← All releases

v0.6.37: Email reports from your own mailbox

Test reports and daily summaries now arrive by email from a mailbox in your tenant, new tenant connections use a federated managed-identity credential by default, and the sender mailbox carries the Maester logo.

What’s new

  • Email reports from a mailbox you own. The setup wizard’s Email step creates one shared mailbox in your tenant, or adopts one you already have. Your Maester Cloud instance sends as that mailbox using its own managed identity. The permission is scoped to that single mailbox through Exchange Online role-based access for applications, so nothing is granted Mail.Send in Entra.
  • Reports shaped as an executive brief. The run report and the daily summary open with your overall posture, a bar per Microsoft product, and severity counts. Choose recipients, send after every run or once a day, optionally only when something regressed, and send a test message from Settings in the portal.
  • Federated credentials for tenant connections by default. New runner apps trust your instance’s managed identity through a federated identity credential. There is no certificate or client secret to store or rotate. A certificate is only used when no managed identity is available.
  • A recognisable sender. The sender mailbox gets the Maester logo as its profile picture. This needs the ProfilePhoto.ReadWrite.All permission on the setup wizard’s Microsoft Graph sign-in, so you will be asked to consent once. The step is optional and never blocks setup. If it was skipped, Re-check the grant sets the picture later.

Fixes

  • New run schedules default to your browser’s time zone instead of UTC.
  • A run that stops making progress is stopped after about 12 minutes, instead of running on until the two-hour run limit.
  • The runner’s network calls now time out, so one slow request can no longer stall a whole assessment.
  • Tenant consent no longer shows a failure when your tenant blocks the cross-tenant redirect after consent has already succeeded.
  • Updating an instance keeps the configured sender mailbox instead of clearing it.
  • Exchange Online setup explains a not-yet-enabled organisation and the expected permission waits in plain words, instead of showing a raw exception.
  • Connection checks use a fresh token and wait for new consent to propagate before reporting a problem.

How to update

  1. Open setup.maester.cloud and sign in with the account you used for setup.
  2. Choose your instance and select Update. The update applies in place, and your stored results and history are untouched.
  3. To turn on email reports, open the Email step. It needs an Exchange Administrator. The mailbox can take up to 15 minutes to become usable, and Exchange can take up to two hours to apply the new permission.

If you run setup from PowerShell, update the module first with Update-Module MaesterCloud -AllowPrerelease, then run Start-MaesterCloudSetup.