Skip to content

Security: Inforeality/m365-identity-automation

Security

SECURITY.md

Security

Safe use

  • Use delegated access and the least Graph scopes needed for the selected report.
  • Do not place client secrets, certificates, tokens, tenant IDs, exported reports, or real user data in this repository.
  • Treat generated identity reports as sensitive and store them according to organizational policy.
  • Test thresholds and filters in a non-production tenant.
  • Review every proposed action before enabling -Apply.

The module does not log access tokens. Its action example requires PowerShell confirmation, -Apply, and the phrase DISABLE GUEST.

Reporting a vulnerability

Open a GitHub security advisory for this repository. Do not include tenant information, tokens, personal data, or exploit data in a public issue.

Supported versions

Security fixes target the latest version recorded in VERSION.

There aren't any published security advisories