Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
281 commits
Select commit Hold shift + click to select a range
a3655b9
Merge pull request #262 from k-grube/fix/mobile-drawer-swipe-close
JohnDuprey Aug 11, 2026
d3ed0d3
feat(mobile): session toggle between card view and the full table
k-grube Aug 12, 2026
09056da
Merge pull request #274 from k-grube/feat/mobile-table-toggle
JohnDuprey Aug 13, 2026
3963eb1
fix(queue-tracker): prevent status pill overflow on mobile
JohnDuprey Aug 13, 2026
050c4f1
feat: add display name separator support to colleague impersonation a…
Corsw Aug 13, 2026
905799b
fix(standards): handle existing phishing branding
ZenTopBrandon Aug 13, 2026
2344dbb
Update CippDataTable.test.jsx
JohnDuprey Aug 14, 2026
9e46821
fix(mobile): cards->table toggle scroll and mobile nav drawer surface
k-grube Aug 14, 2026
d5e65ed
Merge pull request #284 from k-grube/fix/mobile-drawer-and-autoscroll
JohnDuprey Aug 14, 2026
f41712d
feat: custom role simple mode with include/exclude permission rules
JohnDuprey Aug 14, 2026
2a61c0f
perf(auditlog): performance improvements
Zacgoose Aug 14, 2026
8b5f033
feat: seed simple-mode rules from a built-in role template
JohnDuprey Aug 14, 2026
ca14baa
feat(auth): add role impersonation for testing cipp roles
JohnDuprey Aug 14, 2026
7a8eccf
fix(identity): include all assigned licenses in filter options
kris6673 Aug 14, 2026
ef8bc7b
feat(auth): apply role impersonation in Get-CIPPAccessRole
JohnDuprey Aug 14, 2026
8e8d4bb
feat(roles): expand matched permissions to show API endpoints
JohnDuprey Aug 14, 2026
81be1b0
fix(auth): deduplicate and filter null roles
JohnDuprey Aug 14, 2026
d618379
fix(mobile): flex wrapping on configuration-backup
k-grube Aug 14, 2026
62a00d2
Merge pull request #293 from k-grube/fix/mobile-qa-fixes
JohnDuprey Aug 14, 2026
491c27a
fix(auth): exempt IP check from role impersonation
JohnDuprey Aug 14, 2026
94a6e92
feat(roles): add warning about role isolation in impersonation
JohnDuprey Aug 14, 2026
2bd7bf0
fix(auth): require identity before showing denial message
JohnDuprey Aug 14, 2026
4c1acb7
docs(openapi): update schema for templates, roles, and partner info
JohnDuprey Aug 14, 2026
a4529cf
fix: reorder filter sheet, utilities before field list
JohnDuprey Aug 15, 2026
ea56008
fix(mobile): label mute severity chips and add risk/result slots
JohnDuprey Aug 15, 2026
2a930ca
feat(mobile-ux): move permission report actions to FAB on mobile
JohnDuprey Aug 15, 2026
39c4bd9
Merge remote-tracking branch 'origin/dev' into preview/mobile-ux-impr…
JohnDuprey Aug 15, 2026
0aea0f5
feat(autopilot): add group assignment for enrollment profiles
kris6673 Aug 15, 2026
4ebd248
baseline saving
KelvinTegelaar Aug 15, 2026
da95ad2
Fix deny remediation
KelvinTegelaar Aug 15, 2026
5f7b527
temporary fix
KelvinTegelaar Aug 15, 2026
888e38c
more granular permissions
KelvinTegelaar Aug 15, 2026
162e81d
baseline items
KelvinTegelaar Aug 15, 2026
5de48fd
fixes for baselines
KelvinTegelaar Aug 15, 2026
00686a9
baseline compare items
KelvinTegelaar Aug 15, 2026
92dece6
new caches
KelvinTegelaar Aug 15, 2026
7d2a9c3
update batches
KelvinTegelaar Aug 15, 2026
9a0aac5
feat(mobile-ux): improve mobile search, nav, and dialogs
JohnDuprey Aug 15, 2026
76ebbb2
feat(standards): add EnableTeamsConsumerInbound to Teams external acc…
kris6673 Aug 15, 2026
11d59d0
fix(sankey): use painted palette for dark mode detection
JohnDuprey Aug 15, 2026
d834074
standards
KelvinTegelaar Aug 15, 2026
ebbc9db
more conversions
KelvinTegelaar Aug 15, 2026
e08d678
Remove custom, change it to prepare+executor.
KelvinTegelaar Aug 15, 2026
e957a35
baselines updates, adding pester tests
KelvinTegelaar Aug 15, 2026
60636ff
new baselines conversion
KelvinTegelaar Aug 15, 2026
ea5da12
fix: re-apply CPV consent when the last permissions run failed
JohnDuprey Aug 15, 2026
773a6a8
fix: derive the SAM manifest timestamp from content, not file mtime
JohnDuprey Aug 15, 2026
91d9b39
fix: remove forgotten label and add back in bug label name trigger
kris6673 Aug 15, 2026
c98457d
fixes for baselines preps
KelvinTegelaar Aug 15, 2026
69f0271
Merge pull request #300 from kris6673/fix/workflows-i-broke
KelvinTegelaar Aug 15, 2026
301ccbc
Merge pull request #299 from CyberDrain/fix/cpv-consent-retry-gate
KelvinTegelaar Aug 15, 2026
f3044d5
Merge pull request #297 from kris6673/feat/AllowTeamsConsumerInbound
