Dynamics 365 Penetration Testing

Closes in 14 daysSubmission deadline: 07 October 2026, 11:59 PM Australia/Sydney

About this tender

This Tender is invited by the Issuer. Overview The Office of the Commonwealth Ombudsman requires an independent penetration testing assessment of its Microsoft Dynamics 365 environment, including all associated web applications, customer facing portals, web forms, integrations, and supporting services. Purpose The purpose of this assessment is to identify and validate security vulnerabilities that could compromise the confidentiality, integrity, or availability of corporate information, business processes, and customer data. The engagement is intended to provide assurance that the Dynamics 365 platform and connected web assets are configured and operated in accordance with industry security best practices, evaluating the effectiveness of security controls, authentication and authorisation mechanisms, data protection measures, application security, and the resilience of internet facing components against common attack techniques. Scope The scope of testing must include Dynamics 365 applications, Power Platform components, associated web portals, online forms, APIs, integrations with external systems, and any supporting infrastructure that is accessible through the solution. The scope includes: Public Portal Authentication and MFA test (EntraID External) Authentication bypass Cryptographic configuration Abuse of account to extract other user's data Abuse of account to access higher privilege functions Input sanitisation checks Upload of malicious content, including upload of malicious files and bypass of permitted file types Information leaks Other tests as recommended by the penetration tester D365 CRM/Dataverse/SharePoint Document Store D365 permissions testing RBAC bypass testing, including being able to view cases that are not part of the user's business unit and being able to view cases with restricted access SharePoint backing store enumeration and access to files, including being able to view, access, or delete files that are not part of the user's business unit, and access to files associated with cases with restricted viewership Findings are to be documented and reported with risk ratings, evidence of exploitation where applicable, and recommendations for remediation to reduce the organisation's security risk exposure. Information Requested Vendors are requested to provide a fixed price proposal for the complete delivery of the required services. The proposed fee should cover all activities required to achieve the agreed project outcomes and deliverables.

How to respond to this tender

A strong tender response is clear, compliant, and backed by evidence. These steps apply to most Australian and New Zealand public tenders.

Read the requirements in full

Open the official listing and download the full tender pack. Note the response schedules, evaluation criteria, mandatory conditions, and the exact closing time and lodgement method.

Confirm you are eligible and it is worth bidding

Check licences, insurances, certifications, and any conformance requirements before you commit. A quick bid or no-bid decision saves days of wasted effort on a tender you cannot win.

Answer every criterion with evidence

Respond to each evaluation criterion directly and back your claims with concrete examples, referees, and past performance. Address the buyer’s stated need, not a generic capability statement.

Lodge early through the official portal

Submit through the source portal well before the deadline. Late or incorrectly lodged bids are almost always rejected, so leave time for uploads, portal errors, and last-minute questions.

Ready to write winning tenders?

Sign up today, what a relief.

Sign up