days, and the report follows within 1 to 2 weeks of access being granted. The Medium review with attack simulation takes 5 to 7 days, with the report in 2 to 3 weeks. Large scopes are quoted and typically take 3 to 4 weeks. The free retest follows your fixes.
FAQ
Questions about Microsoft 365 security assessment cost
01How much does a Microsoft 365 security assessment cost?
It starts at $4,200 for one tenant of up to 250 users, fixed before work begins, with a free retest. Adding attack simulation from a compromised user, or a tenant of 251 to 1,000 users, is $6,800. Several tenants or more than 1,000 users are quoted from the scope. Every price is on the pricing page.
02Is a Google Workspace review priced the same?
Yes. Google Workspace uses the same tiers: $4,200 for one tenant of up to 250 users, and $6,800 with attack simulation. The checks change with the platform, Google identity, Gmail, and Drive sharing instead of Entra ID, Exchange Online, and SharePoint. The effort does not.
03What is the difference between the $4,200 and $6,800 tiers?
The $4,200 tier is a configuration review: we check how identity, mail, sharing, and apps are set up and verify each gap by hand. The $6,800 tier adds attack simulation from a compromised standard user, an assumed-breach start in your tenant. We try password spraying, token theft, consent phishing, and escalation toward admin roles, and show what one phished account can reach.
04Do you need Global Admin access?
No. The configuration review runs with a read-only role, such as Global Reader in Microsoft 365, and nothing in the tenant is changed. Attack simulation uses a standard test user account you create for us, the same starting point a real attacker gets from one successful phish.
05Why pay for a review when Microsoft Secure Score is free?
Secure Score is a useful checklist of recommended settings and a number. A manual review looks at the tenant as it is really used: mailbox rules that forward mail outside the company, OAuth apps users have consented to, and admin accounts without MFA. We verify each gap by hand and rank it by what an attacker would do with it. Our guide to malicious connected apps shows why consent matters.
06Is this the same as a cloud penetration test?
No. This assessment covers the Microsoft 365 or Google Workspace tenant: identity, mail, files, and apps. Azure, AWS, or GCP subscriptions that run your workloads are a cloud penetration test, from $6,800. Many firms that run only on Microsoft 365 need this assessment and not a cloud test.
Other cost guides
Web Application Penetration Testing Cost
From $5,200API Penetration Testing Cost
From $4,000Mobile Application Penetration Testing Cost
From $6,000Red Team Assessment Cost
From $12,500Cloud Penetration Testing Cost
From $6,800External Network Penetration Testing Cost
From $4,200Internal Network Penetration Testing Cost
From $6,000Secure Code Review Cost
From $4,800AI and LLM Penetration Testing Cost
From $4,500Phishing and Social Engineering Testing Cost
From $3,600Hardware and IoT Penetration Testing Cost
From $5,200Vulnerability Scanning and Assessment Cost
From $1,500Physical Penetration Testing Cost
From $6,800Wireless Penetration Testing Cost
From $3,800Thick Client Penetration Testing Cost
From $6,000Salesforce Penetration Testing Cost
From $5,200Get the exact number for your scope
Tell us what needs testing. You get a written fixed price within one business day, and the number does not move once testing starts.
Prefer the full scoping questionnaire?Get a Fixed-Scope Quote
Tell us what you need tested. We reply within one business day.
Thanks, we've received your message.
We'll be in touch shortly.