KelvinTegelaar Aug 15, 2026
208607a
Merge pull request #296 from kris6673/feat/autopilot-group-assignment
KelvinTegelaar Aug 15, 2026
39767da
Merge pull request #294 from CyberDrain/feat/custom-role-simple-mode
KelvinTegelaar Aug 15, 2026
7e6668e
Merge pull request #282 from ZenTopBrandon/fix/phish-protection-brand…
KelvinTegelaar Aug 15, 2026
31eef9f
test the cache collection before implementing
KelvinTegelaar Aug 15, 2026
e3c91ee
Merge branch 'dev' of https://github.com/CyberDrain/CIPP into dev
KelvinTegelaar Aug 15, 2026
a30a20c
Merge pull request #292 from kris6673/fix/assigned-license-filter-opt…
KelvinTegelaar Aug 15, 2026
3dbab57
Merge pull request #277 from Corsw/patch-1
KelvinTegelaar Aug 15, 2026
c80ac4f
Merge pull request #255 from k-grube/fix/autocomplete-dom-prop-leak
KelvinTegelaar Aug 15, 2026
46b9bc2
fixes storing of standards
KelvinTegelaar Aug 15, 2026
36ec2c3
Merge branch 'dev' of https://github.com/CyberDrain/CIPP into dev
KelvinTegelaar Aug 15, 2026
eb15fb6
baseline tests
KelvinTegelaar Aug 15, 2026
b77817b
docs: update project structure and contributing to the code docs to n…
kris6673 Aug 15, 2026
5d55821
new standards
KelvinTegelaar Aug 15, 2026
4b195fe
feat(cippcore): add Get-CIPPSPOAdminListData and New-CIPPSPOAdminList…
rvdwegen Aug 15, 2026
6f92833
Merge branch 'dev' of https://github.com/CyberDrain/CIPP into dev
rvdwegen Aug 15, 2026
19fe49d
Merge pull request #228 from CyberDrain/preview/mobile-ux-improvements
KelvinTegelaar Aug 15, 2026
e5ee94b
fix(mobile): improve layout on small screens
JohnDuprey Aug 15, 2026
45f9d5d
feat(sharepoint): add sharepoint site browser (WIP)
rvdwegen Aug 15, 2026
0da706d
Merge branch 'dev' of https://github.com/CyberDrain/CIPP into dev
rvdwegen Aug 15, 2026
3e3797c
baselines
KelvinTegelaar Aug 15, 2026
bb8678f
Merge branch 'dev' of https://github.com/CyberDrain/CIPP into dev
KelvinTegelaar Aug 15, 2026
1ab4046
more baseline conversion
KelvinTegelaar Aug 15, 2026
6f99ca5
more converted baselines
KelvinTegelaar Aug 15, 2026
c2ba5a9
fix(ui): prevent mobile horizontal overflow
JohnDuprey Aug 15, 2026
0e6fe35
refactor(ui): replace Alert with CippExpandableAlert
JohnDuprey Aug 16, 2026
d69cbd2
fix: suppress duplicate title on mobile tab pages
JohnDuprey Aug 16, 2026
3a07a4b
feat(gdap): add Partner Center API token check
JohnDuprey Aug 16, 2026
5895027
feat(identity): improve user page loading skeletons
JohnDuprey Aug 16, 2026
3a3303a
feat(identity): add user switcher to view user pages
JohnDuprey Aug 16, 2026
1fc4d29
fix(table): retire drawer action buttons
JohnDuprey Aug 16, 2026
600eb5b
Templates
KelvinTegelaar Aug 16, 2026
f6199e1
Merge branch 'dev' of https://github.com/CyberDrain/CIPP into dev
KelvinTegelaar Aug 16, 2026
de0606c
baselines
KelvinTegelaar Aug 16, 2026
16839fb
Baseline conversions
KelvinTegelaar Aug 16, 2026
2d807e3
conversion
KelvinTegelaar Aug 16, 2026
bea6cf4
new baselines
KelvinTegelaar Aug 16, 2026
751274b
batch 5
KelvinTegelaar Aug 16, 2026
bb92395
Last batch
KelvinTegelaar Aug 16, 2026
9f0bdff
minor big fixes baselines
KelvinTegelaar Aug 16, 2026
ddbd19d
cipp standards agent
KelvinTegelaar Aug 16, 2026
3424a51
frontend fixes
KelvinTegelaar Aug 16, 2026
919758c
fixes baseline
KelvinTegelaar Aug 16, 2026
04e1a56
fixes for baselines
KelvinTegelaar Aug 17, 2026
4f0d8da
baseline fixes
KelvinTegelaar Aug 17, 2026
29cc78a
baseline changes
KelvinTegelaar Aug 17, 2026
b6f96ca
Baseline bugs in compares
KelvinTegelaar Aug 17, 2026
3a0b876
fix(standards): ignore unmanaged policy fields
Zacgoose Aug 17, 2026
64e5ab2
Merge pull request #307 from CyberDrain/preview/auditlog-performance-…
Zacgoose Aug 17, 2026
47170a6
fix(identity): correct inactive users report fields
Zacgoose Aug 17, 2026
eb3eb30
feat(cipp): Introduce UnlicensedOneDriveData alert
rvdwegen Aug 17, 2026
0793727
Merge pull request #247 from CyberDrain/dependabot/github_actions/dev…
Zacgoose Aug 17, 2026
b4c64e3
fix(ca): resolve custom variables before named-location matching
Zacgoose Aug 17, 2026
07e0415
fix(pwpush): stop stale settings from silently breaking every push
Zacgoose Aug 17, 2026
67adec2
chore: Remove non supported group creation types (dynamic dist groups)
Zacgoose Aug 17, 2026
2f35ff3
feat(cipp): record version transitions and surface hosting info on Ve…
Zacgoose Aug 17, 2026
bccbf57
feat: add entity switcher to detail pages
JohnDuprey Aug 17, 2026
