Skip to content

Cloud

Microsoft 365
Security Assessment

Microsoft 365 and Google Workspace tenant testing

Configuration review from $4,200, attack simulation from $6,800, fixed scope, free retest. See all pricing →

Get a fixed quote

Reply in one business day

Senior certified testers, manual-first185+ years combined experienceOnboarding within 24 hoursFree retest includedOur methodology

When you need it

When a Microsoft 365 or Google Workspace tenant needs testing

The situations that bring teams to this engagement, and where it fits alongside the rest of your program.

  • Your whole IT estate is a Microsoft 365 or Google Workspace tenant and no outsider has ever reviewed how it is configured.
  • An invoice was paid to the wrong account, or a mailbox was taken over, and you need to know what a compromised login can still reach.
  • A cyber-insurance application asks whether MFA is enforced on every account and how mailbox rules are monitored.
  • You rolled out conditional access, a new admin role, or a third-party app that asked for broad OAuth permissions.
  • An enterprise customer or auditor wants independent evidence that your SOC 2 or ISO 27001 identity controls actually hold.

Definition

What is a Microsoft 365 security assessment?

A Microsoft 365 security assessment, sometimes called an Office 365 security audit, is a manual review of how your tenant is configured and what a compromised account could reach. It covers identity and MFA, conditional access, mailbox and sharing settings, OAuth app consent, and audit logging, verified by hand rather than exported from a Secure Score dashboard. Access is read-only, so nothing in the tenant is changed while we test.

The same engagement covers Google Workspace, with Google identity, Gmail security, and Drive sharing in place of the Microsoft equivalents, at the same prices. The configuration review starts at $4,200; adding an attack simulation from a compromised user starts at $6,800. Read our explainer on malicious connected apps for one of the paths this test closes.

What we look for

Microsoft 365 and Google Workspace weaknesses we hunt for

A cloud tenant is one login page away from every mailbox, file, and admin control your business runs on. The findings that matter are the ones that let a single phished user read the inbox, move money, or become an administrator.

Identity, MFA, and conditional access

The single sign-on that protects every mailbox and file, and the gaps that let an attacker past it.

We test for

  • MFA coverage gaps and accounts still on password-only sign-in
  • Legacy authentication and protocols that skip MFA entirely
  • Conditional access policy gaps, exclusions, and bypass paths
  • Privileged role sprawl and standing Global Administrator access
  • Guest and external-account access to internal resources

Mail security and account takeover

The controls that decide whether a phished login turns into wire fraud, and whether a spoofed sender lands in the inbox.

We test for

  • Mailbox forwarding and inbox rules that hide or exfiltrate mail
  • SPF, DKIM, and DMARC configuration and spoofing exposure
  • SMTP AUTH and legacy mail protocols still enabled
  • Anti-phishing and impersonation-protection coverage
  • Delegate, send-as, and shared-mailbox permission abuse

OAuth consent and connected apps

The third-party and internal apps granted standing access to mail and files, a foothold that survives a password reset.

We test for

  • Malicious or over-scoped OAuth app consent grants
  • User consent settings that let any app request broad access
  • Service principals and enterprise apps with excessive permissions
  • Stale, unused, and unverified connected applications
  • App-based persistence that outlasts credential changes

File sharing and collaboration

The sharing defaults that quietly expose customer data through a link, a guest, or an over-shared site.

We test for

  • Anonymous and organization-wide sharing links
  • External and guest access across SharePoint, OneDrive, and Teams or Drive
  • Over-permissioned sites, shared drives, and Teams
  • Sensitive data reachable by guests and external users
  • Link expiration, download, and re-sharing controls

Logging, monitoring, and detection

Whether the tenant would even record the attack, and whether anyone would be alerted in time.

We test for

  • Unified or admin audit log coverage and retention
  • Mailbox auditing enabled across accounts
  • Alerting on risky sign-ins, consent grants, and rule changes
  • Sign-in and risk policy coverage
  • Gaps that would hide an account takeover in progress

Attack simulation from a compromised user

The attack-simulation tier: an assumed-breach start from one ordinary account, to prove how far a real phished login reaches.

