Azure Red Team Certification (MCRTP)

Azure Red Team Certification (MCRTP) at a glance
- Format: Hands-on, assessed in a live Azure and Microsoft 365 tenant
- Focus: Entra ID abuse, OAuth and consent attacks, lateral movement
- Level: Professional
- Prerequisites: a general security foundation (no prior Azure expertise required)
- Delivered via: the Microsoft Cloud Attack and Defense bootcamp
Azure Red Team Certification (MCRTP) is earned through the Microsoft Cloud Attack and Defense bootcamp, an instructor-led Pwned Labs program that goes deep on modern attack chains and the detections that catch them, then certifies you hands-on.
Attackers rarely break into Microsoft cloud environments by exploiting a server. They sign in. Identity is the perimeter in Azure and Microsoft 365, and an Azure red team certification worth holding should prove you can abuse that identity layer the way a real intrusion does. The Microsoft Cloud Red Team Professional (MCRTP) is built to test exactly that, hands-on, in live tenants.
What the MCRTP certification proves
MCRTP is a practical Azure and Microsoft 365 red team certification. Instead of a multiple choice exam, you are assessed inside a live Microsoft cloud environment with realistic misconfigurations and logging. You have to enumerate Entra ID, find a foothold, escalate, and move laterally across Azure and M365 to reach the objective. Passing means you demonstrated tradecraft against a real tenant, which is a far stronger signal to an employer than a knowledge test.
Who this certification is for
MCRTP suits penetration testers expanding into Microsoft cloud, red teamers who need Entra ID and M365 depth, and defenders who want to understand attacker tradecraft to build better detections. Prior Azure expertise is not required. The Microsoft Cloud Attack and Defense bootcamp that leads into MCRTP starts with fundamentals and builds toward advanced identity attacks, so a strong general security background is enough to begin.
What you learn on the path to MCRTP
The curriculum follows how Microsoft cloud tenants are actually compromised, with identity at the center. Core areas include:
- Entra ID enumeration and abuse, including role and application permission misconfigurations that lead to privilege escalation.
- Consent and OAuth application attacks, token theft, and abuse of conditional access gaps.
- Lateral movement between Microsoft 365 workloads and Azure resources, and pivoting from cloud identity into subscriptions.
- Abusing Azure services and hybrid join scenarios that connect on-premises Active Directory to Entra ID.
- Detection awareness across Microsoft Entra sign-in logs, unified audit logging, and Microsoft Defender signals.
Working against production-like telemetry means you learn what defenders can see while you operate, which is the purple team perspective that makes a cloud red teamer valuable.
MCRTP compared to other Microsoft security certifications
The Microsoft Certified Azure Security Engineer Associate, known as AZ-500, is a defensive knowledge exam. It validates that you can implement and manage Azure security controls, and it is well regarded for blue team and engineering roles. It is not an offensive assessment and does not require you to compromise anything. Other offensive exams prove penetration testing fundamentals but cover little of the Entra ID and M365 identity abuse that dominates real Microsoft cloud intrusions. MCRTP fills that gap with a fully hands-on, offense-focused assessment specific to Azure and Microsoft 365.
How the MCRTP exam works
The certification is assessed in a live Microsoft cloud tenant, not a simulation. You receive objectives and a time window and must accomplish them with real tradecraft against real services that are logging your activity. There is no quiz and nothing to memorize. The credential is hard to fake because the only way to earn it is to execute the attack.
Related labs to build the skills first
Before committing to the certification, you can practice free starter labs for Azure that run live in your browser. They are the fastest way to test your readiness on real Entra ID and Azure attack techniques. Browse the full catalog at pwnedlabs.io/explore.
Gain career-ready skills
Employers hire for what you can do, not what you can recall. Every objective in this certification maps to a skill you will use on real engagements. By the time you certify, you can:
- Enumerate and abuse Entra ID roles, applications, and permissions
- Execute OAuth consent and token theft attacks
- Identify and exploit conditional access gaps
- Move laterally between Microsoft 365 workloads and Azure resources
- Attack hybrid join scenarios that connect on-premises Active Directory to Entra ID
- Interpret Entra sign-in logs and unified audit logging to operate with defensive awareness
These are the capabilities behind cloud penetration tester, Microsoft cloud red teamer, and cloud security engineer roles. You can build the foundations first with free hands-on labs at pwnedlabs.io/explore, then go deep and certify through the Microsoft Cloud Attack and Defense bootcamp.