b8df60c
fix(pwpush): force re-initialization so config changes reach every wo…
Zacgoose Aug 17, 2026
4e53fc8
feat(support): add support bundle generator
Zacgoose Aug 17, 2026
5fb911e
GITBOOK-618: NG Note Clarification
bmsimp Aug 17, 2026
06a9c25
Merge pull request #301 from kris6673/docs/codeContribution
KelvinTegelaar Aug 17, 2026
8329ceb
baseline changes
KelvinTegelaar Aug 17, 2026
a79aaf8
chore(deps): bump github/codeql-action from 4.37.6 to 4.37.7
dependabot[bot] Aug 18, 2026
b92e560
fix: keep universal search and theme toggle reachable at 900-1199px
k-grube Aug 18, 2026
786a35b
fix: stop the mobile nav drawer scrolling past its content
k-grube Aug 18, 2026
34377cb
fix: indent nested mobile nav items by depth
k-grube Aug 18, 2026
e2a6e57
feat(quarantine): add message details, actions and MIME parsing to qu…
kris6673 Aug 18, 2026
f910a10
fix(support): strip auth tokens from bundles
Zacgoose Aug 18, 2026
5f56464
fixes #257
KelvinTegelaar Aug 18, 2026
fb31d89
fixes #302
KelvinTegelaar Aug 18, 2026
3898258
Merge branch 'dev' of https://github.com/CyberDrain/CIPP into dev
KelvinTegelaar Aug 18, 2026
6d2bea0
feat(cache): add script to trim Azurite cache if size exceeds threshold
rvdwegen Aug 18, 2026
bacb822
fixes #47
KelvinTegelaar Aug 18, 2026
ab82a4d
Merge branch 'dev' of https://github.com/CyberDrain/CIPP into dev
KelvinTegelaar Aug 18, 2026
b83822e
fix(pwpush): handle string account ids in links
Zacgoose Aug 18, 2026
8dc8739
add disabling of alerts and scheduled tasks #304
KelvinTegelaar Aug 18, 2026
e7010ce
Merge branch 'dev' of https://github.com/CyberDrain/CIPP into dev
KelvinTegelaar Aug 18, 2026
078d671
add form key for resets
KelvinTegelaar Aug 18, 2026
bdf3b56
allow removal via selector
KelvinTegelaar Aug 18, 2026
33a4d75
remove alert option for baseline
KelvinTegelaar Aug 18, 2026
ab6d803
add offboarding of Quartatine alerts to offboarding
KelvinTegelaar Aug 18, 2026
98ca595
fix(auth): fail closed when the allowed-tenant scope is explicitly empty
Zacgoose Aug 18, 2026
f6754aa
fix(auth): narrow remaining cached AllTenants readers to allowed tenants
Zacgoose Aug 18, 2026
25dea1b
feat(identity): add guest lifecycle dashboard
Zacgoose Aug 18, 2026
ef20e30
fix(sharepoint): marker-based completion and per-drive fan-out for sh…
Zacgoose Aug 18, 2026
76834eb
feat(tools): sharing-links seeding and scan measurement dev scripts
Zacgoose Aug 18, 2026
0072989
fix(auth): enforce tenant scope on AnyTenant live and write endpoints
Zacgoose Aug 18, 2026
4887e6b
fix(autocomplete): disambiguate default match
Zacgoose Aug 18, 2026
4616513
feat(orchestrator): add priority-aware queue scheduling
Zacgoose Aug 18, 2026
e2be9fa
chore(api): update api spec
Zacgoose Aug 18, 2026
f3a9fe1
fix(exchange): seed contact templates from CIPPRootPath instead of re…
Zacgoose Aug 18, 2026
ba81145
fix(exchange): resolve connector comment variables per target tenant
Zacgoose Aug 18, 2026
ca0f6a4
added ability to duplicate name check, and app consent standard changes
KelvinTegelaar Aug 18, 2026
938c018
Merge branch 'dev' of https://github.com/CyberDrain/CIPP into dev
KelvinTegelaar Aug 18, 2026
3dedce3
fix(queue): read Craft context via variable lookup
Zacgoose Aug 18, 2026
a0356d8
added sendas to offboarding wizard
KelvinTegelaar Aug 18, 2026
7ba43cd
Merge branch 'dev' of https://github.com/CyberDrain/CIPP into dev
KelvinTegelaar Aug 18, 2026
89645f9
docs: cover GitHub token fallback and release notes defaults
bmsimp Aug 18, 2026
547f533
Merge pull request #188 from kris6673/feat/purview-message-encryption
KelvinTegelaar Aug 18, 2026
f45e502
docs: cover custom role simple mode and role impersonation
bmsimp Aug 18, 2026
2dc0c68
fix(orchestration): pass parent run lineage when queueing Craft child…
Zacgoose Aug 18, 2026
0831a04
feat(identity): serve guest lifecycle dashboard from the report cache
Zacgoose Aug 18, 2026
76489ea
new MDE offboarding device action
KelvinTegelaar Aug 18, 2026
0ca554a
Merge branch 'dev' of https://github.com/CyberDrain/CIPP into dev
KelvinTegelaar Aug 18, 2026
7904815
docs(autopilot): complete group assignment documentation
bmsimp Aug 18, 2026
44cfa2f
docs(mobile): document mobile and narrow-screen behaviour
bmsimp Aug 18, 2026
cd04671
add AppleUserInitiatedEnrollmentProfiles
KelvinTegelaar Aug 18, 2026
0d164a8
Merge branch 'dev' of https://github.com/CyberDrain/CIPP into dev
