Orchestrator Documentation
Technical reference for the CONFIG365 Orchestrator — pipeline configuration, drift detection, deployment automation, and multi-tenant management.
Architecture & Structure
Multi-Tenant Architecture
6 min readHow a single multi-tenant app registration manages all customer tenants via centralized credentials and per-tenant admin consent.
Repository Structure
4 min readThe four Gitea repository types — orchestrator, tenant-template, baseline, and tenant-{slug} — and how they relate to each other.
Operations
Tenant Onboarding
7 min readEnd-to-end guide for onboarding a new tenant: discovery, admin consent, repo setup, configuration review, testing, production deployment, and handoff.
Baseline Repository Setup
5 min readHow to create and populate the baseline config repository — exporting from a reference tenant, manual JSON creation, placeholders, and ongoing maintenance.
Configuration Examples
8 min readJSON examples for all supported resource types: Conditional Access, security groups, Intune compliance policies, authentication methods, and Exchange transport rules.
Baseline Policy Groups
6 min readSegment baseline files into named groups and restrict deployment to member tenants only. Supports direct membership (per-tenant) and dynamic license-based rules that auto-include tenants holding specific M365 SKUs — evaluated live at deploy time.
Nightly Maintenance
6 min readConfigure automated nightly tasks: group split rebalancing with member filters, Exchange default font configuration, GAL visibility control, and Intune device auto-rename.
Defender for Endpoint Device Backup
5 min readHow CONFIG365 backs up the full MDE device inventory to the tenant Git repo — required delegated API permissions (Machine.Read), backup file structure, device record shape, and app protection integration.
OS Version Control
5 min readManage minimum OS versions for Windows, macOS, iOS, and Android across compliance and app-protection baseline policies. Latest OS versions are fetched automatically per platform. Detect impacted devices per tenant from Defender backups and apply threshold updates across the baseline in one operation.