Security Audit/Penetration testing SharePoint

We need to do penetration and vulnerability testing in our O365 SharePoint. Ay idea how to proceed with it? I am aware that the IP will be blacklisted by Microsoft incase of penetration and vulnerability testing. However the audit is a criteria to meet. I assume there should be a way to achieve it with help of Microsoft. Any help/ideas are appreciated. Thanks

