Microsoft 365CIO BriefingsRetrospectives

CIO Brief: The Test Environment Nobody Remembered

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from January 2024, written in 2026 with the benefit of hindsight.

The short version: In January 2024, Russian state hackers read email of Microsoft's senior leaders. They got in through an old test account that didn't require multi-factor authentication, then used a forgotten test application with powerful access. Test environments are often less protected — and still connected to real systems.

Why test environments are a risk

Test and development environments are created quickly, often by different teams, and forgotten when projects end. They frequently have weaker security — "it's not production" — while still having links to real systems and data.

The business impact

  • Entry point to production through forgotten connections.
  • Executive email exposure.
  • Hard-to-detect access through applications rather than users.

Questions to ask your team

  • How many Microsoft 365 or cloud tenants and accounts do we have, including test and trial ones?
  • Do test environments require the same multi-factor authentication as production?
  • Do any test applications have access to production data?
  • Who is responsible for shutting down test environments when projects end?

What good looks like

A complete inventory of tenants and test environments, the same baseline security everywhere, no unnecessary links between test and production, and a process to decommission environments when projects end.

The decision

Ask for an inventory of every tenant and cloud account your organization owns. If anyone is surprised by the list, that's your first project.

midnight blizzard microsoft breach impactMidnight Blizzard breaches Microsoft2024

More on this story