Generally Available — contact us for access

Configuration-as-Code
Orchestration Platform
for Microsoft 365

Deploy configs. Detect drift. Stay compliant — across all your tenants, automated with GitOps. A self-hosted alternative to SaaS M365 baseline platforms, running entirely on infrastructure you control.

One container · portal + backend included Gitea Actions · Git-native CI/CD Hosted portal · No local tools required
Self-Hosted
Single container deploy
GitOps
Git-native CI/CD
Nightly
Automated tenant backups
Unlimited
Tenants supported
The Orchestrator

GitOps for Microsoft 365

Define your M365 tenant configuration as JSON in Git. Every change goes through a mandatory WhatIf preview and a human approval gate before anything is applied — with a full backup committed immediately after.

01
WhatIf Preview

Every run starts with a mandatory diff — see exactly what will be created, updated, or deleted before anything changes.

02
Approval Gate

A human reviews the WhatIf report and approves in the CONFIG365 portal. No change reaches a tenant without sign-off.

03
Apply Changes

Microsoft Graph, Exchange, Security & Compliance, and SharePoint PowerShell deploy every resource — groups, policies, Intune configs, sensitivity labels, SpoTenant settings, apps, auth policies, Teams — with detailed per-item feedback.

04
Automated Backup

Immediately after deploy, the full tenant configuration is exported and committed to Git. Also runs nightly at 2 AM UTC.

Enterprise Baseline

A complete, opinionated M365 configuration — Conditional Access, Intune, Defender, identity policies, and more. Phish-resistant and Zero Trust out of the box.

Why CONFIG365?

Built to solve the real operational problems of managing M365 at scale — not a generic automation wrapper, but a purpose-built system for MSPs and IT teams who own many tenants.

{{GROUP:name}}

Groups First

Use {{GROUP:name}} templates in your configs. CONFIG365 resolves names to IDs at deployment, so one baseline works everywhere.

GitOps Native

Gitea Actions workflows with WhatIf preview, approval gates, and full audit trail. Every change tracked in Git history on your own Gitea instance.

Multi-Tenant Ready

One baseline repository, deploy to unlimited tenants. Separate assignments per tenant, consistent configurations.

Detailed Feedback

Clear, actionable output for every policy. Know exactly what changed, what failed, and why. No more cryptic DSC errors.

GCC High Support

Full support for Government Cloud environments. Same workflows, same baselines, just point to the right cloud.

Separate Assignments

Policy configs and assignments in separate files. Change who gets a policy without touching the policy itself.

Daily Automated Backups

Every client's full M365 configuration is exported to Git each night. Full point-in-time restore from any date in history.

.baseline-ignore

Per-Client Flexibility

A .baseline-ignore file in each tenant repo lets MSPs opt specific policies out per client without touching the shared baseline.

CONFIG365:IGNORE

Resource Protection

Any M365 resource with CONFIG365:IGNORE in its description is skipped. Clients can lock their own customizations from being overwritten.

No Local Tools Required

The CONFIG365 portal is a hosted web application — MSP staff need only a browser. No PowerShell, no modules, no local setup. Everything is managed through the UI.

Minimal Attack Surface

CONFIG365 runs as a single OCI container — on Azure Container Apps, Azure App Service, or any Docker host. The management portal, Gitea, and the runner are all bundled inside. No third-party SaaS ever touches your tenant credentials.

App Deployment Built In

Deploy Win32 LOB apps from Chocolatey or WinGet, push mobile apps via Intune, and manage Enterprise App registrations — all from JSON in Git.

Dynamic Group Targeting

Define security groups in JSON with dynamic membership rules. Use {{GROUP:name}} placeholders in any policy — CONFIG365 resolves IDs at deploy time.

groups-config.json

Baseline Policy Groups

Segment baseline files into named groups and restrict deployment to member tenants only. Folders, glob patterns, and individual files — enforced automatically across every config script.

OS Version Control

Set minimum OS thresholds for Android, iOS, Windows, and macOS across compliance and app-protection policies in one view. Latest OS versions are fetched automatically, Defender device backups surface impacted devices per tenant, and updates apply across all targets in a single operation.

Hosted Web Application · Bundled with CONFIG365

The Management Portal

A full-featured admin interface included in your CONFIG365 container. Manage tenants, trigger deployments, review WhatIf diffs, and approve pipeline runs — all from your browser.

Tenant Dashboard

Multi-tenant overview — pipeline status, last backup time, and one-click deploy or approve for every client.

WhatIf Preview

Review every create, update, and delete before it applies. Approve or reject with full diff visibility.

Policy Viewer

Browse any tenant's backed-up configuration with filename and content search, a resizable file tree, and one-click promote to baseline.

App Deployment

Deploy Win32 apps via Chocolatey or WinGet, push mobile apps through Intune, and manage enterprise app registrations — all from JSON in Git.

Baseline Viewer

Compare a tenant's live backup against the shared baseline. Surface deviations and conflicting tenant-only overrides at a glance.

Timeline

Full deployment history with per-commit diffs. Restore any resource to a previous state directly from the UI.

Group Management

Define Entra ID groups as JSON with dynamic membership rules. Baseline-group targeting restricts policies to the right tenant set automatically.

Maintenance Tasks

Run scheduled or on-demand operations: group splits, Exchange font defaults, GAL visibility, and Intune device renaming.

Prefer running it yourself over SaaS lock-in?

CONFIG365 covers the same ground — M365 baselines, multi-tenant deploy, and drift control — as GitOps you host yourself. Credentials stay in your container. Get in touch and we'll walk you through licensing and onboarding.