<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Maester on Nicola Suter</title><link>https://nicolasuter.ch/tags/maester/</link><description>Recent content in Maester on Nicola Suter</description><generator>Hugo -- gohugo.io</generator><language>en-US</language><copyright>© 2026 Nicola Suter</copyright><lastBuildDate>Thu, 04 Dec 2025 20:00:07 +0000</lastBuildDate><atom:link href="https://nicolasuter.ch/tags/maester/rss.xml" rel="self" type="application/rss+xml"/><item><title>Did you hear that maester supports Intune?</title><link>https://nicolasuter.ch/maester-tests-intune/</link><pubDate>Thu, 04 Dec 2025 20:00:07 +0000</pubDate><guid>https://nicolasuter.ch/maester-tests-intune/</guid><description>&lt;p&gt;Did you know that the &lt;a href="https://maester.dev/" target="_blank" rel="noreferrer"&gt;maester&lt;/a&gt; framework now supports Microsoft Intune checks? In this blog post, I&amp;rsquo;ll give you a quick overview of the new capabilities and how to get started.&lt;/p&gt;

&lt;h2 class="relative group"&gt;About Maester
 &lt;div id="about-maester" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#about-maester" aria-label="Anchor"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h2&gt;
&lt;p&gt;Maester is an open-source security assessment framework that helps you evaluate the security posture of your Microsoft Entra ID and Microsoft 365 environments. It provides a collection of tests that can be run against your tenant to identify potential misconfigurations and security risks.&lt;/p&gt;
&lt;p&gt;After executing the tests, maester generates a detailed report that highlights the findings and provides recommendations for remediation:&lt;/p&gt;
&lt;figure&gt;&lt;img
 class="my-0 rounded-md"
 loading="lazy"
 decoding="async"
 fetchpriority="low"
 alt="Maester Example"
 src="https://nicolasuter.ch/content/images/2025/maester-demo.jpeg"
 &gt;&lt;/figure&gt;

&lt;h2 class="relative group"&gt;Intune Related Checks
 &lt;div id="intune-related-checks" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#intune-related-checks" aria-label="Anchor"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h2&gt;
&lt;p&gt;The great thing about maester is that it&amp;rsquo;s highly extensible, allowing you to add custom tests and checks based on your specific requirements. To share some Intune best practices with the community, I contributed a set of Intune related checks to the maester framework.&lt;/p&gt;
&lt;p&gt;The following Intune checks are now available in maester:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;MT.1090 - Global administrator role should not be added as local administrator on the device during Microsoft Entra join&lt;/li&gt;
&lt;li&gt;MT.1091 - Registering user should not be added as local administrator on the device during Microsoft Entra join&lt;/li&gt;
&lt;li&gt;MT.1092 - Intune APNS certificate should be valid for more than 30 days&lt;/li&gt;
&lt;li&gt;MT.1093 - Apple Automated Device Enrollment Tokens should be valid for more than 30 days&lt;/li&gt;
&lt;li&gt;MT.1094 - Apple Volume Purchase Program Tokens should be valid for more than 30 days&lt;/li&gt;
&lt;li&gt;MT.1095 - Android Enterprise account connection should be healthy&lt;/li&gt;
&lt;li&gt;MT.1096 - Ensure at least one Intune Multi Admin Approval policy is configured&lt;/li&gt;
&lt;li&gt;MT.1097 - Ensure all Intune Certificate Connectors are healthy and running supported versions&lt;/li&gt;
&lt;li&gt;MT.1098 - Mobile Threat Defense Connectors should be healthy&lt;/li&gt;
&lt;li&gt;MT.1099 - Windows Diagnostic Data Processing should be enabled&lt;/li&gt;
&lt;li&gt;MT.1100 - Intune Diagnostic Settings should include Audit Logs&lt;/li&gt;
&lt;li&gt;MT.1101 - Default Branding Profile should be customized&lt;/li&gt;
&lt;li&gt;MT.1102 - Windows Feature Update Policy Settings should not reference end of support builds&lt;/li&gt;
&lt;li&gt;MT.1103 - Ensure Intune RBAC groups are protected by Restricted Management Administrative Units or Role Assignable groups&lt;/li&gt;
&lt;li&gt;MT.1105 - Ensure MDM Authority is set to Intune&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;Example
 &lt;div id="example" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#example" aria-label="Anchor"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;p&gt;To run the tests you can simply run:&lt;/p&gt;</description></item></channel></rss>