KelvinTegelaar Aug 18, 2026
68e0c01
refactor(orchestration): resolve priority fallback directly
Zacgoose Aug 18, 2026
a4cea97
feat(support): add manual recording mode to support bundle
Zacgoose Aug 18, 2026
dec6213
add users directly from groups menu
KelvinTegelaar Aug 18, 2026
661a9c5
Merge branch 'dev' of https://github.com/CyberDrain/CIPP into dev
KelvinTegelaar Aug 18, 2026
067ed77
translate license shapes and report update.
KelvinTegelaar Aug 18, 2026
30cb11b
use actual report.
KelvinTegelaar Aug 18, 2026
32a4e5e
feat(halo): add configurable ticket request source
renada-jacob Aug 18, 2026
3f3247f
feat(tests): expose Domain Analyser results to custom tests via the r…
Zacgoose Aug 18, 2026
8ac8570
feat(auth): add self-service access refresh for PIM-activated roles
Zacgoose Aug 18, 2026
6ddd24f
fix(auth): apply role group mapping changes to user access immediately
Zacgoose Aug 18, 2026
23fbd34
chore(api): update api spec
Zacgoose Aug 18, 2026
0930bde
fix(sharepoint): show an empty state instead of a permanent skeleton …
Zacgoose Aug 18, 2026
94b9e73
fix(sharepoint): treat locked sites as inactive instead of failed in …
Zacgoose Aug 18, 2026
d0f916a
fix(sharepoint): authenticate StorageQuotas reads with the SAM certif…
Zacgoose Aug 18, 2026
62ca847
Merge pull request #323 from Renada-Solutions/feat/halo-request-source
KelvinTegelaar Aug 18, 2026
063722f
Merge remote-tracking branch 'upstream/dev' into fix/mobile-ui
k-grube Aug 18, 2026
4f2b055
docs(shared-features): document the entity switcher
bmsimp Aug 18, 2026
ac32924
Merge pull request #316 from k-grube/fix/mobile-ui
KelvinTegelaar Aug 18, 2026
08c22ee
chore(licenses): update Microsoft license SKU data
github-actions[bot] Aug 19, 2026
e8d7fae
docs(user-documentation): drop stale drawer action claims
bmsimp Aug 19, 2026
794b474
docs(identity): document last successful sign-in column
bmsimp Aug 19, 2026
81dd2ae
docs(ca-templates): document custom variables in CA templates
bmsimp Aug 19, 2026
b3530b0
docs(pwpush): document expiry ranges and test failure reporting
bmsimp Aug 19, 2026
6e344fa
docs(groups): drop dynamic distribution group from group pages
bmsimp Aug 19, 2026
5059b01
docs(user-documentation): document version history and hosting details
bmsimp Aug 19, 2026
0d7b4c9
Merge pull request #330 from CyberDrain/chore/license-sku-update-2026…
Zacgoose Aug 19, 2026
9c221f2
docs(shared-features): cover GDAP relationships in entity switcher
bmsimp Aug 19, 2026
ddc53ec
docs(shared-features): document the support file generator
bmsimp Aug 19, 2026
7d6a6a9
add macosx wipe
KelvinTegelaar Aug 19, 2026
d654e28
docs(alert-configuration): document alert enable and disable actions
bmsimp Aug 19, 2026
afeb8ff
docs(offboarding): document quarantine release request alert removal
bmsimp Aug 19, 2026
afac567
docs(roles): cover a custom role tenant scope that resolves to no ten…
bmsimp Aug 19, 2026
06cf290
device encryption state
KelvinTegelaar Aug 19, 2026
6b53d10
Merge branch 'dev' of https://github.com/CyberDrain/CIPP into dev
KelvinTegelaar Aug 19, 2026
10b3efa
docs(identity): add guest users page
bmsimp Aug 19, 2026
33227aa
docs(identity): add guest users to the nav
bmsimp Aug 19, 2026
47644a1
fix(auth): ReadWrite rule grants implied Read permission
Zacgoose Aug 19, 2026
8cdcb62
docs(teams-share): update sharing report scan behaviour
bmsimp Aug 19, 2026
8ba85f3
docs(roles): document operations requiring unrestricted tenant access
bmsimp Aug 19, 2026
b09037d
docs(users): document duplicate username warning on Add User
bmsimp Aug 19, 2026
aa53ad9
docs(offboarding-wizard): document Send As and Send on Behalf grants
bmsimp Aug 19, 2026
0e93789
fix(standards): guard group template against duplicate creation
Zacgoose Aug 19, 2026
325b40a
fix(standards): improve spam filter policy resolution
Zacgoose Aug 19, 2026
1225d52
docs(message-encryption): correct IRM field descriptions and align to…
bmsimp Aug 19, 2026
98d45ca
docs(endpoint): document MDE offboarding and macOS wipe device actions
bmsimp Aug 19, 2026
0752cc3
docs(alerts): document rogue apps alert sources and CIPP curated list
Zacgoose Aug 19, 2026
5acd402
docs(identity): document Add Member action on Groups page
bmsimp Aug 19, 2026
01c15ff
docs(report-builder): document database block value rendering
bmsimp Aug 19, 2026
1484dcd
docs(report-builder): correct licence rendering in generated reports