We test for

  • Password spray and token or session theft (adversary-in-the-middle)
  • OAuth consent phishing against the tenant, with written authorization
  • Mailbox, SharePoint, and Teams data an ordinary user can reach
  • Privilege escalation from a standard user toward admin roles
  • Paths from the tenant toward on-premises Active Directory through a hybrid Entra Connect link

Pricing

Configuration review or attack simulation

The first tier asks whether the tenant is configured safely. The second proves what a real phished login can do.

Configuration review

Identity, mail, sharing, OAuth, and logging reviewed by hand against the CIS benchmark, for one tenant of up to 250 users: $4,200. It shows where the gaps are before an attacker finds them.

With attack simulation

The review plus an assumed-breach start from one compromised standard user: password spray, token or consent theft, the data that user can reach, and escalation toward admin. Also the tier for 251 to 1,000 users, or a hybrid link to on-premises Active Directory: $6,800.

Larger environments

Several tenants or domains, more than 1,000 users, in-depth pivots into on-premises Active Directory, or E5 workloads such as Defender, Purview, and Intune, quoted from the scope and still fixed before work begins.

Google Workspace is tested the same way, at the same prices. When a phished user is the concern, pair this with a phishing simulation to measure who clicks in the first place.

The walkthrough

From one phished user to wire fraud

Business email compromise rarely needs an exploit. An attacker phishes one set of credentials, relays the MFA prompt with an adversary-in-the-middle kit, and signs in. From there they read the inbox for an invoice thread, add a quiet forwarding rule so the victim never sees the replies, and send a payment-detail change from the real account. No malware, no alert, and the money is gone before anyone notices.

The attack-simulation tier follows that exact path from an account you designate, with written authorization, and stops at proof. The report shows which control would have broken the chain: phishing-resistant MFA, a conditional access policy, mailbox rule alerting, or tighter OAuth consent. Our Evilginx explainer describes the token-theft step in detail.

The fraud follows the money. In construction, the bank-detail change arrives days before a pay application is funded; at private equity firms, it rides on capital calls and closing wires. Both pages show how the test is scoped around those payment workflows.

Methodology

Microsoft 365 security assessment methodology

Full methodology →

Every engagement follows the Penetration Testing Execution Standard and the relevant OWASP guides.

These are the phases your Microsoft 365 security assessment runs through.

  1. 01

    Scope & read-only access

    One tenant, a Global Reader or read-only admin role, and the fixed price agreed in writing. Nothing in the tenant is changed.

  2. 02

    Identity & configuration review

    Entra ID or Google identity, conditional access, roles, and settings reviewed by hand and benchmarked against CIS.

  3. 03

    Mail, sharing & app review

    Forwarding rules, mail authentication, external sharing, and OAuth consent examined for the paths an attacker uses.

  4. 04

    Attack simulation

    On the attack-simulation tier, an assumed-breach start from one standard user, proving how far a phished login reaches.

  5. 05

    Report & retest

    A benchmarked report, an attestation letter, and a free retest once your fixes ship.

How it works

How your engagement runs

From scope through the final retest, your team stays in the loop at every step, with findings tracked live in our platform.

  1. 01

    Scope & kickoff

    Targets, roles, and rules of engagement defined in writing, with a fixed scope and timeline.

  2. 02

    Testing goes live

    Findings post to your live platform dashboard the moment our testers confirm them.

  3. 03

    Track remediation

    Follow every finding from open to fixed, with severity, evidence, and status in one place.

  4. 04

    Report & retest

    Executive and technical reports land, then request a free retest in one click.

Proof

Proof in the field

Every engagement is confidential, so the work below is anonymized to sector and engagement type.

All case studies →

Free

Retest on every penetration test

185+

Years combined experience

14

Senior in-house specialists

24h

Onboarding after signing

Fintech · Payments

Web Application Penetration Test

High risk

Critical: a remote code execution flaw in the application’s web framework that could have given an attacker full control of the server. We escalated it to the development team while the test was still running.

Outcome. The critical RCE was reported and remediated during the engagement via an emergency framework upgrade, which also closed the server-side request forgery, and the remaining findings were retested to confirmation.

