Ready-made tests
Hundreds of curated tests covering identity, access, devices and apps โ ready to run on day one.

Your Microsoft Security test automation framework! โ Maester turns Microsoft security best practices into runnable tests so you can make changes with confidence and prove compliance over time.

One framework, hundreds of tests, every change validated. Maester is how modern teams keep Microsoft 365 secure as it evolves.
Hundreds of curated tests covering identity, access, devices and apps โ ready to run on day one.
Run regression tests before you change a Conditional Access policy. Catch loopholes before attackers do.
Schedule Maester in GitHub Actions, Azure DevOps or Azure Automation. Get alerts when posture drifts.
Built on Pester and Microsoft Graph. Encode your own business and security policies as code.
Every test ships with remediation steps and direct links into the Microsoft admin portals.
EIDSCA, CISA SCuBA, CIS Microsoft 365 and ORCA โ all wired into a single test framework.
Run the suites you care about โ community best practices and the major Microsoft 365 compliance baselines, all in one place.
Best-practice tests curated by the Maester community.
170+ testsEntra ID Security Config Analyzer baseline.
60+ testsUS CISA Secure Cloud Business Applications baselines.
70+ testsCIS Microsoft 365 Foundations Benchmark v3.1.0.
60+ testsOffice 365 Recommended Configuration Analyzer.
Exchange OnlineInstall the PowerShell module, connect to Microsoft Graph and get an interactive HTML report of your tenant's posture.








