Ready-made tests
Hundreds of curated tests covering identity, access, devices and apps — ready to run on day one.
A very common reason is a wrong site baseUrl configuration.\n Current configured baseUrl = / (default value)\n We suggest trying baseUrl = \n\n',document.body.prepend(n);var e=document.getElementById("__docusaurus-base-url-issue-banner-suggestion-container"),s=window.location.pathname,o="/"===s.substr(-1)?s:s+"/";e.textContent=o}document.addEventListener("DOMContentLoaded",(function(){void 0===window.docusaurus&&insertBanner()}))
Your Microsoft Security test automation framework! — Maester turns Microsoft security best practices into runnable tests so you can make changes with confidence and prove compliance over time. One framework, hundreds of tests, every change validated. Maester is how modern teams keep Microsoft 365 secure as it evolves. Hundreds of curated tests covering identity, access, devices and apps — ready to run on day one. Run regression tests before you change a Conditional Access policy. Catch loopholes before attackers do. Schedule Maester in GitHub Actions, Azure DevOps or Azure Automation. Get alerts when posture drifts. Built on Pester and Microsoft Graph. Encode your own business and security policies as code. Every test ships with remediation steps and direct links into the Microsoft admin portals. EIDSCA, CISA SCuBA, CIS Microsoft 365 and ORCA — all wired into a single test framework. Run the suites you care about — community best practices and the major Microsoft 365 compliance baselines, all in one place. US CISA Secure Cloud Business Applications baselines. CIS Microsoft 365 Foundations Benchmark v3.1.0. Best-practice tests curated by the Maester community. Entra ID Security Config Analyzer baseline. Office 365 Recommended Configuration Analyzer. Install the PowerShell module, connect to Microsoft Graph and get an interactive HTML report of your tenant's posture. Maester exists to make cloud security testing open, reusable and accessible. The core framework and its tests will remain free, open source and community driven.
Test automation for your Microsoft 365 security posture

Security as code, for the Microsoft cloud
Ready-made tests
Confidently make changes
Continuous monitoring
Easy to customize
Configuration guidance
Compliance baselines
Five baselines, one report
CISA SCuBA
CIS M365
Maester
EIDSCA
ORCA
Security as Code (SaC)
Apply modern DevSecOps practices and continuously monitor critical aspects of your Microsoft cloud.

Conditional Access What-If
Identity is the new control plane! Create iron-clad tests to ensure your tenant's posture is always secure as your access policies evolve.

Maester Test Framework
Quickly set up Maester in your environment by following the step-by-step guides we've built for you.
Bring the ease of writing tests in PowerShell to your Microsoft 365 tenant with Maester!

🔥 Maester Test Reports
The interactive click-through report lets you drill down to the details of
each test.

Quick remediation
Jump straight into the conditional access policy that needs to be fixed or the group that needs to be reviewed.

40+ EIDSCA Tests
EIDSCA is a part of the Microsoft Entra ID - Attack and Defense Playbook and is a collection of common attack scenarios on Microsoft Entra ID and how they can be mitigated.

Maester ❤️ GitHub
Build an archive history of Maester test runs against your tenant with the native
workflow integration in Maester.
Use Workload Identify Federation for your automation account to connect to Microsoft Graph (no more secrets or credential rotation!).
Maester 💛 Azure DevOps
Follow the step-by-step guide in the Maester docs to set up
an automation account with Workload Identify Federation.
Email Alerts
Get notified when a change is introduced in your Microsoft 365 tenant
that affects the security configuration.
Run your first Maester test in under a minute

Security guidance should be executable and available to everyone.