# Azure Pentesting Notes

By

# ⚠️ Rules of Engagement

Microsoft Rules of Engagements for pentesting: pentest-rules-of-engagement

The goal of this program is to enable customers to test their services hosted in Microsoft Cloud services without causing harm to any other Microsoft customers.

Even with these prohibitions, Microsoft reserves the right to respond to any actions on its networks that appear to be malicious. Many automated mitigation mechanisms are employed across the Microsoft Cloud. These will not be disabled to facilitate a penetration test.

# Technical Requirements

  • Windows Machine (10 or 11 up to date without Defender)
  • Real Account on client's Tenant, do not invite your work account as a GUEST
    • At least Global Reader
    • Tenant must have a P1 License
    • The account must be included in any subscription that is within the pentesting scope
  • Python3 + pip3
    • Add Python into your PATH during the install