OneClickComply
    Back to BlogPenetration Testing

    Penetration Testing Microsoft 365: What to Buy in 2026

    26 August 2026
    Penetration testing for Microsoft 365 and cloud email

    TL;DR

    • Penetration testing microsoft 365 needs to cover OAuth phishing, mailbox rule abuse, and conditional access gaps, not just external port scans.
    • Cyber Essentials checks MFA and patching; ISO 27001 auditors usually want a documented pen test on top. Buy both.
    • A focused identity and email test beats a generic automated scan for catching business email compromise paths. Buy the manual test.
    • Skip any tester who scopes your Microsoft 365 test without asking about conditional access policies first.

    Penetration testing microsoft 365 checks whether your email, SharePoint, Teams, and identity setup can survive a real attacker — not a checkbox scan that flags nothing but missing patches.

    Why this matters

    Microsoft 365 is where most UK SMEs actually get breached — not the firewall, the mailbox. Attackers don't need to hack your network when they can phish a login, register a rogue OAuth app, and set up a forwarding rule that quietly copies invoices to an external address.

    A generic penetration test built for on-premise networks misses all of that. Before you buy one, read how to scope a penetration test before you buy one — the scoping conversation is where most Microsoft 365 tests either earn their fee or waste it.

    Microsoft's own published data puts multi-factor authentication at blocking well over 99% of automated account-takeover attempts. That's exactly why testers who ignore identity configuration and go straight to a network scan are checking the wrong box in 2026.

    Who this is for

    This guide is for UK SMEs running most of their operations through Microsoft 365 — email, file storage, Teams calls, and increasingly, line-of-business apps bolted on through OAuth connectors. You're likely chasing Cyber Essentials Plus, working toward ISO 27001, or answering a client security questionnaire that asks when your last penetration test happened.

    If your business has under 250 seats, no in-house security engineer, and a Microsoft 365 tenant that's grown ad hoc over three or four years, this is written for you.

    What to look for in penetration testing for Microsoft 365 and cloud email

    Identity and conditional access coverage

    A proper test attacks your sign-in flow, not just your inbox. Testers should attempt password spraying, review your conditional access policies for gaps, and check whether legacy authentication protocols are still enabled — a common miss that bypasses MFA entirely.

    OAuth and third-party app risk

    Every Teams add-in and connected app is a door into your tenant. Good testers enumerate registered OAuth applications and flag any with excessive Graph API permissions — this is how attackers persist after a phished credential gets reset.

    Mail flow and rule abuse

    Business email compromise almost always involves a hidden inbox rule that forwards or deletes messages silently. Ask whether the test includes a review of mailbox rules, transport rules, and external forwarding settings across your tenant.

    SharePoint and OneDrive external sharing

    Over-permissioned anyone-with-the-link shares are the quiet leak most SMEs never audit. A tester should map external sharing settings and flag any sites or libraries exposed beyond your domain.

    Reporting mapped to your certification

    If the test feeds into ISO 27001 or Cyber Essentials Plus, the report needs to map findings to specific Annex A controls or NCSC requirements — not just a generic severity list. Learn how to interpret a penetration testing report before you sign off on one.

    Retest and remediation window

    A test that ends with a PDF and no retest is half a service. Confirm the provider includes a remediation window and a follow-up check, not a one-and-done engagement.

    Where to start: four engagement types

    The baseline check — email and identity review

    A scoped review of conditional access, MFA enforcement, and legacy auth protocols across your tenant. Typically runs over 1-2 days and suits businesses that have never had a cloud-focused test. Buy if this is your first Microsoft 365 assessment.

    The deep dive — full tenant simulation

    Simulates a phished credential end to end: sign-in, OAuth app registration, mailbox rule creation, and data exfiltration through SharePoint. This is the version auditors expect for ISO 27001 Annex A control testing. Buy if you're certifying against ISO 27001 or need evidence for a client questionnaire in 2026.

    The wildcard — social engineering plus technical test

    Combines a phishing simulation against staff with a technical test of what happens after someone clicks. Useful if your last security awareness training showed weak click-through numbers. Consider it if you haven't run a phishing simulation in over 12 months.

    The bolt-on — automated vulnerability scan only

    A scheduled scan against your tenant's external footprint with no manual identity or mailbox testing. Cheap, fast, and shallow. Skip it if the output you actually need is evidence for Cyber Essentials Plus or an auditor's control walkthrough — check how to budget for penetration testing as a UK SME before you settle for the cheapest quote.

    Turn pen test evidence into certification

    OneClickComply automates the evidence collection ISO 27001 and Cyber Essentials auditors ask for.

    What to avoid

    • Generic pentest packages with no Microsoft 365 scope line. If the statement of work doesn't name conditional access, OAuth apps, or mailbox rules, it's a network test wearing a cloud label.
    • Providers who won't share a sample report before you buy. You need to see whether findings map to Annex A controls or NCSC guidance before committing, especially if an auditor is waiting on the output.
    • A one-off test with no renewal cadence. Cyber Essentials Plus needs re-certification every 12 months, and a tenant that changes weekly needs testing more often than a network that doesn't.

    Verdict comparison

    Engagement typeBest forTypical durationVerdict
    Baseline email and identity reviewFirst-time testers, small tenants1-2 daysBuy
    Full tenant simulationISO 27001 evidence, client questionnaires3-5 daysBuy
    Social engineering + technical testWeak phishing click-through history2-3 daysConsider
    Automated scan onlyNothing beyond a compliance tick-boxHoursSkip

    If your provider list is thin, start with best penetration testing companies for UK small businesses rather than picking the first agency that emails back.

    Frequently asked questions

    One last thing

    The single biggest finding across Microsoft 365 tenant tests isn't a missing patch — it's a forgotten mailbox forwarding rule set up months earlier by a compromised account that nobody removed. Check your own tenant's inbox rules today; you don't need a tester to do that part.

    Seriously Simple Cyber Compliance means the evidence from a test like this doesn't sit in a PDF nobody reads. OneClickComply turns it into the audit trail your certification actually needs in 2026.

    A penetration test that ignores your conditional access policy isn't testing Microsoft 365 — it's testing a network that doesn't exist anymore.