By EJN Labs · 10 Jul 2026 · 9 min read
Azure penetration testing is a manual security assessment of your Microsoft Azure tenant, focused on identity, configuration and architecture rather than Microsoft’s own infrastructure. Testers examine Entra ID, role assignments, network controls, storage and application services to find privilege escalation and exposure paths. Microsoft permits customer-side testing without prior approval under its Unified Penetration Testing Rules of Engagement. Our Microsoft Azure penetration testing services are delivered by UK-based, CREST-certified testers at a CREST-accredited company, with a fixed quote agreed before work begins.
Moving to Azure does not remove the need for security testing; it changes where the risk sits. Under the shared responsibility model, Microsoft secures the physical data centres, the hypervisor and the platform services, while you remain responsible for identities, access policies, network segmentation, data and how services are configured. Azure penetration testing assesses that customer-owned layer, where almost every real-world cloud breach originates.
Azure penetration testing at a glance
| Typical duration | 3–4 days at small scale, 4–5 at growth scale, 5–8 at enterprise scale (single provider) |
| Pricing | One fixed price per scope; published tiers from £4,500; UK market day rates £1,100 to £1,400 |
| Deliverables | Technical and executive report, proof-of-concept evidence, letter of attestation, free retest |
| Accreditation | CREST-accredited company; UK-based, CREST-certified testers; ISO 27001 and ISO 9001 |
| Microsoft permission | Not required for your own resources under the Unified Penetration Testing Rules of Engagement |
| Scheduling | Fixed quote within one working day; signed scope to active testing fast-tracked where an incident or audit deadline requires it |
What Azure penetration testing covers and what it does not
Azure penetration testing covers your configuration and your data plane, and it does not cover Microsoft’s underlying platform. It is the structured, manual assessment of a Microsoft Azure environment to find misconfigurations, weak identity controls and architectural flaws that an attacker could exploit.
Testing the shared infrastructure, attempting denial of service against Azure services, or probing other tenants is prohibited and serves no purpose, because that layer is Microsoft’s responsibility.
A representative scope includes Microsoft Entra ID (the identity service formerly delivered as Azure Active Directory), where testers review conditional access, multi-factor authentication coverage, legacy authentication, guest accounts and application registrations. It also covers role-based access control across subscriptions and resource groups, where over-privileged service principals and standing Owner or Contributor rights are common, alongside network security groups, exposed management ports, peering, storage accounts, key vaults, Azure SQL, App Service, Azure Functions and any externally reachable application. The goal is to map how an attacker who gains an initial foothold could escalate privilege and reach sensitive data.
Permissions: what Microsoft allows you to test
One of the most common questions about Azure penetration testing is whether you need Microsoft’s prior approval. For testing your own resources, you generally do not. Microsoft publishes a Unified Penetration Testing Rules of Engagement that permits customers to test their own deployments without submitting a notification in advance, provided you stay within the stated boundaries. This is a change from years ago, when written sign-off was required, so a scoped engagement can usually begin without waiting on a third party.
The permitted activities include port scanning your own endpoints, testing your applications and APIs hosted on Azure, assessing your Entra ID configuration, and attempting to exploit vulnerabilities in resources you own. The prohibited activities are equally clear: no denial-of-service or load testing without Microsoft’s separate process, no testing of assets belonging to other customers, no attempts against the shared Azure fabric or Microsoft-operated services, and no social engineering of Microsoft staff. Services such as Azure DevOps or third-party marketplace software carry their own terms that need checking before scope. A reputable provider confirms these boundaries in the rules of engagement document and obtains your written authorisation as the tenant owner before any work begins.
The method: how a professional Azure test is run
A credible Azure penetration test follows a repeatable methodology aligned to industry standards and the discipline that underpins CREST-accredited work. The phases below are what our CREST-certified testers follow on every cloud engagement.
Scoping and access provisioning. Testing starts by agreeing the subscriptions, resource groups and identities in scope, then provisioning the access required. A configuration review uses a read-only Security Reader or Global Reader role to enumerate the tenant, while an authenticated assessment uses a low-privileged test account to model an attacker who has compromised an ordinary user.
Identity and Entra ID assessment. Because identity is the new perimeter in cloud, this is the centre of gravity for most engagements. Testers review conditional access for gaps, check whether legacy authentication remains enabled, look for accounts and service principals without multi-factor authentication, examine application and API permissions for excessive consent, and assess privileged role assignments. The objective is to find how a single compromised credential becomes tenant-wide control.
Configuration and privilege escalation. The tester maps role-based access control across the estate to identify over-privileged principals, dangerous custom roles and standing administrative rights that should be just-in-time. They examine managed identities, automation accounts and the ways a foothold on one resource can be pivoted into another through misconfigured permissions. Public exposure of storage accounts, key vaults and databases is verified, alongside secrets hygiene.
Network and application surface. Network security groups, exposed management ports, public endpoints and peering relationships are assessed for unnecessary exposure, and any externally reachable application or API is tested for the usual web and API weaknesses, because a vulnerable App Service is frequently the entry point that the identity findings then amplify.