bmsimp Aug 19, 2026
71e7026
docs(shared-features): document self-service access refresh
bmsimp Aug 19, 2026
14a4a10
docs(halopsa): correct test ticket scope and drop em dash
bmsimp Aug 19, 2026
2929741
docs(mobile-layout): correct account menu breakpoints
bmsimp Aug 19, 2026
e94f951
fix(graph-requests): keep split cache rows in the queue pre-write cle…
Zacgoose Aug 19, 2026
0dd8f77
Merge branch 'dev' of https://github.com/CyberDrain/CIPP into dev
Zacgoose Aug 19, 2026
715b0ba
feat(gdap): enhance onboarding URL resolution in GDAP invite functions
rvdwegen Aug 19, 2026
0823562
feat(cipp): implement application secret verification in Test-CIPPAcc…
rvdwegen Aug 19, 2026
78796ea
Merge branch 'dev' of https://github.com/CyberDrain/CIPP into dev
rvdwegen Aug 19, 2026
9dfab85
chore(licenses): update Microsoft license SKU data
github-actions[bot] Aug 20, 2026
d23afd8
Merge pull request #341 from CyberDrain/chore/license-sku-update-2026…
Zacgoose Aug 20, 2026
28e7abf
fix(gdap): ensure OnboardingUrl is set correctly in GDAP invite funct…
rvdwegen Aug 20, 2026
603bcb1
Merge branch 'dev' of https://github.com/CyberDrain/CIPP into dev
rvdwegen Aug 20, 2026
4700275
docs(cipp): document application secret verification on Permissions page
bmsimp Aug 20, 2026
1e5bb20
Update Compliance Portal URL to Purview link
jonwbstr Aug 20, 2026
86c7aaf
Add SharePoint Portal link to Hudu Magic Dash
jonwbstr Aug 20, 2026
bcb443a
Merge pull request #345 from jonwbstr/HuduIntegration-magicdash-add-l…
KelvinTegelaar Aug 20, 2026
9cba749
Merge pull request #344 from jonwbstr/HuduIntegration-switching-magic…
KelvinTegelaar Aug 20, 2026
1d374ec
feat(cipp): enhance group management functions with new capabilities
rvdwegen Aug 20, 2026
791c697
feat(cipp): enhance group management and UI components
rvdwegen Aug 20, 2026
ba6091c
fix(standards): clarify user submissions drift rule state
MWG-Logan Aug 20, 2026
2ad9c1f
Merge pull request #348 from MWG-Logan/feat/investigate-drift-standard
KelvinTegelaar Aug 20, 2026
4725bf4
Merge branch 'dev' into quarantine-overhaul
KelvinTegelaar Aug 20, 2026
23ff8d1
Merge pull request #318 from kris6673/quarantine-overhaul
KelvinTegelaar Aug 20, 2026
cace79c
docs(hudu): list all always-included Magic Dash portal links
bmsimp Aug 20, 2026
2108156
docs(groups): document member and owner sub-tables
bmsimp Aug 20, 2026
e4c2877
fix(sharing-links): resume throttled scans
Zacgoose Aug 21, 2026
f532448
docs(quarantine): document the Files and Teams tabs
bmsimp Aug 21, 2026
9040f66
feat(container-management): show update history as a data table
Zacgoose Aug 21, 2026
53cafd5
fix(core): roll chained orchestrator runs into one queue status
Zacgoose Aug 21, 2026
226751a
feat(worker-health): surface skipped jobs and add job detail off-canvas
Zacgoose Aug 21, 2026
31a6220
docs: replace embedded API schema with reference to built in integrat…
bmsimp Aug 21, 2026
53815ca
Merge branch 'dev' of https://github.com/CyberDrain/CIPP into dev
bmsimp Aug 21, 2026
0bad504
Merge pull request #313 from CyberDrain/dependabot/github_actions/dev…
KelvinTegelaar Aug 21, 2026
9a80ce9
Merge pull request #252 from CyberDrain/dependabot/npm_and_yarn/front…
KelvinTegelaar Aug 21, 2026
a95df62
Merge pull request #249 from CyberDrain/dependabot/npm_and_yarn/front…
KelvinTegelaar Aug 21, 2026
97bd945
Merge pull request #248 from CyberDrain/dependabot/npm_and_yarn/front…
KelvinTegelaar Aug 21, 2026
e2ccac2
Merge pull request #126 from jspern/refactor/tap-standard
KelvinTegelaar Aug 21, 2026
c6dd7a4
feat(vacation): support standalone alert exclusion
Zacgoose Aug 21, 2026
960f814
feat(users): add bulk action to require password change at next logon
rvdwegen Aug 21, 2026
f49c602
feat(offboarding): enhance Out of Office message handling
rvdwegen Aug 21, 2026
b60a216
versions up.
KelvinTegelaar Aug 21, 2026
5b10ea4
remove workflow, fix tests
KelvinTegelaar Aug 21, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
161 changes: 161 additions & 0 deletions .github/agents/CIPP-Standard-Agent.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,161 @@
---
name: CIPP Baseline Standard Builder
description: >
Builds new baseline standards for the CIPP Baselines engine: a definition JSON in
backend/Config/BaselineStandards, plus - only when the logic demands it - a prepare hook
and executor in backend/Modules/CIPPCore/Public/Baselines.
---

