Releases: KelvinTegelaar/CIPP
Release list
v10.6.0 - The Hydration Break
World cup Woooo!
As we've all been watching the world cup with amazement and surprise, we're still building pretty cool stuff at the same time. This release is in honour of the many hydration breaks we've had during the cup so far. Because there's been so many, its not one cocktail, but three. Check them out here and remember to stay hydrated!
ps: This release contains some new permissions, so make sure to apply those using CIPP -> Application Settings -> Permissions and refreshing your CPV permissions to get everything up and running.
Copilot & Shadow AI detection
One of our requested features was "Can we do more with Copilot and AI". After clarifying the feature requests a little and getting a clear sign of what you were looking for we of course delivered. You asked for the ability to manage copilot settings and see them. You've asked for standards around copilot settings, and you wanted to see more in depth information about adoption of AI in general.
That's all included. Not just in our dashboard where you can find the copilot readiness report, but also in our entirely new Copilot and AI section. You can now use CIPP to manage copilot in-depth; pinning the chat, blocking access to specific content, blocking or allowing image generation, allowing copilot to search the web, disabling or enabling copilot in the admin centers; all possible with just a click. As a standard, but also on demand.
We've also introduced Agent365 package management; create, share, or prevent agents from deploying in your managed tenants. Whether its for one tenant or all. Of course we've also included Microsoft's Copilot report data, adoption, usage trends, or activity.
But now the really cool part; with all that M365 data, we've heard your comments about the worries of Shadow AI, and created a reporting and executive report for that too. Let me show you how that looks;
Now, this page uses information already present in M365 and does not require any additional licensing; we use Intune to discover installed applications, we use Entra to discover any approved apps, now that does leave you with some blindspots; a lot of AI usage is done in the browser instead of installed apps. In our next release we'll be adding a detection method for those too. Shadow AI detection for everyone.
SharePoint Madness unmaddend (Is that even a word? It is now!)
This release cycle we've had 5 different SharePoint feature requests coming in, ranging from permissions, to sharing links visibility, to adding groups instead of users, and boy did we deliver, and we're building on this so much.
The biggest issue we've had with this was GDAP; Microsoft officially does not want you to manage SharePoint data directly with GDAP, so we had to work around that just a little bit, and we've done so with the expected CyberDrain flair. Instead of me just chatting away about it, let me show you.
We've added a bunch of options under SharePoint Management, like these;

Including allowing you to Revoke sharing links, delete an entire site, but also setting library level permissions.

Thought that was all? Of course not. No more going to the SharePoint admin center to try and undelete an accidentally deleted file, either bulk or singluar. No more struggling with infinite pagination on the portal itself, and instead just selecting the things you need:
Oh, and finally, the extended info display was also updated to show the exact site members, who the owners and visitors are. Jeez that's a lot of Sharepoint, and we're only getting started.
because of course it's cool to manage SharePoint, but seeing the risk in SharePoint is something that's just as important. That's why we've created the SharePoint Sharing Report.
A report that immediately tells you how much of your data in your tenant has been shared, where data has been used, how many links have been generated, what kind of links. This information can be key to understand how data was ingested by an AI, or how specific users had data they should not have had. The report shows your biggest sharers, and also allows you to invalidate links when they should not be shared.
Want a quick look? of course, here you go:

This report is being extended as we speak; Purview, applications with access, retention labels, and even automated labeling is all coming soon.
So what else is up? Well, we've pimped some of our integrations.
One of our newest community contributors introduced CVE Management within CIPP using Defender TVM. This allows you to manage known CVEs easily using our interface, but that's not all. The fantastic @DamienMatthys also made sure this integrates directly with Ninjaone's vunerability management. Are you a NinjaOne user? enable the sync for this in the integration settings and see M365 and Defender vunerabilities flow into NinjaOne easily for each tenant.
@renada-jacob also worked at our integrations; Reneda loves Halo and they love us(They are one of our Professional Services Partners!) and decided to contribute code to the Halo integration. You now have the ability to link tickets directly to the correct user. No more "General User" - If a MFA ticket is about "James Logan-Howlett" It'll be assigned to him, and not to the generic user. Pretty awesome stuff!
Jeez these are getting long, what else did you do?
The dashboard has gotten a nice update; Alerts now show up there directly, BEC has received a facelist and some new features by @kris6673, we've added the ability to completely configure auth methods from the frontend too - No longer just needing to use Standards, one-off quick changes are possible too. We've also added a feature to vacation mode to create a temporary scoped CA policy for the duration of someone's vacation, special thanks to @StoricU for that.
I'm just here for the list. Gimme the list.
We've added:
- Add pages for Deleted Sites and External Users; update navigation
- Enhance SharePoint site management
- Add Edit Site Properties form and integrate with site management
- Enhance SharePoint site member role handling
- improve source of authority state change
- Improve set sign in state with validation
- enhance user actions TAP generation
- add option to include mail-enabled security groups and group them
- Add handling for license missing deviations in drift management
- Enhance proxy address handling by merging Entra ID and Exchange data
- Add color picker support for sensitivity labels and enhance label color handling
- add Microsoft 365 / Entra Backup roles to JIT list
- show MCP API URL (/api/ExecMcp) on CIPP-API integration page
- add email aliases and hide-from-GAL to group templates
- Add default checkboxes for webhooks.
- Add Stale Entra Devices Remediation Action for standards
- add mailbox access card to exchange page
- add bulk remove mailbox permissions functionality
- Add delivery insights
- add tooltips and keyboard shortcut hints
- add per-method auth method config UI
- Adds an Alerts card to the dashboard showing fired alert instances for the selected tenant: active alerts on top (each snooze-able), with snoozed alerts greyed at the bottom showing time remaining and who snoozed them. Lets you review and manage alerts without leaving the dashboard.
- restore manual searches
- Add audit log alert presets for external forwarding and Exchange admin elevation
- include/exclude group pickers for Intune assign
- add sent messages check and update checks numbering
- add severity action to incidents list
- add navigation links to various cards for better UX
- Add default calendar permission options and warning
- Add room calendar processing options
- add allTenants support for shared mailbox enabled report
- show SMTP auth state on user tab
- expose PSA Ticket Strategy on the alert configuration form
- ability to add/remove nested groups in group memberships
- add Link tickets to affected users toggle
- add functions to manage SharePoint external users and site user removal
- Enhance group member addition and removal logging with group names
- Improve SharePoint site role membership handling
- Support non-group SharePoint member updates
- add license name to offboarding
- Add or update the Azure App Service build and deployment workflow config
- add functions to format alert cell values and normalize alert display rows
- Refactor target object handling in Get-CippCustomDataAttributes and enhance user attribute selection in Invoke-ListUsers
- Enhance reusable settings template handling in tenant alignment functions and standards
- Adds a read-only endpoint that surfaces the currently-active fired alert items for a tenant, so the frontend can display live alert instances (not just configured rules or snoozed items). Backs the new Alerts card on the dashboard.
- and so much more
We've fixed:
- Fixed Drift Template names not found when using tags.
- ensure sorted output for child values and handle comparison errors in Intune template
- exclude .None permissions from permission check
- remove users from mail-enabled security groups during li...
v10.5.0 - The Jungle Juice
Jungle juice has a little bit of everything in it.
The coolest thing about having an event like MSPGeekCon is that we get to be together with our entire team for a while and throw our wildest ideas out there. I love events because I get to spend it with people I care about and just build the most awesome software we can. The slight delay on releases is worth it as we have some huge things coming for you now.
