Monitor your Microsoft 365 tenant's security configuration using Maester!
Maester is an open source PowerShell-based test automation framework designed to help you monitor and maintain the security configuration of your Microsoft 365 environment.
To learn more about Maester and to get started, visit Maester.dev.
- Automated Testing: Maester provides a comprehensive set of automated tests to ensure the security of your Microsoft 365 setup.
- Customizable: Tailor Maester to your specific needs by adding custom Pester tests.
- More to come...
Install-Module -Name Maester -Scope CurrentUser
md maester-tests
cd maester-tests
Install-MaesterTests .\tests
To run the tests in this folder run the following PowerShell commands. To learn more see maester.dev.
Connect-Maester
Invoke-Maester
An optional parameter, -Environment
, can be utilized on Connect-Maester
to specify the name of the national cloud environment to connect to. By default global cloud is used.
Allowed values include:
- Global (default, if parameter is not specified)
- China
- Germany
- USGov
- USGovDOD
Connect-Maester -Environment USGov
The Maester team will add new tests over time. To get the latest updates, use the commands below to update this folder with the latest tests.
- Update the
Maester
PowerShell module to the latest version and load it. - Navigate to the folder where you have your Maester tests.
- Run
Update-MaesterTests
.
Update-Module Maester -Force
Import-Module Maester
Update-MaesterTests
Maester is also published to the GitHub marketplace and can be used directly in any GitHub workflow.
Just provide the required client and tenant id. For more details please refer to the docs.
name: Maester Daily Tests
on:
push:
branches: ["main"]
# Run once a day at midnight
schedule:
- cron: "0 0 * * *"
# Allows to run this workflow manually from the Actions tab
workflow_dispatch:
permissions:
id-token: write
contents: read
checks: write
jobs:
run-maester-tests:
name: Run Maester Tests
runs-on: ubuntu-latest
steps:
- name: Run Maester action
uses: maester365/maester@main
with:
client-id: ${{ secrets.AZURE_CLIENT_ID }}
tenant-id: ${{ secrets.AZURE_TENANT_ID }}
include_public_tests: true # Optional
pester_verbosity: None # Optional - 'None', 'Normal', 'Detailed', 'Diagnostic'