Welcome to the Maester Cloud blog
A place to share the journey of building Maester Cloud. What we ship, why we built it the way we did, and what we learn as we go.
Maester started with a simple idea: security guidance for Microsoft 365 should be something you can run, not just read. Today admins around the world run Maester’s open-source tests against their tenants from laptops, GitHub Actions, and Azure DevOps pipelines.
Running the tests turned out to be the easy part. The questions that come next are harder. What changed since last week? Who turned that policy off? Is this failure new, or have we already decided to live with it? Can I show an auditor what our tenant looked like six months ago?
Maester Cloud is our answer to those questions. It keeps your Maester and Zero Trust Assessment results in a portal you run in your own Azure subscription. It keeps years of tenant history, highlights drift between runs, and tells you the moment something regresses.

The Tests page: every test, across every tenant, with what changed since the last run.
Why a blog?
We already publish release notes for every version. They tell you exactly what changed and how to update. They’re deliberately short and factual.
This blog is for everything release notes leave out:
- What we built and why. The problem a feature solves, the customer conversation that started it, and the trade-offs behind the design.
- How things work under the hood. Maester Cloud runs in your subscription, so you deserve to know what it does there. We’ll write about the architecture, the security model, and the Azure costs.
- What we’re learning. Building a commercial product around an open-source project is a balancing act. We’ll share what works, what doesn’t, and what we change because of your feedback.
Building in the open
Maester stays open source. The runner and the tests are MIT-licensed and free, and that won’t change. Maester Cloud is the commercial layer around it, and it pays for the time that goes back into the open-source project. (The manifesto has the longer version of that promise.)
Being open about how we build the product follows from the same idea. If you run Maester Cloud, you should be able to see where it’s heading and tell us when we get it wrong.
What’s next
The next post walks through the biggest release since the private preview. It brings test configuration, a review queue for new tests, an accepted-risks register, and saved views.
To follow along, subscribe to the RSS feed. If there’s something you’d like us to write about, email [email protected].
Thanks for being here at the start.