This release is focused around AI, Compliance, standards, and more, but before we jump into lets talk about a little popup you'll get when logging in after updating; we're performing some improvements on how we handle SSO and we're preparing for some infrastructural changes that'll allow us more flexibility. After login, you'll be greeted by a pop-up asking you to create the SSO app for us. Click the button, so you're prepared for the future migration.
Oh and if you're a user of CW, AT, or Kaseya BMS, you should head over to the integration page for a little surprise, right after drinking some Jungle Juice of course
The Official CIPP-MCP Beta!
Yes, you're reading that right - We're release the CIPP Tools MCP into the wild, but behind a feature flag. Get on over to CIPP -> Application Settings-> Features to enable the MCP. After enabling the MCP you'll be able to ask any questions to Claude or any other AI you like using, with natural language. For example:

We're releasing the beta as a read-only tool, but in a couple of weeks we'll be introducing more MCP-Goodness. Together with @cipp-ashe as our COO and AI lead we're going to make sure we bring more AI assistance to you in a responsible and controlled manner.
Purview and purwho?
This release we've also added the ability to completely run with compliance management; we already could do some things such as DLP policies and setting retention, but we figured why stop there? You can now completely template your entire Purview environment, including Sensitive information Types, and deploy them everywhere. It makes handling Purview and AI compliance so much easier.
Of course we didn't just add the templates; we've also made sure you can use our standards to get the same configuration deployed to your clients in an explainable way.
Application Deployment as a standard
A couple of months ago we've added the ability to deploy any custom application using CIPP
We've now added the ability to deploy applications as a standard. You create an application template in our system from an existing app, or you use WinGet, Choco, or your own custom application. You can all upload it inside of the portal and deploy anything you want directly to Intune.
As soon as you add a tenant to the standard, they receive these applications to be installed, or even better; uninstalled. Massively uninstall bloatware with the click of a button using CIPP now.
SharePoint Retention Management
One of the biggest complaints my MSPs team has is how hard it is to manage SharePoint retention at times; especially when there are a million copies of the same file everywhere, with a million versions because Microsoft's managed SharePoint file history can be a tad aggresive.
So we've added two cool new options; one is to set the SharePoint versioning for existing and new sites to a specific number of files or days. The other is the ability to launch a SharePoint cleanup job. No more using 10TB of data just on 100x versions:
New Tenant Tests and Compliance testing
We've added a full test suite for SMB1001:2026 to CIPP using the test suites, allowing you to easily see how far along you are using our test suites, we've also added the M365 Foundations Benchmark v6 and v7 suites to test against.
Of course just willy nilly creating tests for frameworks doesn't help anyone so we've also improved the testing overviews to show you which standards make sure you can satisy the requirements for testing:

Talking about standards, whats new there?
We've always had the ability to configure Auth Methods, but they were split over a couple of different standards for flexbility, but some users asked if we could make a single standard where they configure all of them; that's one thing we've added for you, but we've added a lot more, about 15 new standards to use with all the added functionality in M365.
- Email as alternate login ID standard
- DLP via DCS standard
- DLP via DCS OWA standard
- Intune Device Join
- Device Registration
- Windows Hello - Added additional options
- Smart Lockout standard
- FIDO2 profile standards
- Autopatch standard
- New auth methods standard
- CA template package tags (tag-based deployment)
- AAD Premium license gate on ExternalMFATrusted
- Levenshtein/fuzzy matching for Intune drift (configurable distance)
- Manual standards run processes all templates for precedence
- License capability presets
- Standards template deployment for Intune apps
- By-standard alignment summary view
- Custom Test - alert on X statuses
- Special beta standard: Configure Autopatch
What other new cool gizmos do you have for us?
There's so many feature requests in this list that its hard to keep track sometimes but some other features we've added that we're proud of are also built by our contributors:
- Group License management, easily deploy licenses to groups using CIPP and CIPP Templates now
- The ability to exclude licenses from alerts only instead of the entire product
- The ability to deploy Device Prep Profiles
We've added:
-
Apple ADE + Android enrollment profile listing/deletion
-
Device Prep(Autopilot v2) profile
-
CAS mailbox management endpoint (ExecSetCASMailbox)
-
Remove users from admin roles
-
Add/remove nested groups in group memberships
-
Group-Based Licensing
-
Online archive report (mailbox + archive size columns)
-
Bulk update contact/UPN fields
-
AllTenants: Intune pages, Teams/SharePoint, SPO sites (greatly faster)
-
SharePoint management functionality
-
OneDrive sharing disable (offboarding + menu)
-
HVE user management + cache
-
Licence Universal Search
-
Apps and Service Principals in universal search
-
New license report endpoint
-
AutoExpandingArchive org-level property exposed
-
Backup excluded tenants config
-
PendingAcceptance guest handling + updated reporting
-
SSO auth popup
-
Additional portal links in Hudu extension sync
-
Exclude From Alert support on licenses
-
Optimize CIPP DB orchestration
-
CA policy editor + template creator/editor redesign
-
Lookup CA template names via API
-
CA policy to package tag UI elements
-
Run standard now UX — autocomplete for tenants/groups/individual
-
Breadcrumb text selectable/copyable
-
Icons in tabbed layouts
-
Intune template details improved
-
Template displayName used for labels
-
Side nav expanded for UX
-
Permanent dismissal for release notes
We've fixed
-
Standards run errors (Retention, MDO, general)
-
Manually run standards not in applied standards report
-
TenantAllowBlockList always non-compliant
-
Intune standard change detection queries
-
CIS 5.1.4.1 and SMB1001 (2.8) tags moved to join standard
-
intuneRestrictUserDeviceRegistration now targeting azureADRegistration
-
Presets applied to rest of standards (DefenderForOffice365 etc)
-
Desktop activations Copilot-ready test
-
Standard name retrieval logic improved
-
Tenant groups cache alternating on refresh
-
AllTenants retrieval issue
-
AllTenants sync on OneDrive/SharePoint
-
Intune policy listing speed for AllTenants
-
AllTenants SPO timeout with large tenant lists
-
Duplicate test calls
-
EditIntunePolicy wrong role
-
Autopilot endpoint roles (Autopilot.Read)
-
Quarantine deny action
-
Bulk mailbox rule changes
-
Template trigger
-
ExoGroups add-member (auto-retry for new users)
-
Mail contact standard reworked
-
CA policy compare blank line + pipe char escaping
-
"Temporary Access Password" → "Temporary Access Pass"
-
Template ID casing
-
Caching cleanup bug
-
Scheduler details/list headers removed
-
Queue rerun protection timing
-
404 detection for non-existing roles
-
JIT admin autocomplete creatable removed
-
Tab title showing as undefined
-
Version check / version encoding updates
-
Translation keys updated
-
Fallback to app version if not specified
-
Tenant group scope cache
-
Explicit tenant removal from table
Sponsors
We extend our gratitude to our supporters at https://renroros.no/, https://immy.bot/, https://oit.co/, https://ninjaone.com/, Huntress at https://huntress.com/, https://halopsa.com/, https://www.deskdirector.com/, https://hudu.com/, our friends at https://www.meetgradient.com/, https://rewst.io/ https://augmentt.com/ and newly added Domotz and Guardz!
New Contributors
- @StoricU made their...
v10.4.0 - The Jamaican Ten-Speed
I am speed
This release is different, it's a little funky because we barely added features. We say barely, but we still tackled something like 15 feature requests, it just wasn't the focus this time.
This time we wanted to focus on speed. Speed of responses by our API, but also speed of cold starts, and just to get you the feeling of you driving a Ferrari. Our team went deep into the internals of Azure Functions and I am proud to say we delivered; response times that are the lowest they've ever been and jobs that just run so much faster.
Pour yourself a Jamaican Ten-Speed and lets get going.