# CIPP Baseline Standard Builder

## Mission

You build **baseline standards** — the drift-first declarative standards that live in
`backend/Config/BaselineStandards/<Category>/<Name>.json`. The engine
(`Invoke-CIPPBaselineStandard`) owns compare, triage, deviations, history and persistence
for every standard; your job is only to describe **what to read, what compliant looks
like, and how to write it**.

Never call this system "Standards V3" — the feature is **Baselines**, and every table,
route and folder uses `Baseline*` names.

## Choosing the format — the most important decision

**Prefer the single-file definition.** If the standard is a simple Graph or Exchange edit —
read one object (ideally from a CIPPDb cache), compare a handful of properties, PATCH or
run a cmdlet to fix it — the definition JSON alone is the whole standard. The engine
renders `%variable%` tokens, reads the cache, compares, and hands the rendered remediate
spec to a **generic executor**. No PowerShell is written at all.

**Move to a prepare hook and/or named executor only when it becomes more complex.** The
rule of thumb: the moment you need PowerShell to *derive* the expected or current state
(parse a settings tree, compute a dynamic list, join multiple caches, normalize formats),
you need a prepare hook. The moment the write is more than "send these rendered values"
(create-vs-update decisions, delete-and-recreate, multi-step calls, merge-preserving
writes, per-item loops), you need a named executor. Replace **only the part that needs
code** — a standard can be hook + generic executor, or declarative read + named executor.

| Situation | Format |
| --- | --- |
| Read one cached object, compare fields, one PATCH / one cmdlet | Definition JSON only |
| Current state needs computation (parse settingInstance trees, derive effective state, join caches, normalize values) | Add `prepare` hook |
| Write needs logic (create-or-update, delete-and-recreate, full-array rewrites with live values, multi-endpoint sequences, per-item continue-past-failure) | Add named executor |
| One deployed object per operator-chosen name or template | Instance model (`multiple` + `instanceIdentity`) plus hook + executor |

