v0.6.69: Test configuration and accepted risks
Choose which tests run in each tenant, review new tests before they run, record accepted risks that leave your failing counts and posture, run tests ad hoc, and save filtered views of Tests and Changes.
What’s new
- Choose which tests run, and where. A new Configuration page turns tests on or off for all tenants, with overrides for specific tenants. Turned-off tests are skipped by the runner and left out of results, counts and posture. You can also pick your emergency access accounts here. The picker searches your directory and suggests accounts that every enabled Conditional Access policy excludes.
- Review new tests before they run. When a Maester update adds tests, they wait in a New tests queue, marked with a badge in the navigation, where you decide which tenants run them. You can switch this to opt in automatically instead.
- Accepted risks. Record a decision for a failing test, either until a date or as a permanent exclusion, for all tenants or for specific ones. An accepted failure is shown as Accepted and no longer counts as failing or toward posture, in the portal and in report and daily summary emails. A failure is never counted as a pass, and each run’s stored results are unchanged.
- Ad hoc runs. Admins can run only the tests they pick, the new tests, or all enabled tests. Run this test on a test’s page starts one directly. Ad hoc runs show in Runs with their own icon, stay out of history, trends, drift and the email digest, and are deleted after 7 days.
- Saved views on Tests and Changes. Filter by source (Maester, CISA, CIS, EIDSCA, ORCA, Zero Trust, Custom), tag, severity and product, choose columns and sort, then save the view for yourself or share it with your organization. Star a view to open it by default. Filters are kept in the page address, so you can share a link to a filtered page.
- Results by tenant on each test. A test’s page now has Overview, Tenants and Guidance tabs: each tenant’s own recent results and risk decision, and the test’s guidance shown once.
- See what your instance costs in Azure. In setup, the instance overview shows this month’s Azure charges for its resource group, the forecast for the month and last month’s total. A new Costs page breaks spending down by service and by resource. Viewing costs needs Reader or Cost Management Reader on the resource group.
- Report uploads from the module.
Send-MaesterCloudReportis now part of the MaesterCloud PowerShell module, along with the newTest-MaesterCloudUpload. It checks whether your portal accepts uploads from the identity you sign in with, without starting a run. When an upload is refused, it shows the identity the portal saw and what to change.-PortalUrlis now required. The module is now published as stable versions.
Fixes
- If a scheduled run can’t start, for example because Azure is briefly unreachable, the start is retried and the failure is reported. Before, that tenant lost its run for the day, and other tenants’ schedules in the same check were skipped.
- When you add an automation uploader on the Access page, the portal checks its IDs against Microsoft Graph. If you enter the App registration’s object ID by mistake, it saves the enterprise application’s object ID instead, which uploads need. A new Find the app search fills in both IDs and the display name for you. The check needs a verified Microsoft Graph connection for your portal’s tenant.
- Uploads from an app now record the app’s display name as the uploader.
- An idle instance uses less network traffic in the background, so Azure Container Apps can bill it at the lower idle rate.
- The portal no longer shows briefly without styling when it first loads.
- In setup, a pending update now leads the instance’s next steps with an Update to button, and setup never offers to move an instance to an older release.
- In setup, if you try the Email step again too soon after it succeeded, it now confirms the mailbox is already set up instead of asking you to wait.
How to update
- Open setup.maester.cloud and sign in with the account you used for setup.
- Choose your instance and select Update to v0.6.69. The update applies in place, and your stored results and history are untouched.
- All your existing tests stay on. Tests that later Maester versions add are held for review by default. To have them run automatically, change it on the Configuration page.
If you run setup from PowerShell, update the module first with Update-Module MaesterCloud, then run Start-MaesterCloudSetup. -AllowPrerelease is no longer needed, and Update-Module moves preview installs onto the stable version.