As of June 15, 2017, Microsoft no longer requires pre-approval to conduct a penetration test. Currently, is there anyway to have a test reviewed prior to running for liability reasons?

Peter Thurwachter (MINDTREE LIMITED) 621 Reputation points
2021-03-11T17:44:36.183+00:00

Hello, This doc https://learn.microsoft.com/en-us/azure/security/fundamentals/pen-testing states:

--------------------

As of June 15, 2017, Microsoft no longer requires pre-approval to conduct a penetration test against Azure resources. This process is only related to Microsoft Azure, and not applicable to any other Microsoft Cloud Service. Important: While notifying Microsoft of pen testing activities is no longer required customers must still comply with the Microsoft Cloud Unified Penetration Testing Rules of Engagement.

--------------------

The "Microsoft Cloud Unified Penetration Testing Rules of Engagement." states:

-------------------

Any violation of these Rules of Engagement or the relevant service terms may result in suspension or termination of your account and legal action as set forth in the Microsoft Online Service Terms. You are responsible for any damage to the Microsoft Cloud and other customers data or use of the Microsoft Cloud that is caused by any failure to abide by these Rules of Engagement or the Microsoft Online Service Terms.

-------------------

I wish to confirm the following.

So long as the "RULES OF ENGAGEMENT TO PERFORM PENETRATION TESTING ON THE MICROSOFT CLOUD" are followed, does this mean even if Microsoft Cloud and other customers data is damaged, so long as " the report is validated and is submitted to the Microsoft Security Response Center (MSRC). " Will the party running the test be protected from "You are responsible for any damage to the Microsoft Cloud and other customers data" ?

The party I am asking on behalf of is stuck in a Catch 22. They don't want to be held responsible if the penetration test breaks something, that being said this documentation and the FAQs at the bottom of the doc: https://www.microsoft.com/en-us/msrc/faqs-report-an-issue?rtc=1 all seem to apply only when after the penetration test has been performed.

Is there anyway / method of submitting a penetration test for review (I have detailed excelfile but it's in Japanese) prior to running the test inorder to protect themselves from litigation?

Thank you

Not Monitored
Not Monitored
Tag not monitored by Microsoft.
35,818 questions
0 comments No comments
{count} votes

Accepted answer
  1. JamesTran-MSFT 36,361 Reputation points Microsoft Employee
    2021-03-16T20:07:16.993+00:00

    @Peter Thurwachter (MINDTREE LIMITED)
    Thank you for your post and I apologize for the delayed response! Unfortunately, Pen testing isn't supported here on the Q&A forums.

    I wasn't able to find anyway of submitting a Pen test for review, but for this specific type of question, I'd recommend reaching out to the Microsoft Security Response Center, either by submitting an issue or providing feedback.

    Thank you for your time and patience throughout this issue.

    ----------

    Please remember to "Accept Answer" if any answer/reply helped, so that others in the community facing similar issues can easily find the solution.

    1 person found this answer helpful.
    0 comments No comments

1 additional answer

Sort by: Most helpful
  1. Peter Thurwachter (MINDTREE LIMITED) 621 Reputation points
    2021-03-16T20:10:08.4+00:00
    0 comments No comments