CyberLabs
Penetration Testing Hub · cyberlabs.ie
Azure & Microsoft 365 Security Checklist
Nine checks that close the biggest cloud risks — most of them configuration you already control. Do these before any professional cloud test.
Before you test — Only test cloud tenants you own or have explicit written permission to test. Unauthorised access is a criminal offence in Ireland under the Criminal Justice (Offences Relating to Information Systems) Act 2017.
Identity
MFA is enforced for every user, and especially every admin — via conditional access, not per-user toggles. Legacy authentication is blocked tenant-wide. Global Administrator count is minimal (single digits) and all use privileged identity management (PIM) / just-in-time access. Service principals and app registrations are inventoried; none has more permission than it needs. Data & sharing
No storage accounts or SharePoint sites are shared publicly by accident. External sharing and mail-forwarding rules are reviewed and controlled. Guest access is limited and reviewed regularly. Monitoring
Secure Score is monitored and the high-impact recommendations are actioned. Sign-in and audit logs are retained and someone actually reviews the alerts.