Forum Discussion
Brian Wilson
Apr 17, 2017Copper Contributor
Azure Penetration Testing
Our firm has PaaS and IaaS resources deployed on Azure. We're undergoing a security audit by a prospective client who has asked how often Microsoft's security team conducts penetration tests of Azure systems and when the last test was performed. I have found various postings and white papers by Microsoft mentioning the internal penetration testing (https://technet.microsoft.com/en-us/security/mt346049.aspx, https://gallery.technet.microsoft.com/Cloud-Red-Teaming-b837392e), but none that give specifics that would allow us to answer the audit team's questions. Where could we find answers to these questions?
Thanks.
I would take a look at Microsoft Trust Center:
here is a link to multiple Azure compliance audit reports, including latest pen test:
2 Replies
Sort By
- Andrey Sheremetinskiy
Microsoft
I would take a look at Microsoft Trust Center:
here is a link to multiple Azure compliance audit reports, including latest pen test:
- William ArnoldCopper Contributor
Most recent penetration testing report is from early 2016 - I would like to see these produced more often (even in our on-premise solutions, we produce these quarterly).