All this, and then soon we'll have an announcement about even more awesome upgrades to speed.
Applied Standards Report
We've added a report for the Applied Standards to get this by all tenants, instead of per template, an easy overview to see which client is compliant and which is not.
New Check Monitoring, Secure Score Drop, and more
We've added the ability to immediately get check alerts per email, to monitor drops in secure score, and you can now select multiple tenants for scripted alerts, making setup a little easier.
We've added:
- AdminSSPR standard
- Exchange Cloud Management standard (remote/on-premises mailboxes)
- Colleague Impersonation Alert standard
- Global Quarantine Settings standard + configuration options
- Per-standard alignment view in tenant alignment
- Drift "Deny - Remediate" deviation action
- Drift permanent deny marker
- "Drop" method for Secure Score
- "Save as Template" for Defender deployment form
- "Save to GitHub" action for templates
- "Create Template from User" action
- Dashboard improvements
- Detection script support for custom applications
- Custom Subject field for alert notifications
- Enable/disable actions for scripts and alerts
- Tenant management page: tenant groups in table, refresh button, more details
- SmtpAuthSuccess input and validators
- Add publisher to excluded app options
- Add category prefix to bookmarks
We've fixed
- Alert notification pipeline (custom subjects, AllTenants filter, webhook template, audit log wiring, severity levels)
- Notification contact removal during tenant offboarding
- JIT Admin: groups in templates, selected user fix
- Drift deny for compliant + other policies, initial filter on drift templates page
- CA vacation mode looping
- Duplicate forwarding entry creating 2 scheduler entries
- Domain template not applying if domain already set
- Graph Explorer losing config on re-open
- Sidenav + subpage nav highlighting
- Frontend loop on 500 errors outside app bounds
- Render loops
- ActiveSync last sync fields blank
- EXO permission cache speed + duplicate calls removed
- DetectedApps bulk skip pagination
- Custom scripts editor
- SafeLinks policy editor/creation page
- API results overflowing drawer on narrow screens
- Group template resubmit on edit
- Scheduler scope field removed
- Super Admin pages moved to /cipp/advanced/
- Progress bars, SharePoint layout, column sizing
Sponsors
We extend our gratitude to our supporters at https://renroros.no/, https://immy.bot/, https://oit.co/, https://ninjaone.com/, Huntress at https://huntress.com/, https://halopsa.com/, https://www.deskdirector.com/, https://hudu.com/, our friends at https://www.meetgradient.com/, https://rewst.io/ https://augmentt.com/ and newly added Domotz and Guardz!
New Contributors
- @chris-dewey-1991 made their first contribution in #5725
- @zenturash made their first contribution in #5813
- @fit-jv made their first contribution in #5861
Full Changelog: v10.3.0...v10.4.0
v10.3.0 - The Fishbowl
I think we caught a big one!
For the past few weeks our team has been going at it. We've been building everything you've been asking for at an unbelievable rate. Our entire dev team had one focus; build a release that included everyone's wishes and feature requests, and fix any bugs we find and squash them!
This release is called the Fishbowl because we touched so many different things. So before we get started with telling you all the cool new stuff, grab a straw, stick it into this Fishbowl and lets get going.
Custom Reporting and database access
Under tools -> Report Builder or on the dashboard you'll now find our new report builder. Our report builder allows you access to everything inside of our database at any moment in time; this means you can create custom reports for one tenant, or all tenants. You have the option to generate it as a PDF, CSV, JSON, or just text. This includes the option to email these reports directly and schedule them monthly.
Want a custom report that shows someone how their license usage relates to their CA policies? boom done. All in a simple format where you can add any block you want; Maester tests, CIPP database access, or just custom HTML/Markdown blocks. Add whatever you want at whatever time.
But of course we're not letting you just go out and have to create everything yourself. We've made sure our catalog contains a bunch of reports such as an actually usable Copilot readiness report. or a CISA report or even a General Tenant report.
Want to check out how it looks? of course we prepared a demo for you here: https://app.storylane.io/share/vcrohqu0snfg
Custom Maester/PowerShell Tests and custom alerts
Yes. We're now allowing you to run custom PowerShell tests, meaning that you can check any setting against the CIPP database, this database is updated every 24 hours right before your tests launch so you can see exactly what the results are. You can use JSON or markdown output so you're immediately able to use this in your own custom reports too.
And that's not all. These scripts can also be used to directly alert on. Imagine you've created a PowerShell script that looks up any CA policies with the user "Bla" excluded. You can now report on that.
licenses expiring but assigned to a VIP user? That can be a custom alert. Anything in our database, can be alerted on going forward, and its all using PowerShell so no need to learn a new language!
Want to see that in action? go check it out: https://app.storylane.io/share/qevotii3ats1
Vacation mode pimped.
Vacation mode also got some extra love in this release; expansion for scheduling groups, forwarding, but also a new tutorial to explain you how to use vacation mode. Go check it out here: https://app.storylane.io/share/d7llhd4j78qv
Better webhooks
The webhooks have had some work too; you now have the option to change our schema - the new universal schema allows you to react better on automated requests or forward it to your system of choice. The webhooks now also have support for authentication or specialized headers.
Timezones and stuff
We've moved from our old schedule which uses NCron to Chronos, Chronos is cooler, better, newer, awesomer, and supports timezones. Please go into your superadmin settings to switch the timezone for your function app to get optimal performance; no more running standards in the middle of your workday!
If you've used the WEBSITE_TIME_ZONE setting, its now time to remove that, as this brings better support. :)
And so much more:
There's so much more to mention this time that I just cant. Look at the list below, I think this might just be our biggest release yet.
We've added:
- Custom Scripts — full test system with manual runs, scheduler support, and enable/disable actions
- Vacation Mode — mail forwarding support with scheduling
- Intune Application Deployment Templates — create, manage, and upload to GitHub
- Intune Policy Comparison — compare policies side by side
- MDE Onboarding Status — new report under Security
- Create Template from User
- Group membership in user templates
- Colleague Impersonation Alert standard
- SMTP Auth Success alert
- Global Quarantine Settings standard
- Exchange Mailbox SOA Change standard
- Exchange Cloud Management for on-premises mailboxes standard
- Defender policy templates — Invoke-AddDefenderTemplate with template-only mode support
- App & service principal expiry checks
- Standardised Alert Schema — opt-in webhook schema toggle for webhooks
- Webhook authentication methods — configurable auth for notification webhooks
- GDAP Roles — updated with new MS role added April 2026
- Command blocklist for scheduled tasks — additional blocked commands for security
- Active Sync device blocking standard
- Compliance state chips in table formatting
- Pages search & keyboard navigation
- Logbook tooltip for truncated messages
- Exclude license from dashboard dropdown
- HIBP API key clear action
- SMTP sign-in date range filter
- Add litigation/retention mailbox fields
- Dashboard test UI improvements and report editor
- Chrome Extension — domain squatting detection and additional settings
We've fixed:
- Intune drift — deletion detection, cache clear, bundle remediation, "dud" remediation
- Bulk Intune app assignment — assignment fields and data formatter refactored
- Standards template import — wrong API endpoint in PolicyImportDrawer
- Manual cache refresh — passing GUID instead of defaultDomainName
- Scheduler scope — removed erroneous scope field, added tenant name
- JIT Admin TAP warning — warns when TAP not enabled in tenant
- Username clipboard — no longer copies display label with username
- LAPS standard — redundant Graph API calls removed
- Teams Phone DID removal — missing Content-Type header
- App registration secret expiry — respects Microsoft's expiration restrictions
- Reporting DB manual run
- Custom application scripts — variable entry fix
- Mailnickname sanitisation
- API client resilience — better handling for Entra replication timin
- MFA method removal — refactored to individual requests
- Onboarding — GDAP onboarding rescheduling, legacy add-in removal fix
- Group template resubmit on edit page
- Alert overflow in narrow drawers
- Audit log filtering — OData sanitization, multi-row entries, timer calculations
- businessPhones handling in user defaults
- Username fields — missing fields in template object creation
- Hudu people/devices — forced to array
Sponsors
We extend our gratitude to our supporters at https://renroros.no/, https://immy.bot/, https://oit.co/, https://ninjaone.com/, Huntress at https://huntress.com/, https://halopsa.com/, https://www.deskdirector.com/, https://hudu.com/, our friends at https://www.meetgradient.com/, https://rewst.io/ https://augmentt.com/ and newly added Domotz and Guardz!
