Operations

Nightly Maintenance

CONFIG365 runs a set of automated maintenance tasks every night at 4 AM UTC. Each task is independently configurable at the baseline level (applying to all tenants) and at the tenant level (overriding or extending baseline rules).

6 min read Updated April 2, 2026

Overview

Schedule

Nightly at 4 AM UTC

Workflow

maintenance-pipeline.yml

Configure via

Maintenance tab in the web portal

Config storage: Each task reads a JSON config file from the baseline repository and optionally from the tenant repository at config/maintenance/. Tenant entries with the same id field override the baseline entry — all other baseline rules still apply.

Pipeline parameters

Parameter Default
whatIfMode false
debugMode false

Maintenance Tasks

Group Split Rebalancing

Automatically rebalances Entra group members across child groups according to configured percentages. Only moves members that are in the wrong child group — devices/users already in the correct group are untouched.

Config file

baseline/maintenance/group-splits.json

config/maintenance/group-splits.json (tenant override)

Required permissions

  • GroupMember.Read.All
  • Group.ReadWrite.All

Config shape

{
  "groupSplits": [
    {
      "id": "split-abc",
      "displayName": "Modern Workplace Device Split",
      "sourceGroupId": "xxxxxxxx-...",
      "sourceGroupName": "Baseline - Modern Workplace Devices",
      "targetGroups": [
        { "groupId": "xxxxxxxx-...", "name": "Group A (30%)", "percentage": 30 },
        { "groupId": "xxxxxxxx-...", "name": "Group B (70%)", "percentage": 70 }
      ],
      "filters": {
        "groupOperator": "and",
        "groups": [
          {
            "operator": "and",
            "rules": [
              { "field": "trustType", "operator": "eq", "value": "AzureAd" },
              { "field": "lastActivity", "operator": "withinDays", "value": 90 }
            ]
          }
        ]
      }
    }
  ]
}

Member filter fields

Field Applies to
trustType Device
lastActivity Device
osType Device
mdmManaged Device
lastSignIn User
hasLicense User

Filter groups support AND/OR logic between rules, and AND/OR logic between groups.

  • – Percentages do not need to sum to 100 — unallocated members remain in the source group.
  • – The "minimal moves" algorithm only reassigns members that need to change groups.
  • – Optional member filters support AND/OR logic across device and user properties.

Exchange Default Font Configuration

Sets the default Outlook font name and size for every mailbox-enabled member of the configured Entra groups. Uses delegated Exchange Online authentication (same Graph access app as tenant connect).

Config file

baseline/maintenance/exchange-fonts.json

config/maintenance/exchange-fonts.json (tenant override)

Required permissions

  • Group.ReadWrite.All
  • Exchange.Manage

Config shape

{
  "exchangeFonts": [
    {
      "id": "font-abc",
      "displayName": "Marketing default font",
      "groupId": "xxxxxxxx-...",
      "groupName": "Marketing Team",
      "fontName": "Aeroport Light",
      "fontSize": 11
    }
  ]
}
  • – Requires delegated Exchange.Manage on the Graph access app and a completed tenant Connect (device code) in the portal.
  • – Tenant rules override baseline rules with the same id.
  • – External users (#EXT#) are automatically excluded.

Exchange GAL Visibility

Hides or shows all mailbox-enabled members of an Entra group in the Exchange Online Global Address List. Setting hidden: true calls Set-Mailbox -HiddenFromAddressListsEnabled $true on each member.

Config file

baseline/maintenance/exchange-gal-hide.json

config/maintenance/exchange-gal-hide.json (tenant override)

Required permissions

  • Group.ReadWrite.All
  • Exchange.Manage

Config shape

{
  "galHideRules": [
    {
      "id": "gal-abc",
      "displayName": "Hide Service Accounts from GAL",
      "groupId": "xxxxxxxx-...",
      "groupName": "Service Accounts",
      "hidden": true
    }
  ]
}
  • – Set hidden: false to re-show previously hidden users in the GAL.
  • – Requires delegated Exchange.Manage the same as Exchange Font Configuration.
  • – Tenant rules override baseline rules with the same id.

Intune Device Auto-Rename

Renames enrolled Intune devices that are members of an Entra group to the format PREFIX-USER5RAND2. Devices already matching the format are skipped to avoid unnecessary restarts.

Config file

baseline/maintenance/intune-device-rename.json

config/maintenance/intune-device-rename.json (tenant override)

Required permissions

  • GroupMember.Read.All
  • Device.Read.All
  • DeviceManagementManagedDevices.ReadWrite.All
  • DeviceManagementManagedDevices.PrivilegedOperations.All

Config shape

{
  "renameRules": [
    {
      "id": "rename-abc",
      "displayName": "Rename SON devices",
      "groupId": "xxxxxxxx-...",
      "groupName": "Baseline - Modern Workplace Devices",
      "prefix": "SON"
    }
  ]
}
  • – PREFIX is 1–3 uppercase alphanumeric characters configured per rule.
  • – USER5 is the first 5 alphanumeric characters of the primary user's display name, uppercased and right-padded with X if shorter.
  • – RAND2 is 2 random uppercase alphanumeric characters generated at rename time.
  • – Skip check: device name matches ^PREFIX-[A-Z0-9]{7}$ (case-insensitive) → already renamed, no action taken.
  • – The rename API is a beta endpoint (graph.microsoft.com/beta). A device restart is required for the new name to take effect in Windows.
  • – DeviceManagementManagedDevices.PrivilegedOperations.All is required specifically for the setDeviceName action — ReadWrite.All alone is not sufficient.

Execution Order

Tasks run sequentially, each in its own Gitea Actions job. A failure in one task does not stop subsequent tasks — each job uses if: always() to continue on failure.

  1. 1
    GroupSplits — Group Split Rebalancing
  2. 2
    ExchangeFonts — Exchange Default Font Configuration
  3. 3
    ExchangeGalHide — Exchange GAL Visibility
  4. 4
    IntuneDeviceRename — Intune Device Auto-Rename
  5. 5
    MaintenanceSummary — Summary report (always runs)