Penetration Testing Hub · cyberlabs.ie

Azure & Microsoft 365 Security Checklist

Nine checks that close the biggest cloud risks — most of them configuration you already control. Do these before any professional cloud test.

Before you test — Only test cloud tenants you own or have explicit written permission to test. Unauthorised access is a criminal offence in Ireland under the Criminal Justice (Offences Relating to Information Systems) Act 2017.

Identity

MFA is enforced for every user, and especially every admin — via conditional access, not per-user toggles.
Legacy authentication is blocked tenant-wide.
Global Administrator count is minimal (single digits) and all use privileged identity management (PIM) / just-in-time access.
Service principals and app registrations are inventoried; none has more permission than it needs.

Data & sharing

No storage accounts or SharePoint sites are shared publicly by accident.
External sharing and mail-forwarding rules are reviewed and controlled.
Guest access is limited and reviewed regularly.

Monitoring

Secure Score is monitored and the high-impact recommendations are actioned.
Sign-in and audit logs are retained and someone actually reviews the alerts.
Educational, not legal advice. Test only what you own or are authorised to test.
Full guide: Cloud Penetration Testing on Azure & M365
© CyberLabs · cyberlabs.ie