New Contributors
- @RSI-KaleGraybill made their first contribution in #5652
Full Changelog API: KelvinTegelaar/CIPP-API@10.2.6...10.3.0
Full Changelog: v10.2.0...v10.3.0
v10.2.0 - Blue Monday
Everyone hates Monday.
And because everyone hates Monday, we figured to brighten yours up with a new release! This release is jampacked with features by contributors, fixes to nasty little gremlins all around. Let's get this show on the road. First off, lets make a Blue Monday and get going to see what goodies we're bringing you this week.
By the way; we're doing our first on-site events very soon with our educational content. Rotterdam is booked up, and we're looking for a venue for London. Want to join us there? check out https://cipp.ms/london-bootcamp.
Vacation Mode v2.0
Vacation mode has gotten some changes; it's no longer just Conditional Access that takes a break on your users. We've added temporary mailbox permissions, Temporary OOO settings, and improvements to the entire process for vacation mode. It's now a simple wizard and you can select whatever you'd like to happen to those happy people enjoying their vacation.
BitLocker Key Search
We've expanded our universal search; isn't it annoying when you have to find a Bitlocker key for a user, and they have to give you this endless ID first before you can find their key? We've solved that issue for you; We allow you to look for a partial key inside of the CIPP DB to find any bitlocker key and retrieve it live from Entra/Intune.
Better bookmarks
Sometimes a little UX goes a long way. @Brad-M-K decided to give bookmarks a makeover, and we love it! Thanks for the improvements Brad, and for your first contributions to the project!
And so much more:
We've added:
- Vacation Mode — standalone wizard with mailbox permissions, calendar access, and OOO scheduling (supports non-English tenants via locale-independent folder resolution)
- BitLocker Key Search — new Tenant Tools page to search by Key ID or Device ID and retrieve recovery keys
- Incident Report with attachment options
- New Standard: Restrict User Device Registration
- New Standard: Configure local admin rights for device-joined users
- New Standard: Windows Backup and Restore configuration
- CA Policy Tester: authentication flow selection
- MFAAdmins alert: enforcement gate check (admins with MFA registered but no policy enforcing it) + Include Disabled option
- JIT reason included in add/remove alert messages
- Bookmark sidebar with drag-and-drop reordering, sort modes, lock toggle, and mobile touch support
- License backfill system — unknown SKUs are resolved cross-tenant and cached locally, display names update dynamically in tables and user cards
- Restore wizard with type filtering and step visibility improvements
- Backup management dialogs (run on demand + schedule)
- Assignment filter options for application assignments
- Button to deploy a group template directly from the groups page
- Ctrl+Alt+K keyboard shortcut to focus the tenant selector
- Severity color mapping in the logbook
- Enabled/disabled status filter in the Standards dialog
- Outbound connector route message support
- SMTP auth alert now catches both 'Authenticated SMTP' and 'SMTP' clientAppUsed values
We've improved:
- Intune assignment verification — policies are now checked against actual assignments before applying
- NinjaOne license sync — TermInfo preserved per-license (was incorrectly aggregated); service plan details now included in reporting
- GrantSendOnBehalfTo permissions now cached (no extra Graph calls)
- Scheduled task management — duplicate name prevention, improved removal feedback
- Bookmark management — rewrite of top-nav popover with non-destructive sort, per-device storage (not synced cross-device), max 50 limit
- Sidebar scroll — smooth animation, isolated wheel events, no body scroll interference
- MFA scripted alert — extra info surfaced, single shared snapshot prevents mixed-staleness alerts
- PwPush - CloudFlare Tunnel / CF-ZTNA support
- Universal search now respects tenant access permissions
- Applied standards report layout and actions dropdown
- User form validation and required field handling
We've fixed:
- Intune Reusable Policy Settings — RAWJson casing mismatch causing silent sync failures
- Intune Script Editor — editor loading in read-only mode on existing scripts
- Standard silently overwriting 'Users may join devices to Microsoft Entra' setting
- Teams Federation Settings standard not reflecting allowed/blocked domain changes
- Broken documentation links in onboarding wizard and GDAP management pages
- HTML escaping of URLs in action links breaking OAuth consent flows (& → &)
- Encrypted policy template handling
- MX record alert
- Domain analyser tenant filtering
- Offboarding logbook no longer showing group removal entries
- Shift+Home text selection in autocomplete inputs
- Post-execution alerts firing even when not configured on the task
- UPN vs UserPrincipalName mismatch in mailbox operations
- CA Test Results table columns and fetching state
- null checks in various Standards and Intune paths
Sponsors
We extend our gratitude to our supporters at https://renroros.no/, https://immy.bot/, https://oit.co/, https://ninjaone.com/, Huntress at https://huntress.com/, https://halopsa.com/, https://www.deskdirector.com/, https://hudu.com/, our friends at https://www.meetgradient.com/, https://rewst.io/ https://augmentt.com/ and newly added Domotz and Guardz!
New Contributors
Full Changelog: v10.1.0...v10.2.0
v10.1.0 - The Bulldog Smash
I kissed a dog and I liked it
We've had some amazing times in the last couple of weeks; most of our team was at Right of Boom this month and we launched our first official CIPP training there. Seeing all the people that came to visit our booth and training was amazing; we had about 180 people following our session and teaching them about CIPP, about M365, about why Microsoft made specific choices and so much more.
Remember that this was only the first of many; our CIPP certification is coming to a location near you soon. Completely free M365 education brought to you from an MSP perspective. No funneling, no wanting you to buy products, just pure education.
Lets make ourselves a new cocktail The Bulldog Smash and look at the changes.
Custom Intune Application?! Oh my.
So for the longest time one of the requests we've had was "How can we add our own Intune Applications into CIPP?" and we had to find a way to make it possible. One of our contributors tried creating a custom app builder but it turned out to be pretty hard to use that with our infrastructure. Instead, we've chosen for a more industry standard solution: PowerShell. you can now add any Intune app, template it, and deploy it across all your tenants easily.
We're also adding templating, and an entire curated catalogue of applications for everyone to use in the next release. Want to check out how it looks? Here's a screenshot
BPA deprecation & log Retention Policies
So as we announced previously, we're deprecating BPA in favour of our tests - Tests are the replacement for custom BPA reports as they'll allow you to collect more information. We've created a new option under the settings menu to re-enabled BPA for if you're still using it, while being aware we're removing it in a later version.
You've also asked us to allow you to retain LESS of the logs, because of organizational reasons. We've introduced a settings menu to allow you to set a logbook retention policy.
Better GDAP and Direct Tenant onboarding
One of the comments in our Discord triggered us to look long and hard at tenant onboarding; the biggest complaint was that it was a lot of places you had to jump to, another was that people forgot to follow the instructions in our docs so we've tried to dive a bit more into how people think and do more actions for you.
