Orchestrator

Orchestrator Documentation

Technical reference for the CONFIG365 Orchestrator — pipeline configuration, drift detection, deployment automation, and multi-tenant management.

Getting Started

Architecture & Structure

Operations

Tenant Onboarding

7 min read

End-to-end guide for onboarding a new tenant: discovery, admin consent, repo setup, configuration review, testing, production deployment, and handoff.

OnboardingAdmin ConsentVariable GroupsTesting

Baseline Repository Setup

5 min read

How to create and populate the baseline config repository — exporting from a reference tenant, manual JSON creation, placeholders, and ongoing maintenance.

baselineJSON ConfigsPlaceholdersMaintenance

Configuration Examples

8 min read

JSON examples for all supported resource types: Conditional Access, security groups, Intune compliance policies, authentication methods, and Exchange transport rules.

JSONConditional AccessIntuneExchange

Baseline Policy Groups

6 min read

Segment baseline files into named groups and restrict deployment to member tenants only. Supports direct membership (per-tenant) and dynamic license-based rules that auto-include tenants holding specific M365 SKUs — evaluated live at deploy time.

groups-config.jsonLicense RulesDynamic MembershipDeployment Enforcement

Nightly Maintenance

6 min read

Configure automated nightly tasks: group split rebalancing with member filters, Exchange default font configuration, GAL visibility control, and Intune device auto-rename.

MaintenanceGroup SplitsExchangeIntuneRename

Defender for Endpoint Device Backup

5 min read

How CONFIG365 backs up the full MDE device inventory to the tenant Git repo — required delegated API permissions (Machine.Read), backup file structure, device record shape, and app protection integration.

MDEMachine.ReadDevice InventoryApp ProtectionBackup

OS Version Control

5 min read

Manage minimum OS versions for Windows, macOS, iOS, and Android across compliance and app-protection baseline policies. Latest OS versions are fetched automatically per platform. Detect impacted devices per tenant from Defender backups and apply threshold updates across the baseline in one operation.

Compliance PoliciesApp ProtectionMAMImpacted Devices