Skip to content

Maester M365 Security Audit Guide — SUPERSEDED

Redirected. This is the stale Maester guide. The maintained document is: Maester M365 Audit Guide

This file is kept for historical reference only. Do not update it.

Why this file was superseded:

  • Track 4 in this version instructed remediators to "document accepted risk" — language that was interpreted as adding ACCEPTED_RISK status to findings. In a HIPAA environment, ACCEPTED_RISK status is never permitted. The current guide uses "document risk acceptance with Rory's sign-off" for items that cannot be remediated, making clear that the Security Officer must approve any deviation.
  • Authentication documentation updated: Connect-AzAccount causes an Exchange auth regression; the current guide notes this explicitly.

Superseded: 2026-06-27. All Maester questions and updates go to maester-audit-guide.md.

Internal use only — Cirius Group