So, onboarding has received quite a facelift. If you want to see it, we have a couple of storylanes for you to check here:
Executing the CIPP Setup Wizard First Time Setup → https://app.storylane.io/share/vxdbaztterzq
Adding a GDAP Tenant via the Setup Wizard → https://app.storylane.io/share/p6cyd3t8w8ru
Adding a Direct Tenant via the Setup Wizard → https://app.storylane.io/share/kcszcpgdcg6m
Graph Explorer
We've also upgraded our Graph Explorer, more functionality, more badass reports, and prettification:https://app.storylane.io/share/p0ljufhpgkmb
Universal Search returns
With the hard work of @rvdwegen we've made our universal search box on the dashboard come back. This now searches the entire database for users or groups so you can easily jump to the overview for these.
And so much more:
We've added:
- View group page to the Groups section
- View device page to the Intune section
- DB manual refresh section in settings
- Graph Explorer UX improvements
- Universal search (DB-backed)
- Win32 PowerShell app creation flow
- Feature flags for opt-in BPA collection
- Log retention policy (90-day default)
- Scheduler backoff and retry for rate limits
- Office Apps Licensing in PhishProtection Standard
- MFA report improvements for internal guests
- Ease of GDAP onboarding improvements
- Docs/guidance on migrating CSP tenant in CIPP
- Reuseable Intune settings by @MWG-Logan
We've fixed
- Offboarding Wizard Step 3: user lists not refreshing on tenant switch (stale React Query cache key)
- Offboarding reruns not working correctly
- Custom roles preventing Chocolatey app deployment
- NinjaOne/Hudu Device Sync issues
- SAM user not being auto-added to GDAP groups during onboarding
- Exchange user forwarding detection ambiguous with duplicate display names
- Exchange info card render issue
- Scripted alert errors creating excessive noise
- Group template deployment missing alias validation
- Conditional Access template import dropping uploads
- Azure PowerShell onboarding blocked by error 50199
- App approval templates missing default delegated scopes
- DKIM rotate standard not updating both selectors
- Standards save dialog saying 'every 3 hours' when backend runs every 4 hours
- Manual remediation failures
- Bug with bulk drift remediation actions payload
We've improved
- Exchange calendar permissions now served via cache
- DomainAnalyser pulls domains from DB instead of Graph
- Intune standard runtime overhaul
- Adjusted Exchange org management role check threshold
- Renamed 'Classic' to 'Standards' for clearer Standards vs Drift messaging
- Removed Quad9 DNS option
- Refactored Backup Engine (New-CIPPBackup → New-CIPPBackupTask)
- Refactored Drift Management Alignment Engine
- Refactored NinjaOne Synchronization Pipeline
- Clarified Group Template Username requirements
- Fixed standards timing inconsistency in docs (3h → 4h)
- Alert Comment improvements
Sponsors
We extend our gratitude to our supporters at https://renroros.no/, https://immy.bot/, https://oit.co/, https://ninjaone.com/, Huntress at https://huntress.com/, https://halopsa.com/, https://www.deskdirector.com/, https://hudu.com/, our friends at https://www.meetgradient.com/, https://rewst.io/ https://augmentt.com/ and newly added Domotz and Guardz!
New Contributors
- @dependabot[bot] made their first contribution in #5207
- @TecharyJames made their first contribution in #5349
- @StevenVBeek made their first contribution in #5346
Full Changelog: v10.0.0...v10.1.0
New Contributors API
- @mpressley-np made their first contribution in KelvinTegelaar/CIPP-API#1822
- @StevenVBeek made their first contribution in KelvinTegelaar/CIPP-API#1820
Full API Changelog: KelvinTegelaar/CIPP-API@10.0.9...10.1.0
v10.0.0 (CIPP X) - The Xanadu
We did a Microsoft.
The first release of the new year and it's a big one. During the last 4 weeks our developers and our contributors came together to make a magical new version of CIPP.
Before we get started with the cool new features, this is one of those releases where we really pushed on making things happen for our entire industry. We've integrated more OSS projects into our OSS product, that allows us all to be lifted up but also contribute back to these projects. That's why I want to thank the team at Maester and @merill for making sure we all keep the OSS spirit alive.
Now, let's make ourselves a Xanadu cocktail and look at the changes.
Oh yeah, we also did a Microsoft; skipped 9 and went straight to 10. Just because we're so proud of this release.
New Dashboard, who dis?
We've looked at our dashboard good and long and figured we need more actionable data on there. Getting our community feedback was amazing during this process and we've built a pretty cool new overview.
The new dashboard shows you exactly the tenant state you'd expect to see; Secure Score, MFA status, which MFA devices are used, licenses, but also counts of your users, policies, and more. You'll also notice a new card called "Assessment" and the ability to select a report. This is data that is collected every night and we perform all tests in each test suite fully automatically.
That means you can test against any Maester test included in CIPP, currently we have the full Microsoft ZTNA test thanks to the help of Microsoft directly, we have ORCA, Scuba, and there is more coming; Full CIS testing using the Maester framework inside of CIPP, for all your tenants.
We're also allowing you to create your own tests in the next version - Allowing you to query against any object our M365 database to see what's going on with your tenant. Custom reporting? Coming too!
Interested how this looks? check out the demo here.
Drifting with better UX
We had some really good suggestions around UX so we figured lets drift around the corner and help you understand things better. First of we've added filters to the drift page, allowing you to easily compare to the settings you want, the drift page now also shows things that are aligned correctly.
When things aren't aligned however, we've added the ability for you to see exactly what object isn't in sync. So if a CA policy is missing its excluded users group, you'll be able to zoom in on that much easier. Want to see how that looks? check out this screenshot.
Reports reports reports
We've had users ask for a couple of pretty complex reporting for a long time now; the MFA report for every single tenant at the same time, and a report of all users mailbox permissions. With the new testing database we've created for Maester it's actually much easier to execute these kind of complex reports. So what does this mean? You can now find a mailbox permissions report under our Exchange header. This report is updated nightly, but of course we've created a button to get an instant report too.
JIT improvements
Thanks to @Zacgoose we've updated our JIT settings; you're now able to set the maximum time for a JIT admin inside of the settings menu, and you're able to create JIT templates so it's always setup exactly the way you like it. Thanks Zac!
Timezones
Under super admin you can now find a timezone settings. Here you can setup the timezone the function app runs in, this is useful if your jobs sometimes run during working hours and you don't want that. Just a quick QoL improvement we've implemented.
And so much more:
- We've implemented a new alert for when Secure Defaults and CA isn't present.
- We've fixed a bug when you deleted a standard and it didn't remove it
- We've fixed the issue with links for enterprise apps not being right
- We fixed an issue with MX record reporting not showing all results
- We've fixed another problem with BEC and usernames with the same format.
- Updated the drift management page to always show the names of policies
- Updated the standards report to be slightly prettier. :)
- And so much more.
Sponsors
We extend our gratitude to our supporters at https://renroros.no/, https://immy.bot/, https://oit.co/, https://ninjaone.com/, Huntress at https://huntress.com/, https://halopsa.com/, https://www.deskdirector.com/, https://hudu.com/, our friends at https://www.meetgradient.com/, https://rewst.io/ https://augmentt.com/ and newly added Domotz and Guardz!
