Azure App Service

anguiz7z 0 Reputation points
2024-01-22T17:59:35.7+00:00

Hi, I would like to know whether Azure App Service infrastructure can be pentested? From network VAPT perspective. If yes - what can be scope items? If not - may I know what components shouldn't be touched?

Azure App Service
Azure App Service
Azure App Service is a service used to create and deploy scalable, mission-critical web apps.
8,490 questions
{count} votes

2 answers

Sort by: Most helpful
  1. Grmacjon-MSFT 18,896 Reputation points
    2024-01-23T21:18:49.7833333+00:00

    Hello @anguiz7z , the short answer is yes.

    Azure App Service infrastructure can be penetration tested. Microsoft allows customers to perform their own penetration tests on their Azure resources without prior approval.

    However, there are certain rules of engagement that must be followed. Here are some common types of penetration tests that are allowed:

    • Testing for Open Web Application Security Project (OWASP) vulnerabilities.
    • Endpoint fuzz testing—trying random inputs to find vulnerabilities.

    However, one type of penetration test that you can’t perform is any kind of Denial of Service (DoS) attack. This includes initiating a DoS attack itself, or performing related tests that might determine, demonstrate, or simulate any type of DoS attack It’s important to note that while Microsoft no longer requires pre-approval to conduct a penetration test against Azure resources, customers must still comply with the Microsoft Cloud Unified Penetration Testing Rules of Engagement If you’re unsure about the scope of your penetration test or need further guidance, I recommend reviewing the Azure Penetration Testing Rules of Engagement documentation.

    -Grace

    0 comments No comments

  2. SnehaAgrawal-MSFT 22,346 Reputation points
    2024-01-24T02:58:44.7333333+00:00

    @anguiz7z Thanks for reaching here! Yes you can perform your own pentests –

    Suggest you to review information at Microsoft Cloud Penetration Testing Rules of Engagement for constraints on expected behavior. Hope this helps,

    Let us know if further query or issue remains.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.