Nightly Maintenance
CONFIG365 runs a set of automated maintenance tasks every night at 4 AM UTC. Each task is independently configurable at the baseline level (applying to all tenants) and at the tenant level (overriding or extending baseline rules).
Overview
Nightly at 4 AM UTC
maintenance-pipeline.yml
Maintenance tab in the web portal
Config storage: Each task reads a JSON config file from the baseline repository and optionally from the tenant repository at config/maintenance/. Tenant entries with the same id field override the baseline entry — all other baseline rules still apply.
Pipeline parameters
| Parameter | Default |
|---|---|
whatIfMode | false |
debugMode | false |
Maintenance Tasks
Group Split Rebalancing
Automatically rebalances Entra group members across child groups according to configured percentages. Only moves members that are in the wrong child group — devices/users already in the correct group are untouched.
Config file
baseline/maintenance/group-splits.json
config/maintenance/group-splits.json (tenant override)
Required permissions
GroupMember.Read.AllGroup.ReadWrite.All
Config shape
{
"groupSplits": [
{
"id": "split-abc",
"displayName": "Modern Workplace Device Split",
"sourceGroupId": "xxxxxxxx-...",
"sourceGroupName": "Baseline - Modern Workplace Devices",
"targetGroups": [
{ "groupId": "xxxxxxxx-...", "name": "Group A (30%)", "percentage": 30 },
{ "groupId": "xxxxxxxx-...", "name": "Group B (70%)", "percentage": 70 }
],
"filters": {
"groupOperator": "and",
"groups": [
{
"operator": "and",
"rules": [
{ "field": "trustType", "operator": "eq", "value": "AzureAd" },
{ "field": "lastActivity", "operator": "withinDays", "value": 90 }
]
}
]
}
}
]
} Member filter fields
| Field | Applies to |
|---|---|
trustType | Device |
lastActivity | Device |
osType | Device |
mdmManaged | Device |
lastSignIn | User |
hasLicense | User |
Filter groups support AND/OR logic between rules, and AND/OR logic between groups.
- – Percentages do not need to sum to 100 — unallocated members remain in the source group.
- – The "minimal moves" algorithm only reassigns members that need to change groups.
- – Optional member filters support AND/OR logic across device and user properties.
Exchange Default Font Configuration
Sets the default Outlook font name and size for every mailbox-enabled member of the configured Entra groups. Uses delegated Exchange Online authentication (same Graph access app as tenant connect).
Config file
baseline/maintenance/exchange-fonts.json
config/maintenance/exchange-fonts.json (tenant override)
Required permissions
Group.ReadWrite.AllExchange.Manage
Config shape
{
"exchangeFonts": [
{
"id": "font-abc",
"displayName": "Marketing default font",
"groupId": "xxxxxxxx-...",
"groupName": "Marketing Team",
"fontName": "Aeroport Light",
"fontSize": 11
}
]
} - – Requires delegated Exchange.Manage on the Graph access app and a completed tenant Connect (device code) in the portal.
- – Tenant rules override baseline rules with the same id.
- – External users (#EXT#) are automatically excluded.
Exchange GAL Visibility
Hides or shows all mailbox-enabled members of an Entra group in the Exchange Online Global Address List. Setting hidden: true calls Set-Mailbox -HiddenFromAddressListsEnabled $true on each member.
Config file
baseline/maintenance/exchange-gal-hide.json
config/maintenance/exchange-gal-hide.json (tenant override)
Required permissions
Group.ReadWrite.AllExchange.Manage
Config shape
{
"galHideRules": [
{
"id": "gal-abc",
"displayName": "Hide Service Accounts from GAL",
"groupId": "xxxxxxxx-...",
"groupName": "Service Accounts",
"hidden": true
}
]
} - – Set hidden: false to re-show previously hidden users in the GAL.
- – Requires delegated Exchange.Manage the same as Exchange Font Configuration.
- – Tenant rules override baseline rules with the same id.
Intune Device Auto-Rename
Renames enrolled Intune devices that are members of an Entra group to the format PREFIX-USER5RAND2. Devices already matching the format are skipped to avoid unnecessary restarts.
Config file
baseline/maintenance/intune-device-rename.json
config/maintenance/intune-device-rename.json (tenant override)
Required permissions
GroupMember.Read.AllDevice.Read.AllDeviceManagementManagedDevices.ReadWrite.AllDeviceManagementManagedDevices.PrivilegedOperations.All
Config shape
{
"renameRules": [
{
"id": "rename-abc",
"displayName": "Rename SON devices",
"groupId": "xxxxxxxx-...",
"groupName": "Baseline - Modern Workplace Devices",
"prefix": "SON"
}
]
} - – PREFIX is 1–3 uppercase alphanumeric characters configured per rule.
- – USER5 is the first 5 alphanumeric characters of the primary user's display name, uppercased and right-padded with X if shorter.
- – RAND2 is 2 random uppercase alphanumeric characters generated at rename time.
- – Skip check: device name matches ^PREFIX-[A-Z0-9]{7}$ (case-insensitive) → already renamed, no action taken.
- – The rename API is a beta endpoint (graph.microsoft.com/beta). A device restart is required for the new name to take effect in Windows.
- – DeviceManagementManagedDevices.PrivilegedOperations.All is required specifically for the setDeviceName action — ReadWrite.All alone is not sufficient.
Execution Order
Tasks run sequentially, each in its own Gitea Actions job. A failure in one task does not stop subsequent tasks — each job uses if: always() to continue on failure.
- 1
GroupSplits— Group Split Rebalancing - 2
ExchangeFonts— Exchange Default Font Configuration - 3
ExchangeGalHide— Exchange GAL Visibility - 4
IntuneDeviceRename— Intune Device Auto-Rename - 5
MaintenanceSummary— Summary report (always runs)