Reporting and retest. Every confirmed issue is documented with a clear description, a reproducible proof of concept, a severity rating and remediation guidance mapped to Azure controls. Once your team has applied the fixes, a retest validates the work at no additional cost so you can evidence closure to an auditor, customer or your own board.
Common findings in Azure environments
Across UK Azure tenants, the same weaknesses recur. Over-privileged identities are the dominant issue: service principals granted Contributor or Owner at subscription scope, human accounts holding standing administrative roles instead of just-in-time access through Privileged Identity Management, and automation accounts with more reach than their task requires. Weak conditional access follows close behind, with policies that exempt too many accounts, fail to block legacy authentication, or leave privileged roles without phishing-resistant multi-factor authentication. Exposed storage and secrets remain stubbornly common, from publicly reachable storage accounts and unrestricted key vaults to credentials hard-coded into App Service configuration. Misconfigured network controls and insecure application services then provide the initial foothold, after which the identity findings turn a single compromise into a tenant-wide incident.
How much Azure penetration testing costs in the UK
Azure penetration testing in the UK is priced by tester days, typically at a day rate of £1,100 to £1,400, not from a per-resource menu. A single-subscription tenant with a tidy identity model takes a few days, while a multi-subscription estate with many applications takes longer.
Effort is driven by scope complexity: the number of subscriptions, the size of the Entra ID tenant, the count of in-scope applications, and whether the engagement is a configuration review, an authenticated assessment or both. Complex role assignments also add time.
As a guide, a single-provider cloud engagement is £4,500 to £8,000 at small scale, £8,000 to £14,000 at growth scale and £14,000 to £22,000 at enterprise scale, quoted as one scope-based fixed price rather than a day-rate bill; see the published tiers on the pricing page. For how day counts translate into project pricing, see our guide to penetration testing cost in the UK. A flat low price for a cloud review usually signals an automated scan rather than a manual test.
How EJN Labs approaches Azure penetration testing
EJN Labs is a CREST-accredited UK penetration testing firm, and every Azure engagement is delivered by UK-based, CREST-certified testers. Our cloud work is aligned to Microsoft’s Unified Penetration Testing Rules of Engagement and to recognised cloud security benchmarks. We are also certified to Cyber Essentials, Cyber Essentials Plus, ISO 27001 and ISO 9001, so our evidence stands up to auditor and procurement scrutiny.
We price by scope complexity with a fixed quote agreed before work begins, and every test ends with a report your team can act on plus a free retest once your fixes are in place. You can see how Azure testing sits within our cloud penetration testing service and our services overview, or request a scoped quote through our CREST pen testing quote form.
Frequently Asked Questions
Do I need Microsoft’s permission to run an Azure penetration test?
No, you generally do not need Microsoft’s permission or advance notification to test your own Azure resources. Microsoft’s Unified Penetration Testing Rules of Engagement permit customers to test their own deployments, provided the work stays within the stated boundaries that the rules set out.
Those boundaries exclude denial-of-service testing, other tenants and the shared Azure platform. As the tenant owner, you still authorise the work in writing before testing begins.
What is the difference between an Azure configuration review and a penetration test?
A configuration review reports misconfigurations, a penetration test proves they can be exploited. The review enumerates your tenant from a read-only role and compares settings against best practice, while an Azure penetration test actively exploits weaknesses to demonstrate the real impact an attacker could achieve.
The review is valuable but passive. Exploitation goes further, chaining identity gaps and privilege escalation to show what a genuine compromise would mean. Many engagements combine both. If you want the review as a standalone engagement, see our Azure cloud security review.
Can a vulnerability scanner replace an Azure penetration test?
No, a vulnerability scanner cannot replace an Azure penetration test. Automated cloud posture tools flag misconfigurations, but they cannot reason about how a single compromised account escalates to tenant-wide control, and they cannot confirm which findings are genuinely exploitable in your specific architecture.
A scan is still a useful supporting input, but only a manual test provides the exploitation evidence that auditors, customers and boards expect.
What access do you need to test our Azure tenant?
It depends on the scope. A configuration review needs a read-only role such as Security Reader or Global Reader, while an authenticated assessment that models a compromised user needs a low-privileged test account. We agree the exact access model at scoping, and we never require standing administrative rights.
How long does an Azure penetration test take?
Three to four testing days is typical for a focused assessment of a single-subscription tenant with a tidy identity model, with the report delivered shortly after testing finishes. Larger estates with multiple subscriptions or complex role assignments take longer, because duration scales with the size and complexity of the environment.
We confirm the exact duration at scoping, so you have a fixed timeline and a fixed price before work begins.
Do you retest after we fix the findings?
Yes. A retest is included at no additional cost. Once your team has addressed the reported issues, our testers verify the fixes and issue an updated report confirming closure, which you can share with auditors, customers or your ISO 27001 assessor as evidence.
Get a scoped Azure penetration testing quote
If you are ready to assess your Microsoft Azure tenant against identity, configuration and architecture risks, our CREST-certified testers can scope the work and provide a fixed price. Request a tailored quote through our CREST pen testing quote form, or explore our cloud penetration testing service first.




Leave a Reply