Pricing and enrollment
Enrollment includes the full self-paced curriculum, lab access, and certification exam attempts. Current pricing and bundle options are shown below, and full details are on the Microsoft Cloud Attack and Defense bootcamp page.

Need employer sponsorship? Download the employer funding request letter.
Frequently asked questions
Is MCRTP a hands-on certification?
Yes. MCRTP is assessed in a live Azure and Microsoft 365 tenant with realistic misconfigurations and logging. There is no multiple choice component.
Do I need Azure experience before starting?
No prior Azure expertise is required. The bootcamp starts with fundamentals and builds toward advanced Entra ID and M365 attacks. A general security foundation is enough.
How is MCRTP different from AZ-500?
AZ-500 focuses on implementing and managing Azure security. MCRTP is an offensive, fully practical certification earned by operating in a live Microsoft cloud environment. The two complement each other well.
What is the difference between MCRTP and MCRTE?
MCRTP is the professional-level certification. The Microsoft Cloud Red Team Expert (MCRTE) is the expert-level path focused on enterprise-scale attack chains for experienced practitioners.
Does MCRTP cover hybrid Active Directory attacks?
Yes. The curriculum includes hybrid join scenarios that connect on-premises Active Directory to Entra ID, reflecting how real enterprise environments are built.
What practitioners say.
Caleb Havens
Red Team Operator & Social Engineer, NetSPI
"I’ve attended two training sessions delivered by Pwned Labs: one focused on Microsoft cloud environments and the other on AWS. Both sessions delivered highly relevant content in a clear, approachable manner and were paired with an excellent hands-on lab environment that reinforced key concepts and skills for attacking and defending cloud infrastructures. The training was immediately applicable to real-world work, including Red Team Operations, Social Engineering engagements, Purple Team exercises, and Cloud Penetration Tests. The techniques and insights gained continue to be referenced regularly and have proven invaluable in live operations, helping our customers identify vulnerabilities and strengthen their cloud defenses."
Sebas Guerrero
Senior Security Consultant, Bishop Fox
"The AWS, Azure, and GCP bootcamps helped me get up to speed quickly on how real cloud environments are built and where they tend to break from a security standpoint. They were perfectly structured, with real-world examples that gave me rapid insight into how things can go wrong and how to prevent those issues from happening in practice. I’m now able to run cloud pentests more confidently and quickly spot meaningful vulnerabilities in customers’ cloud infrastructure.”
Dani Schoeffmann
Security Consultant, Pen Test Partners
"I found the Pwned Labs bootcamps well structured and strongly focused on practical application, with clear background on how and why cloud services behave the way they do and how common attack paths become possible. The team demonstrates both sides by walking through attacks and the corresponding defenses, backed by hands-on labs that build confidence using built-in and third-party tools to identify and block threats. The red-team labs are hands-on and challenge-driven, with clear walkthroughs that explain each step and the underlying logic. I’ve seen several of these techniques in real engagements, and the bootcamp helped me develop a repeatable methodology for cloud breach assessments and deliver more tailored mitigation recommendations."
Matt Pardo
Senior Application Security Engineer, Fortune 500 company
"I’ve worked in security for more than 15 years, and every step up came from taking courses and putting the lessons into practice. I’ve attended many trainings over the years, and Pwned Labs’ bootcamps and labs are among the best I’ve experienced. When you factor in how affordable they are, they easily sit at the top of my list. As a highly technical person, I get the most value from structured, hands-on education where theory is immediately reinforced through labs. Having lifetime access to recordings, materials, and training environments means you can repeat the practice as often as needed, which is invaluable. If you’re interested in getting into cloud security, sign up for Pwned Labs.”
Steven Mai
Senior Penetration Tester, Centene
“Although my background was mainly web and network penetration testing, the ACRTP and MCRTP bootcamps gave me a solid foundation in AWS and Azure offensive security. I’m now able to take part in cloud penetration testing engagements and have more informed security discussions with my team.”