What's Changed in the API
- Added overwrite toggle for transport rule standard by @kakaiwa in KelvinTegelaar/CIPP-API#1755
- Enterprise Apps link in new service principal alerts are not in the correct format by @Zacgoose in KelvinTegelaar/CIPP-API#1757
- Fix: Fix app protection policies not being listed by @kris6673 in KelvinTegelaar/CIPP-API#1756
- Add Get-CIPPAlertIntunePolicyConflicts function by @MWG-Logan in KelvinTegelaar/CIPP-API#1759
- Fix: hashtable alert errors for CIPPAlertOneDriveQuota by @kris6673 in KelvinTegelaar/CIPP-API#1760
- Bug: Handle array type for conditions.users in Conditional Access Template processing by @sfaxluke in KelvinTegelaar/CIPP-API#1754
- Check accountEnabled property for shared mailbox user by @Zacgoose in KelvinTegelaar/CIPP-API#1758
- Feat: Add functions to list and manage trusted and blocked senders by @kris6673 in KelvinTegelaar/CIPP-API#1744
- Fix: Sort group members and owners by displayName by @kris6673 in KelvinTegelaar/CIPP-API#1765
- Fix: Remove measure command from Get-CIPPAlertNewAppApproval by @kris6673 in KelvinTegelaar/CIPP-API#1762
- Add secret name / ID to table by @chase-vgo in KelvinTegelaar/CIPP-API#1761
- Optimize MFA state retrieval and policy mapping by @Zacgoose in KelvinTegelaar/CIPP-API#1764
- Add JIT Admin template management and settings by @Zacgoose in KelvinTegelaar/CIPP-API#1767
- Fix: Update return message for license assignment by @kris6673 in KelvinTegelaar/CIPP-API#1770
- Fix: Enhance error handling for user creation tasks by @kris6673 in KelvinTegelaar/CIPP-API#1768
- Dev to release - CIPP X(10.0.0) by @KelvinTegelaar in KelvinTegelaar/CIPP-API#1772
Full Changelog: KelvinTegelaar/CIPP-API@8.8.2...10.0.0
What's Changed
- Dev to hotfix by @JohnDuprey in #5112
- Dev to hotfix by @JohnDuprey in #5124
- Added overwrite toggle for transport rule standard by @kakaiwa in #5141
- Add Intune policy conflict alert configuration by @MWG-Logan in #5150
- Feat: Add requestDate column with formatted DateTime by @kris6673 in #5161
- Tenant selector bug fix by @ZenTopBrandon in #5167
- Update GDAP invite URLs to new Microsoft admin domain by @sfaxluke in #5175
- Stop Dependabot bullying by @LukeSteward in #5172
- Feat: Add trusted and blocked senders exchange user card and action by @kris6673 in #5092
- Add JIT Admin Templates and settings integration by @Zacgoose in #5192
- Dev to release - CIPP X(10.0.0) by @KelvinTegelaar in #5202
New Contributors
- @LukeSteward made their first contribution in #5172
Full Changelog: v8.8.0...v10.0.0
v8.8.0 - The Swamp Water
SPPEEEEDD and PPOWEEERRRR
This release we've been pushing the envelope on backend improvements, our dev team shifted their focus to maintenance, and it shows, we've been removing some older legacy code and polishing what we have to increase our speed. We've also built so many feature requests again, which I love for the last release of the year; imagine being able to make a large group of MSPs happy with just what they needed.
So, let's make a cocktail out of the swamp water of old code that we took out, and take a nice refreshing dive into our new release
Standards and Intune
Our team looked at the way we deploy standards and Intune policies and wanted to improve on this; not just for speed but also reporting and just general prettiness of how this works, so we've built better tracking around the state of Intune Policies, decreasing the amount of processing power needed to implement policies; a great benefit of this speed increase is also that your (self-hosted) costs will go down thanks to more efficiency.
We've also added better frontend options for selecting how you deploy policies and set assignments, you'll have a better experience and an easier way to set applications, intune policies, and CA policy assignments to groups or users.
Backup Retention Policies
Many people use the tenant backup feature in CIPP, and use CIPP configuration backups, the biggest issue some users bumped into was that we stored things infinitely - You're now able to create your own backup retention policies using the CIPP settings menu! The default is 30 days, but you can extend this to whatever you'd like.
Intune Passcodes
Aren't those device passcodes or pins annoying? Using the latest update you're able to clear them for managed devices, especially handy when a user forgot their passcodes.
JIT improvements
One of our users loves the JIT feature but wanted more auditing, so we did just that, from now on we'll add which user has created the JIT request directly in the table, we also added the start and end date for extra clarity and the JIT user current state. The table also looks a little nicer now.
So many fixes
I'd love to sit her for a day and type out every single fix, but please check the full release notes and code below because we have so much being released in this one. :)
Sponsors
We extend our gratitude to our supporters at https://renroros.no/, https://immy.bot/, https://oit.co/, https://ninjaone.com/, Huntress at https://huntress.com/, https://halopsa.com/, https://www.deskdirector.com/, https://hudu.com/, our friends at https://www.meetgradient.com/, https://rewst.io/ https://augmentt.com/ and newly added Domotz and Guardz!
As each year around this time I'm proud to announce our event sponsor; Right of Boom. If you aren't aware yet, CyberDrain is at the Right of Boom event this year with our CyberDrain Skill Journey preday. This preday is an action packed session that teaches you all about managing M365 with CIPP. We're also giving you a voucher for an M365 fundamentals exam.
What's Changed
- Update CippTransportRuleDrawer.jsx by @Zacgoose in #4988
- Fix: Add condition for copying sent items based on recipient type and rename field by @kris6673 in #4992
- Dev to hotfix by @JohnDuprey in #4994
- Feat: Add custom group assignment option for Intune applications and enhance assignment dialogs by @kris6673 in #4996
- Dev to hotfix by @KelvinTegelaar in #5007
- Add Admin Role Reporting to MFA User List by @ZenTopBrandon in #5014
- feat: Add multi-group selection support for Add to Group user action by @kris6673 in #5019
- Feat: Intune assignments overhaul by @kris6673 in #5013
- Fix SMTP Auth alerts by @JyskIT-DK in #5010
- Fix: Update alert icons to use MUI for consistency by @kris6673 in #5004
- Chore: Update confirmation messages to include userPrincipalName by @kris6673 in #5025
- Feat: Add Discovered Apps Intune page by @kris6673 in #5034
- Add tooltips to input fields for truncated labels by @Copilot in #5051
- Add TaskState filters to CA Vacation Mode page by @Copilot in #5050
- Feat: Add alert for quarantine release requests and rename frontend alert agent by @kris6673 in #5068
- Feat: Add auto-archiving configuration standard by @kris6673 in #5077
- Feat: Add validators to the standards by @kris6673 in #5078
- Fix: Users bulk actions, set out of office options in UI by @kris6673 in #5081
- exclude all tenant user template from template list page by @Zacgoose in #5083
- Add alert for Global Admins outside approved list by @MWG-Logan in #5088
- Add reference and post execution fields to forms by @Zacgoose in #5086
- Feat: Add MDM enrollment standard for registration process by @kris6673 in #5089
- Feat: Add 14-day and 21-day recurrence intervals for alert scheduling… by @kris6673 in #5090
- Feat: Add toggle for displaying more partner relationships by @kris6673 in #5100
- Dev to release by @KelvinTegelaar in #5104
New Contributors
- @ZenTopBrandon made their first contribution in #5014
Full Changelog: v8.7.0...v8.8.0
What's Changed on the API
- Add Admin Role Reporting to MFA User List by @ZenTopBrandon in KelvinTegelaar/CIPP-API#1723
- Feat: Intune assignments overhaul by @kris6673 in KelvinTegelaar/CIPP-API#1722
- Feat: Add QuarantineReleaseRequests alert for handling quarantine release requests by @kris6673 in KelvinTegelaar/CIPP-API#1733
- Fix PWPush Pro account dropdown not populating by @lacymooretx in KelvinTegelaar/CIPP-API#1730
- Improve tenant filtering in audit log rules by @Zacgoose in KelvinTegelaar/CIPP-API#1726
- Return AllTenants user templates along with specific tenant user templates by @Zacgoose in KelvinTegelaar/CIPP-API#1731
- Fix: Loading issue for ListMailQuarantine with allTenants by @kris6673 in KelvinTegelaar/CIPP-API#1732
- Feat: Improve JIT Admin creation and copy button behavior by @kris6673 in KelvinTegelaar/CIPP-API#1736
- Feat: Add auto-archiving configuration standard by @kris6673 in KelvinTegelaar/CIPP-API#1737
- Add Get-CIPPAlertGlobalAdminAllowList function and tests by @MWG-Logan in KelvinTegelaar/CIPP-API#1741
- Add includeAllTenants flag to user defaults listing by @Zacgoose in KelvinTegelaar/CIPP-API#1739
- Reference message for multiple endpoints including scheduled tasks by @Zacgoose in KelvinTegelaar/CIPP-API#1740
- Feat: Add MDM enrollment control during account registration by @kris6673 in KelvinTegelaar/CIPP-API#1743
- Remove Az.KeyVault 6.3.1 module and add KeyVault secret cmdlets ,updated dev workflow file by @Zacgoose in KelvinTegelaar/CIPP-API#1742
- Add function permissions cache and build script by @Zacgoose in KelvinTegelaar/CIPP-API#1747
- Dev to release by @KelvinTegelaar in KelvinTegelaar/CIPP-API#1748
New Contributors API
- @lacymooretx made their first contribution in KelvinTegelaar/CIPP-API#1730
Full Changelog: KelvinTegelaar/CIPP-API@8.7.2...8.8.0
v8.7.0 - Cocktail of The Week
Cocktail of the week?