## The single-file definition

Anatomy (see `Defender Standards/AtpPolicyForO365.json` for a real example):

```jsonc
{
"name": "MyStandard", // must match the file name
"label": "Human-facing label",
"cat": "Exchange Standards", // must match the category folder
"impact": "Low Impact", "impactColour": "info",
"helpText": "...", "executiveText": "...", "docsDescription": "...",
"requiredCapabilities": [], // flat = any-of; nested arrays = AND of any-of groups
"disabledFeatures": { "report": false, "warn": false, "remediate": false },
"compare": "subset",
"variables": {
"MySwitch": { "type": "switch", "label": "...", "default": true, "omitWhenBlank": true }
},
"expected": { // compliant state; %tokens% render from variables
"someProperty": true,
"otherProperty": "%MySwitch%"
},
"read": { "cacheType": "ExoOrganizationConfig" }, // CIPPDb cache the engine reads
"remediate": { // a GENERIC executor + its rendered spec
"executor": "ExoRequest",
"cmdlets": [ { "cmdlet": "Set-OrganizationConfig", "params": { "SomeProperty": true } } ]
}
}
```

Generic executors available to declarative definitions: `GraphRequest` (ordered
`requests[]` of `{ method, uri, body, asApp, continueOnError }` against Graph beta),
`ExoRequest` (`cmdlets[]`), `TeamsRequest`, `ExoPolicyRule`, `ExoBulkSweep`,
`GraphBulkSweep`. `expected` supports `$anyOf` sets for properties with several acceptable
values. `read` supports `filter`, `array`, `object` and `defaults` for descending into
cached rows.

Variable rules that bite:

- **Every optional variable referenced in `remediate` must set `omitWhenBlank: true`** —
otherwise an unconfigured variable leaves the raw `%token%` string in the spec.
- `required: true` variables gate the standard: unconfigured means "Not configured", the
engine never compares or writes the raw token.
- Number fields are saved as strings by the frontend; the engine coerces on the declared
`"type": "number"` — declare it, never work around it.

## When it becomes more complex: prepare hooks and executors

### Prepare hook — `Get-CIPPBaseline<Name>State.ps1`

```powershell
function Get-CIPPBaseline<Name>State {
[CmdletBinding()]
param($Item, $TenantFilter)
# read caches / live state, derive both sides
@{
Expected = [PSCustomObject]@{ ... } # what compliant looks like
Current = [PSCustomObject]@{ ... } # what the tenant looks like, SAME keys
}
# or: @{ Current = $null } for honest "No Data"
}
```

- Read caches through `Get-CIPPBaselineCacheRows` (with `-CollectorType` for types written
by an umbrella collector) and distinguish empty-but-collected from never-collected with
`Test-CIPPBaselineCacheCollected`. Live reads are acceptable where no cache fits (small
singletons), matching what the classic read.
- Grade **only what the baseline configures** — an empty optional field expresses no
opinion and must not appear in `Expected`.
- Carry anything the executor needs (object ids, computed lists) as **extra members on
`Current`** via `Add-Member` — extra members are not graded, only `Expected`'s keys are.
- The variables arrive raw: autoComplete values may be `{label, value}` objects — unwrap
with `$V.X.value ?? $V.X`.

### Executor — `Invoke-CIPPBaseline<Name>.ps1`

```powershell
function Invoke-CIPPBaseline<Name> {
[CmdletBinding()]
param($Remediate, $TenantFilter, $Current)
# $Remediate = the rendered remediate spec; $Current = the hook's read (carried members included)
}
```

- Definition points at it by convention: `"remediate": { "executor": "<Name>", "camelKey": "%Variable%" }`.
- **Throw on hard failure** — the engine records an honest `Error` outcome. For multi-item
writes, continue past per-item failures and throw only when *every* item failed.
- Match the source-of-truth's **auth mode exactly** (`-AsApp $true` where required — read
any classic implementation's write block to the end before porting).
- Standards sharing one settings object must **live-read before create-vs-patch
decisions** — concurrent one-off remediations race each other's cache refreshes.
- Directory-settings (`beta/settings`) PATCHes require the **full values array**; partial
arrays are rejected.
- A write the executor must gate itself (fingerprint checks, always-run semantics) pairs
with `"checkBeforeRun": false` on the definition so remediation runs every time.

### Instance standards (named objects and templates)

A standard that deploys one object per operator-chosen name or per stored template declares
`"multiple": true` and `"instanceIdentity": "<variableName>"`. Template-backed families add
`"identity": { "partition": "<templates partition>", "nameField": "name" }` so exports
bundle the template. One instance grades ONE object; an unresolvable template grades **No
Data, never Compliant**.

## Non-negotiables

- **One function per file.** Hook and executor are separate files. Never build arrays with
`+=` — use `[System.Collections.Generic.List[object]]`.
- When porting a classic standard, the default is an **exact port of its wire behaviour**;
flag questionable classic behaviour instead of silently "improving" it. Deviations
require sign-off and get recorded in
`docs/dev-documentation/cipp-dev-guide/baseline-standards-migration.md`.
- Every new standard ships with tests in `backend/Tests/Baselines/` (mock the cache reads,
pin the grading decisions and the write shapes) and the tests are **mutation-checked**:
break each load-bearing decision in the source and confirm a test fails.
- New cache types need a `Set-CIPPDBCache<Type>` collector — the convention lookup drives
collect-on-miss and the post-remediation refresh. Umbrella-written types get a thin
dedicated collector with the same URI and row shape.
27 changes: 0 additions & 27 deletions .github/workflows/Check_for_Version_Update.yml

This file was deleted.

