You ran Maester 200 times. Now what?

Maester is an amazing tool. Point it at an Entra ID tenant. A few minutes later you have one self-contained HTML report. It tells you which of about 280 security controls hold and which do not: CIS, CISA/SCuBA, EIDSCA, ORCA, plus any custom Pester test you write yourself. Run it once and it is excellent. Run it every night, across several tenants, and you learn something else. A report is not the same thing as a practice. After a few months you have a blob container with hundreds of files, three per run: ...

September 9, 2026 · Mateusz Jendza

Entra ID Four Musketeers

Changelog 2025-11-17 initial version 2026-01-02 updated Zero Trust Assessment pipeline to publish only HTML files (all others are not needed to display the report) TL;DR Maester: Review your tenant configuration using Pester (PowerShell) tests written by the community or customised by you. EntraExporter: Export tenant state to JSON files. Review changes between exports and take action. ZeroTrustAssessment: Evaluates tenant posture against Zero Trust baseline. Provides the big picture and summary of findings. Together they enable repeatable change management, drift detection, and continuous improvement. Introduction Operating Entra ID at scale requires more than ad-hoc scripting. Configuration must be observable, assessable, repeatable, and improvable. Rather than building custom verification scripts, backup solutions, or assessment frameworks from scratch, leverage three proven tools from Microsoft and the community—collectively known as the Entra ID Three Musketeers: Maester, EntraExporter, and ZeroTrustAssessment. Each addresses a critical piece of the operational lifecycle—governance testing, configuration export, and security assessment—forming a complete loop for identity platform maturity. ...

November 17, 2025 · Mateusz Jendza
×