So I like wordplay, I like being a bit on the nose with things, today is one of those where I figured that this release could be called the cocktail of the week, which actually is a cocktail. Don't believe me? check out the recipe here.. Now, prepare that drink, sit down, and we'll have a chat about all the cool new features and fixes we have for you.
Conditional Access, Vacations, and upgrades
We've had this awesome feature in our Conditional Access configuration for while; Vacation mode. A user goes on vacation, and gets temporarily excluded or included to a Conditional Access Policy or a location. We've figured we could improve on this even more so that's what we've done. Vacation mode now uses an exclusion group instead of just adding the user willynilly,
we've also improved vacation mode that IF a user is on vacation, and you have location based alerts setup that can exclude that user from location based alerting.
Of course, that's not all. We've decided to upgrade Conditional Access while we're at it. You now have a new checkbox to automatically create groups if they are missing. That means if you deploy a CA policy with a group that doesn't exist yet, we'll build the group for you.
Cool fact; if the group exists in the templates, we'll use that template to make sure its using the correct parameters. It's magic! Automagic!
Better Enterprise Application Deployment experience
The Enterprise application deployment experience has gotten to be a little complex with a lot of tasks, we decided we could do better, we wanted to ease the UX experience for you.
Its now as simple as going over to Tenant Administration -> Applications and clicking the button "Create Template from app" - That template is then deployable via standards, or via the one-off deployment and will include all the permissions for that application.
Expansion of our Dynamic Groups for tenants
Last release we've added our Dynamic Tenant Groups, this release we're expanding on that by adding the ability to use variables in these groups to sort tenants, and by adding the ability to add static groups to dynamic groups - giving you so much extra flexbility to create and customize groups to your heart content.
Secure Score Improvements
We've added filtering to our secure score pages so its easier to sort what tasks you still have to do, but we also added a pretty cool new standard. This standard allows you to set any secure score item to the status you want it to be. Using an external mail solution or AV? set all of those to "Resolved by Third Party" automagically. There's that word again, Automagic!
So many fixes
I'd love to sit her for a day and type out every single fix, but please check the full release notes and code below because we have so much being released in this one. :)
Sponsors
We extend our gratitude to our supporters at https://renroros.no/, https://immy.bot/, https://oit.co/, https://ninjaone.com/, Huntress at https://huntress.com/, https://halopsa.com/, https://www.deskdirector.com/, https://hudu.com/, our friends at https://www.meetgradient.com/, https://rewst.io/ https://augmentt.com/ and newly added Domotz and Guardz!
As each year around this time I'm proud to announce our event sponsor; Right of Boom. If you aren't aware yet, CyberDrain is at the Right of Boom event this year with our CyberDrain Skill Journey preday. This preday is an action packed session that teaches you all about managing M365 with CIPP. We're also giving you a voucher for an M365 fundamentals exam.
What's Changed
- Dev to hotfix by @JohnDuprey in #4861
- Display group type in labels for clarity by @kris6673 in #4885
- Fix: Fix skeleton loading display when propertyItems array is empty by @kris6673 in #4868
- Feat? Add default domain display for tenant details by @kris6673 in #4884
- Fix sorting for nested properties in tables by @kris6673 in #4873
- Input validation for CIPP Roles by @LoldenCode in #4875
- Edit transport rules, changed to draw by @Zacgoose in #4890
- Feat: Remove deprecated policy pages and update assignment filter pages by @kris6673 in #4889
- Feat: Add TeamsExternalChatWithAnyone standard by @kris6673 in #4908
- Update licenses to the latest version from Microsoft by @kris6673 in #4913
- Chore: Format code with Prettier and remove some unused imports by @kris6673 in #4933
- Feat: Improve license overview to show assigned users and license groups by @kris6673 in #4930
- Fix: Retrieval of FileVault key by @kris6673 in #4922
- Fix: group settings display issue by updating edit group links by @kris6673 in #4921
- [WIP] Add alert for tenants with report-only CA policies by @Copilot in #4946
- Feat: Add "Who can bypass the lobby?" setting to Teams meeting policy by @kris6673 in #4962
- Feat: Add bulk export functionality for selected rows in CSV and PDF formats by @kris6673 in #4961
- Feat: Add source of authority configuration by @kris6673 in #4951
- Fix:Consolidate hide/unhide actions for Global Address List visibility by @kris6673 in #4950
- Add filter controls to Secure Score recommendations view by @Copilot in #4966
- Feat: Add form reset on successful guest invitation by @kris6673 in #4969
- Dev to release by @KelvinTegelaar in #4977
New Contributors
- @Copilot made their first contribution in #4946
What's Changed in API
- Support for editing transport rules by @Zacgoose in KelvinTegelaar/CIPP-API#1690
- Fix BPA logging to include tenant information in error messages by @kris6673 in KelvinTegelaar/CIPP-API#1685
- Improve error logging in a few standards by @kris6673 in KelvinTegelaar/CIPP-API#1686
- Refactor logging and variable usage in assignment filter functions by @kris6673 in KelvinTegelaar/CIPP-API#1688
- Add organization ID as a reserved variable and update text replacement function by @ZenTopBrandon in KelvinTegelaar/CIPP-API#1689
- Feat: Add TeamsExternalChatWithAnyone standard by @kris6673 in KelvinTegelaar/CIPP-API#1691
- Update licenses to the latest version from Microsoft by @kris6673 in KelvinTegelaar/CIPP-API#1692
- Feat: Improve license overview to show assigned users and license groups by @kris6673 in KelvinTegelaar/CIPP-API#1696
- Fix: Retrieve FileVault key in addition to BitLocker key by @kris6673 in KelvinTegelaar/CIPP-API#1695
- Fix: Refactor group type determination logic for ListGroups and ListUserGroups by @kris6673 in KelvinTegelaar/CIPP-API#1693
- Fix: Filter out excluded licenses in Sync-CippExtensionData function by @kris6673 in KelvinTegelaar/CIPP-API#1697
- Fix: Office App deployment issues by @kris6673 in KelvinTegelaar/CIPP-API#1699
- Chore: Move Invoke-RemoveQueuedApp to correct folder by @kris6673 in KelvinTegelaar/CIPP-API#1694
- [WIP] Add alert for tenants with report-only CA policies by @Copilot in KelvinTegelaar/CIPP-API#1704
- Fix: Exclude bulk registration accounts from MFA alerts and improve alert structure by @kris6673 in KelvinTegelaar/CIPP-API#1698
- Chore: Better admin roles member listing,improve error handling and standardize function casing by @kris6673 in KelvinTegelaar/CIPP-API#1700
- Re-add business premium capability by @chase-vgo in KelvinTegelaar/CIPP-API#1706
- Fix: Refactor Teams global meeting policy to include AutoAdmittedUsers setting by @kris6673 in KelvinTegelaar/CIPP-API#1709
- Feat: Add functions to manage SOA by @kris6673 in KelvinTegelaar/CIPP-API#1705
- Feat: Fix ExpiringLicenses alert firing issue and enhance alert data structure by @kris6673 in KelvinTegelaar/CIPP-API#1708
- Add SecureScoreRemediation standard for bulk Secure Score control updates by @Copilot in KelvinTegelaar/CIPP-API#1711
- Dev to release by @KelvinTegelaar in KelvinTegelaar/CIPP-API#1712
New Contributors
- @ZenTopBrandon made their first contribution in KelvinTegelaar/CIPP-API#1689
- @Copilot made their first contribution in KelvinTegelaar/CIPP-API#1704
Full Changelog: KelvinTegelaar/CIPP-API@8.6.2...8.7.0
Full Changelog: https://github.com/KelvinTegelaar/CI...
