Reselling Maester Cloud
Maester Cloud is available to partners in the Microsoft Cloud Solution Provider (CSP) program through Azure Marketplace. This page covers what you are selling, what your customer needs, how onboarding works, and who handles which support requests.
What you're selling
Continuous security testing for Microsoft 365 and Entra, built on the open-source Maester project. Maester Cloud runs the Maester tests against the customer's tenant on a schedule, and customers can also upload Zero Trust Assessment results they run themselves. It keeps years of results, shows what changed between runs, and emails the customer when a setting drifts.
The Self-Hosted plan deploys into the customer's own Azure subscription, so their results stay under their governance in the region they choose.
Where it fits
- Microsoft 365 or Entra tenants that want continuous security testing, not a once-a-year audit.
- Teams already running Maester who need history, drift alerts, and evidence they can hand to an auditor.
- Customers who want the data to stay in their own Azure subscription and region.
One plan, two terms
- Offer
- Maester Cloud
- Publisher ID
- jozra
- Offer ID
- maester-cloud
- Plan ID
- self-hosted
- Pricing model
- Flat rate per customer tenant
- List price
- $189/mo or $2,268/yr
- Terms
- Monthly or 1-year, auto-renewing
The price above is the Azure Marketplace list price. You set the price your customer pays. The Azure resources the deployment creates, such as the web app, runner, and storage, are billed separately on the customer's own Azure subscription.
What the customer needs
- An Azure subscription the customer controls, where someone can create a resource group and assign roles. Maester Cloud deploys there.
- A Microsoft Entra admin who can grant consent for the sign-in app and the Microsoft Graph read permissions the tests need.
- An Exchange Online mailbox, if the customer wants run reports and drift alerts sent by email. This is optional.
The permissions reference lists every app and permission, so the customer's security team can review them before purchase.
From purchase to first results
- 1
Buy the plan for the customer
Purchase the Self-Hosted plan in Partner Center under the customer's tenant, choosing monthly or 1-year.
- 2
Send the setup link to the customer's admin
After the purchase, Microsoft offers a "Configure account" link. The person who signs in on that page becomes the account owner, so it should be the customer's admin, not someone at your company. The owner can add teammates later.
- 3
The customer deploys into their Azure
From their Maester Cloud account, a guided setup signs in to Azure and Microsoft Graph and deploys the stack into a subscription and region they choose. No CLI or scripts are needed, and setup can be resumed if it is interrupted.
- 4
First results the same day
The built-in runner starts running the Maester tests against the tenant on a schedule. Each run is compared with the previous one, so changes show up as drift and can trigger an email alert.
Who handles what
You (reseller)
- First contact for the customer: billing, renewals, plan and term changes, cancellation.
- Basic questions about what the product does and what the customer needs before deploying.
- Passing us anything technical, along with the customer's tenant ID and marketplace subscription ID.
Maester Cloud
- Break-fix support for setup, deployment, the runner, the portal, and email reports.
- Updates: new releases are listed on the changelog, and customers apply them from their account.
- Pre-sales technical questions, by email or on a call.
Email [email protected] for any support request, and say that you are a CSP partner.
Share these with your customers
Brand assets
Use these in your own catalogue and campaigns. Please don't alter the logo.