# maester365/maester

Maester is a test automation framework to help you stay in control of your Microsoft security configuration.

Repository: https://github.com/maester365/maester
Canonical: https://ross.abutalabs.com/products/maester
Homepage: https://maester.dev
Language: HTML
License: MIT
License Family: permissive
Topics: devops, entra, microsoft-365, microsoft-graph, config-as-code, configuration-management, cybersecurity
Last push: 2026-09-03T00:48:13+00:00

## Health v2 (maintenance only)
Score: 88/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 100, release rhythm 83, longevity 72
- inputs: {"age_days": 1021, "days_push": 0, "days_rel": 37, "gap_med": 86, "n_releases_24m": 8}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1080, forks 278 (observed 2026-09-03T02:15:14.648451+00:00)

## What it is
Maester is a PowerShell-based test automation framework that monitors and validates the security configuration of Microsoft 365 and Entra ID tenants. It ships 360+ built-in tests mapped to compliance baselines (CISA SCuBA, CIS, EIDSCA, ORCA) and runs them via Pester in CI/CD pipelines or locally.

## Use cases
- audit my microsoft 365 tenant security configuration
- run CISA SCuBA baseline tests against Entra ID
- monitor conditional access policy drift in CI
- test m365 security posture as code with Pester
- check Exchange Online configuration against ORCA baseline
- generate security compliance reports for Microsoft 365

## When to choose
- you manage a Microsoft 365 or Entra ID tenant and want automated security configuration checks
- you need to prove compliance against CISA, CIS, EIDSCA, or ORCA baselines
- you want security tests running in GitHub Actions, Azure DevOps, or GitLab pipelines
- you want to write custom Pester tests for your own tenant policies

## When to avoid
- your infrastructure is not Microsoft-centric (AWS, GCP, on-prem Linux)
- you need runtime threat detection or SIEM rather than configuration auditing
- you want a GUI-only tool without PowerShell familiarity

## Facets
- artifact type: framework
- maturity: active
- function: testing, security, monitoring, configuration-management, ci-cd, cli
- domain: security, cloud-computing, legal
- platform: cli, windows, cloud
- tags: powershell, microsoft-365, entra-id, pester, security-posture, compliance-baselines, cisa-scuba, cis-benchmark, conditional-access, microsoft-graph, devops, automation, macos, linux, docker

## Member repositories
- maester365/maester (main) score 88

## Provenance
- Observed fields: from GitHub, fetched 2026-09-03T02:15:14.648451+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T06:53:37.441050+00:00, confidence not recorded.
  - readme: https://github.com/maester365/maester (fetched 2026-09-03T02:15:14.648451+00:00, sha a677f348b387)
  - homepage: https://maester.dev (fetched 2026-08-29T12:55:36.296530+00:00, sha 742f84576f99)
  - site_page: https://maester.dev/docs/intro (fetched 2026-08-29T12:55:36.306230+00:00, sha d7b256175232)
  - site_page: https://maester.dev/docs/next/intro (fetched 2026-08-29T12:55:36.308133+00:00, sha e7c990ffbb12)
  - site_page: https://maester.dev/docs/tests (fetched 2026-08-29T12:55:36.309998+00:00, sha 9fb6f1310ae3)
  - site_page: https://maester.dev/docs/commands (fetched 2026-08-29T12:55:36.312758+00:00, sha 0d4f959b39e2)
  - site_page: https://maester.dev/docs/installation (fetched 2026-08-29T12:55:36.316601+00:00, sha 179e078f1014)
  - site_page: https://maester.dev/docs/tests/cisa (fetched 2026-08-29T12:55:36.318436+00:00, sha fdaff4e8e5e1)
  - site_page: https://maester.dev/docs/tests/cis (fetched 2026-08-29T12:55:36.320249+00:00, sha 5d185dde36c1)
  - site_page: https://maester.dev/docs/tests/maester (fetched 2026-08-29T12:55:36.322116+00:00, sha a5292087d817)
- Data as of 2026-08-30T08:39:29.467469+00:00.