v8.6.0 - Woo Woo
Woo Woo!?
This release is named the Woo Woo, because what I really wanted to woo everyone using it, and everyone that doesn't yet. Did it work? Well, if it didn't, go to our friends over at Opendrinks to go get yourself a Woo Woo
Lets get down to business. We have some awesome new features and some great QoL stuff in this release. Lets start with something a little dynamic shall we?!
Dynamic Tenant Groups
So imagine, you're messing around with your tenant groups and you've created a bunch of them but now you have to maintain those. Everyone is constantly adding or removing licenses or packages at your MSP so it becomes complex to keep these up to date right?
Well, no more. We're introducing Dynamic Tenant Groups. This allows you to create tenant groups that are based on a tenants license, available features, and more. We even give you default groups such as "M365 Business Premium" and "Entra Premium" groups so you can easily get started using our examples.
Want to see it in action? check out our storylane here: https://app.storylane.io/share/idk6ryipa9ch
Release notes in app
So we've had some questions from users of the app; Where can they find the latest release notes without leaving? some engineers don't check Github or aren't active in discord. Well, you might just be reading these directly from the application. There's even a handy button to switch releases at the top if you want to catch up. As easy as reading your favourite webcomic.
Fixes Fixes Fixes
There's been so much QoL and bugfixes again, or new features that are just amazing, let's list the important ones and get back to your day job.
- Fixed an issue with internal references not loading
- Fixed an issue with Partner webhooks/automated onboarding not populating the fields
- Fixed an issue with Standards allowing blank tenants
- Added a new alert for MX record monitoring
- Fixed issues with group templates and deployment of groups
- Fixed an issue with repeat alerts for breach detection
- Added more deleted item types to delete items list
- Added group visibility option in the group management section
- Fixed dark and light mode HTML and PSA emails
- Added the ability to retrieve filevault keys
- Fixed an issue with duplicate app detection when deploying chocolatey or winget apps.
- Improved UX for badges in tables with different colours
Sponsors
We extend our gratitude to our supporters at https://renroros.no/, https://immy.bot/, https://oit.co/, https://ninjaone.com/, Huntress at https://huntress.com/, https://halopsa.com/, https://www.deskdirector.com/, https://hudu.com/, our friends at https://www.meetgradient.com/, https://rewst.io/ https://augmentt.com/ and newly added Domotz and Guardz!
As each year around this time I'm proud to announce our event sponsor; Right of Boom. If you aren't aware yet, CyberDrain is at the Right of Boom event this year with our CyberDrain Skill Journey preday. This preday is an action packed session that teaches you all about managing M365 with CIPP. We're also giving you a voucher for an M365 fundamentals exam.
Seats are limited, and early bird is ending soon. If you want to be able to get your CIPP certifications, please head on over to the registration page here
Already registered? Scared of going alone? Understanding that learning is more fun together? Register for a chance to win a second ticket for a colleague or friend then go to this page
What's Changed for API
- Feat: Add Invoke-ListGitHubReleaseNotes function for GitHub release retrieval by @kris6673 in KelvinTegelaar/CIPP-API#1676
- Feat: New standard to control BitLocker key recovery for owned devices by @kris6673 in KelvinTegelaar/CIPP-API#1675
- Fix: Enhance EntraConnectSyncStatus alert with detailed information by @kris6673 in KelvinTegelaar/CIPP-API#1678
- Refactor Reference assignment in GDAP invite script by @Zacgoose in KelvinTegelaar/CIPP-API#1677
- LAPS not LAPs by @isgq-github01 in KelvinTegelaar/CIPP-API#1679
- Feat: Logging improvements, add AllTenants support for listing tenant allow/blocklist by @kris6673 in KelvinTegelaar/CIPP-API#1674
- Fix: Refactor Invoke-ExecJITAdmin and add Invoke-ListJITAdmin by @kris6673 in KelvinTegelaar/CIPP-API#1680
- Feat: Add support for setting group visibility in Microsoft 365 groups by @kris6673 in KelvinTegelaar/CIPP-API#1681
- Fix: Remove wrong license check by @kris6673 in KelvinTegelaar/CIPP-API#1682
- Dev top release by @KelvinTegelaar in KelvinTegelaar/CIPP-API#1683
Full Changelog: KelvinTegelaar/CIPP-API@8.5.2...8.6.0
What's Changed
- Dev to hotfix by @JohnDuprey in #4784
- Fix: EDR only assignment and remove deprecated option by @kris6673 in #4793
- Feat: Enable multiple selections for user permissions and refactor alias handling by @kris6673 in #4796
- Feat: Add Transport and Connector drawers by @kris6673 in #4783
- Fix: Replace removed add pages with drawer buttons by @kris6673 in #4803
- Reset form values on successful shared mailbox creation by @kris6673 in #4811
- Dev to hotfix by @JohnDuprey in #4812
- Feat: Add pop-up notification for new releases by @kris6673 in #4815
- Feat: Add refresh functionality for Out Of Office data and fix contact permissions fetching by @kris6673 in #4819
- Feat: New standard to control BitLocker key recovery for owned devices by @kris6673 in #4814
- Fix: Readd "View release notes" button by @kris6673 in #4823
- It's LAPS not LAPs :P by @isgq-github01 in #4827
- Fix: Enhance state badge UX in lists by @kris6673 in #4830
- Feat: Add AllTenants support for tenant allow/block list by @kris6673 in #4813
- Fix: Update API URL for listing JIT Admins by @kris6673 in #4829
- (bug): Adjusted data handling to handle cases where ForwardingAddress… by @Jr7468 in #4840
- Feat: Add visibility option to M365 Group settings by @kris6673 in #4839
- Fix: Update confirmation texts to include device names and add condition for FileVault action by @kris6673 in #4845
- Fixes for deploying new EXO rule by @Zacgoose in #4847
- Dev to release by @KelvinTegelaar in #4857
- fix typo by @JohnDuprey in #4858
Full Changelog: v8.5.0...v8.6.0