6 changes: 3 additions & 3 deletions .github/workflows/CodeQL_Analyser.yml
Original file line number Diff line number Diff line change
Expand Up @@ -26,11 +26,11 @@ jobs:
- name: Checkout Repository
uses: actions/checkout@v6
- name: Initialize CodeQL
uses: github/codeql-action/init@v4.37.4
uses: github/codeql-action/init@v4.37.7
with:
languages: ${{ matrix.language }}
queries: security-extended
- name: Autobuild
uses: github/codeql-action/autobuild@v4.37.4
uses: github/codeql-action/autobuild@v4.37.7
- name: Perform CodeQL Analysis
uses: github/codeql-action/analyze@v4.37.4
uses: github/codeql-action/analyze@v4.37.7
2 changes: 1 addition & 1 deletion .github/workflows/Comment_on_Issues.yml
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@ on:
- labeled
jobs:
add-comment_bug:
if: github.repository_owner == 'CyberDrain'
if: github.repository_owner == 'CyberDrain' && github.event.label.name == 'bug'
runs-on: ubuntu-slim
permissions:
issues: write
Expand Down
6 changes: 2 additions & 4 deletions .github/workflows/Label_Issues.yml
Original file line number Diff line number Diff line change
Expand Up @@ -14,8 +14,7 @@ jobs:
- name: Label Issues
uses: andymckay/labeler@e6c4322d0397f3240f0e7e30a33b5c5df2d39e90
with:
add-labels: "not-assigned"
repo-token: ${{ secrets.GITHUB_TOKEN }}
add-labels: "bug"
label_issues_frs:
if: github.repository_owner == 'CyberDrain' && contains(github.event.issue.title, 'Feature')
runs-on: ubuntu-slim
Expand All @@ -25,5 +24,4 @@ jobs:
- name: Label Issues
uses: andymckay/labeler@e6c4322d0397f3240f0e7e30a33b5c5df2d39e90
with:
add-labels: "enhancement, not-assigned"
repo-token: ${{ secrets.GITHUB_TOKEN }}
add-labels: "Feature, no-priority"
6 changes: 3 additions & 3 deletions .github/workflows/codeql.yml
Original file line number Diff line number Diff line change
Expand Up @@ -24,11 +24,11 @@ jobs:
- name: Checkout Repository
uses: actions/checkout@v4
- name: Initialize CodeQL
uses: github/codeql-action/init@v4.37.4
uses: github/codeql-action/init@v4.37.7
with:
languages: ${{ matrix.language }}
source-root: frontend
- name: Autobuild
uses: github/codeql-action/autobuild@v4.37.4
uses: github/codeql-action/autobuild@v4.37.7
- name: Perform CodeQL Analysis
uses: github/codeql-action/analyze@v4.37.4
uses: github/codeql-action/analyze@v4.37.7
Original file line number Diff line number Diff line change
@@ -0,0 +1,46 @@
{
"name": "CopilotLimitedMode",
"label": "Set Copilot Limited Mode",
"cat": "Copilot (M365) Standards",
"tag": [],
"impact": "Medium Impact",
"helpText": "Enables or disables Copilot limited mode, scoped to a named group when enabling.",
"executiveText": "Restricts what Copilot will discuss for a chosen population - limiting responses on sensitive topics while the organization builds its AI governance posture.",
"docsDescription": "Grades the Copilot limited mode flag and, when enabling, that the scoping group matches the configured name. The Copilot admin settings API is delegated-only. An enabled posture whose group cannot resolve reports No Data rather than grading against nothing.",
"impactColour": "warning",
"addedDate": "2026-08-16",
"powershellEquivalent": "Graph: PATCH copilot/admin/settings/limitedMode",
"recommendedBy": [],
"requiredCapabilities": [],
"disabledFeatures": {
"report": false,
"warn": false,
"remediate": false
},
"secureScoreImpact": 0,
"compare": "subset",
"variables": {
"LimitedModeEnabled": {
"label": "Enable limited mode",
"type": "switch",
"default": false
},
"GroupName": {
"label": "Scoping group name (required when enabling)",
"omitWhenBlank": true,
"type": "textField"
}
},
"read": {
"requiredCaches": [
"CopilotAdminSettings",
"Groups"
],
"cacheType": "CopilotAdminSettings"
},
"prepare": "Get-CIPPBaselineCopilotLimitedModeState",
"remediate": {
"executor": "CopilotLimitedMode",
"limitedModeEnabled": "%LimitedModeEnabled%"
}
}
Loading
Loading