1

Critical (RCE)

Mid-test

Critical remediated

2

High

Read the case study

HR & Payroll SaaS

Web Application Penetration Test

High risk

Critical: a file-inclusion flaw that let an attacker read sensitive files from the server through the application itself. High: stored cross-site scripting capable of session theft, insecure direct object references, and an authorization bypass that let an administrator create or delete organization owners.

Outcome. Delivered a remediation plan sequenced by real business impact, critical and high findings first, with a complimentary retest to verify every fix.

28

Findings

1

Critical

5

High

Read the case study

FAQ

Frequently asked questions

What teams most often ask before scoping Microsoft 365 security assessment.

Still have questions? 
01What is a Microsoft 365 security assessment?

It is a manual review of how your Microsoft 365 tenant is configured and what a compromised account could reach: identity and MFA, conditional access, mailbox forwarding and inbox rules, mail authentication (SPF, DKIM, DMARC), external sharing across SharePoint, OneDrive, and Teams, OAuth app consent, and audit logging. Every finding is verified by hand and benchmarked against the CIS Microsoft 365 Foundations Benchmark, not just exported from Secure Score.

02Do you test Google Workspace too?

Yes, the same way and at the same prices. Google identity and Google Workspace roles stand in for Entra ID, Gmail security and forwarding for Exchange Online, and Drive external sharing for SharePoint and OneDrive. Findings are benchmarked against the CIS Google Workspace Foundations Benchmark and reported in the same format.

03What access do you need, and is it read-only?

A Global Reader role in Microsoft 365, or an equivalent read-only admin role in Google Workspace. It lets us review every setting, policy, mailbox rule, and app consent without changing anything. The attack-simulation tier also needs one standard test account we can start from, which you designate, so the assumed-breach test never touches a real employee without your say-so.

04What is the difference between the configuration review and the attack simulation?

The configuration review, from $4,200, checks that the tenant is set up safely: it finds the gaps in MFA, conditional access, sharing, and app consent before an attacker does. The attack simulation, from $6,800, adds an assumed-breach start from one compromised standard user and proves what a real phished login can do, from password spray and token theft to the data that account can reach and escalation toward admin roles. Start with the configuration review if the tenant has never been checked. Choose the simulation if you have already had a takeover attempt or need proof of impact.

05Do you need Microsoft or Google approval to test our tenant?

Not from Microsoft. Its security testing rules of engagement let you test your own tenant without asking first, provided the work stays inside it: no denial-of-service testing, no access to other customers’ data, and no phishing of Microsoft employees. The same Microsoft rules cover Azure subscriptions, which our Azure penetration testing guide walks through. For Google Workspace, the work stays within Google’s terms and acceptable use policy. On either platform, the configuration review only reads settings through an admin role you grant, and we confirm the provider’s current rules during scoping.

06Will our users notice?

The configuration review is read-only and invisible to users. The attack simulation is coordinated with a small control group on your side, runs from the account you designate, and only phishes your own users where you authorize it in writing. Nothing is destructive, and captured credentials or tokens are handled under NDA and destroyed after the retest.

07How much does it cost?

The configuration review is $4,200 for one tenant of up to 250 users, fixed before work begins, with a free retest. Adding the attack simulation from a compromised user, or a tenant of 251 to 1,000 users, is $6,800. Several tenants, more than 1,000 users, or E5 workloads reviewed in depth are quoted after scoping. Google Workspace is priced the same. Our Microsoft 365 assessment cost page explains what moves the price.

08Does this help with business email compromise and cyber insurance?

Directly. Business email compromise is one of the most common attacks on a Microsoft 365 or Google Workspace tenant, and it turns on MFA coverage, mailbox rule monitoring, and OAuth consent, which are exactly what this assessment reviews. The report also answers the MFA-enforcement and email-security questions on cyber-insurance applications and renewals, and the attestation letter gives your broker independent evidence.

Ready to test your defenses?

Talk to our team about scoping Microsoft 365 security assessment.

Prefer the full scoping questionnaire? 

Get a Fixed-Scope Quote

Tell us what you need tested. We reply within one business day.