Configuration-as-Code
Orchestration Platform
for Microsoft 365
Deploy configs. Detect drift. Stay compliant — across all your tenants, automated with GitOps. A self-hosted alternative to SaaS M365 baseline platforms, running entirely on infrastructure you control.
GitOps for Microsoft 365
Define your M365 tenant configuration as JSON in Git. Every change goes through a mandatory WhatIf preview and a human approval gate before anything is applied — with a full backup committed immediately after.
Every run starts with a mandatory diff — see exactly what will be created, updated, or deleted before anything changes.
A human reviews the WhatIf report and approves in the CONFIG365 portal. No change reaches a tenant without sign-off.
Microsoft Graph, Exchange, Security & Compliance, and SharePoint PowerShell deploy every resource — groups, policies, Intune configs, sensitivity labels, SpoTenant settings, apps, auth policies, Teams — with detailed per-item feedback.
Immediately after deploy, the full tenant configuration is exported and committed to Git. Also runs nightly at 2 AM UTC.
A complete, opinionated M365 configuration — Conditional Access, Intune, Defender, identity policies, and more. Phish-resistant and Zero Trust out of the box.
Why CONFIG365?
Built to solve the real operational problems of managing M365 at scale — not a generic automation wrapper, but a purpose-built system for MSPs and IT teams who own many tenants.
Groups First
Use {{GROUP:name}} templates in your configs. CONFIG365 resolves names to IDs at deployment, so one baseline works everywhere.
GitOps Native
Gitea Actions workflows with WhatIf preview, approval gates, and full audit trail. Every change tracked in Git history on your own Gitea instance.
Multi-Tenant Ready
One baseline repository, deploy to unlimited tenants. Separate assignments per tenant, consistent configurations.
Detailed Feedback
Clear, actionable output for every policy. Know exactly what changed, what failed, and why. No more cryptic DSC errors.
GCC High Support
Full support for Government Cloud environments. Same workflows, same baselines, just point to the right cloud.
Separate Assignments
Policy configs and assignments in separate files. Change who gets a policy without touching the policy itself.
Daily Automated Backups
Every client's full M365 configuration is exported to Git each night. Full point-in-time restore from any date in history.
Per-Client Flexibility
A .baseline-ignore file in each tenant repo lets MSPs opt specific policies out per client without touching the shared baseline.
Resource Protection
Any M365 resource with CONFIG365:IGNORE in its description is skipped. Clients can lock their own customizations from being overwritten.
No Local Tools Required
The CONFIG365 portal is a hosted web application — MSP staff need only a browser. No PowerShell, no modules, no local setup. Everything is managed through the UI.
Minimal Attack Surface
CONFIG365 runs as a single OCI container — on Azure Container Apps, Azure App Service, or any Docker host. The management portal, Gitea, and the runner are all bundled inside. No third-party SaaS ever touches your tenant credentials.
App Deployment Built In
Deploy Win32 LOB apps from Chocolatey or WinGet, push mobile apps via Intune, and manage Enterprise App registrations — all from JSON in Git.
Dynamic Group Targeting
Define security groups in JSON with dynamic membership rules. Use {{GROUP:name}} placeholders in any policy — CONFIG365 resolves IDs at deploy time.
Baseline Policy Groups
Segment baseline files into named groups and restrict deployment to member tenants only. Folders, glob patterns, and individual files — enforced automatically across every config script.
OS Version Control
Set minimum OS thresholds for Android, iOS, Windows, and macOS across compliance and app-protection policies in one view. Latest OS versions are fetched automatically, Defender device backups surface impacted devices per tenant, and updates apply across all targets in a single operation.
The Management Portal
A full-featured admin interface included in your CONFIG365 container. Manage tenants, trigger deployments, review WhatIf diffs, and approve pipeline runs — all from your browser.
Tenant Dashboard
Multi-tenant overview — pipeline status, last backup time, and one-click deploy or approve for every client.
WhatIf Preview
Review every create, update, and delete before it applies. Approve or reject with full diff visibility.
Policy Viewer
Browse any tenant's backed-up configuration with filename and content search, a resizable file tree, and one-click promote to baseline.
App Deployment
Deploy Win32 apps via Chocolatey or WinGet, push mobile apps through Intune, and manage enterprise app registrations — all from JSON in Git.
Baseline Viewer
Compare a tenant's live backup against the shared baseline. Surface deviations and conflicting tenant-only overrides at a glance.
Timeline
Full deployment history with per-commit diffs. Restore any resource to a previous state directly from the UI.
Group Management
Define Entra ID groups as JSON with dynamic membership rules. Baseline-group targeting restricts policies to the right tenant set automatically.
Maintenance Tasks
Run scheduled or on-demand operations: group splits, Exchange font defaults, GAL visibility, and Intune device renaming.
Prefer running it yourself over SaaS lock-in?
CONFIG365 covers the same ground — M365 baselines, multi-tenant deploy, and drift control — as GitOps you host yourself. Credentials stay in your container. Get in touch and we'll walk you through licensing and onboarding.