Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
Expand Up @@ -26,22 +26,11 @@
"compare": "subset",
"variables": {
"ReviewerRoles": {
"type": "autoComplete",
"type": "AdminRolesMultiSelect",
"multiple": true,
"creatable": false,
"label": "App Consent Reviewer Role",
"omitWhenBlank": true,
"api": {
"url": "/api/ListGraphRequest",
"data": {
"Endpoint": "roleManagement/directory/roleDefinitions",
"$select": "id,displayName",
"$top": 999
},
"dataKey": "Results",
"labelField": "displayName",
"valueField": "id",
"queryKey": "ListEntraRoleDefinitions"
}
"label": "App Consent Reviewer Roles",
"omitWhenBlank": true
},
"ReviewerUsers": {
"type": "autoComplete",
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@
"cat": "Exchange Standards",
"tag": [],
"impact": "High Impact",
"helpText": "Disables Exchange Web Services (EWS) organization-wide. This reduces the attack surface by blocking legacy API access to mailbox data. Warning: This may break Office web add-ins on builds older than 16.0.19127.",
"helpText": "Disables Exchange Web Services (EWS) organization-wide. This reduces the attack surface by blocking legacy API access to mailbox data. Warning: This may break Office web add-ins on builds older than 16.0.19127. Conflicts with the \"Configure EWS allowed applications\" standard, which sets EwsEnabled to true: do not apply both to a tenant.",
"executiveText": "Disables Exchange Web Services (EWS) across the organization to reduce attack surface and prevent legacy API access to sensitive mailbox data. This aligns with Microsoft's Baseline Security Mode recommendation to minimize exploitable endpoints while requiring updates to applications that depend on EWS.",
"docsDescription": "Disables Exchange Web Services (EWS) at the organization level to reduce attack surface. EWS provides cross-platform API access to sensitive Exchange Online data such as emails, meetings, and contacts. If compromised, attackers can access confidential data, send phishing emails, or spoof identities. Disabling EWS also reduces legacy app usage and minimizes exploitable endpoints. Note that this may break first-party features including web add-ins for Word, Excel, PowerPoint, and Outlook on builds older than 16.0.19127.",
"impactColour": "danger",
Expand Down
97 changes: 97 additions & 0 deletions Config/BaselineStandards/Exchange Standards/EWSAllowedAppIds.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,97 @@
{
"name": "EWSAllowedAppIds",
"label": "Configure EWS allowed applications",
"cat": "Exchange Standards",
"tag": [],
"impact": "High Impact",
"helpText": "Adds the selected applications to the Exchange Online EWS app allow list (EwsAllowedAppIDs) and sets EwsEnabled to true. Apps already on the list are kept, and known-malicious apps are never added. Do not use together with the \"Disable Exchange Web Services\" standard on the same tenant: they set EwsEnabled to opposite values. Once CIPP writes the list, Microsoft stops auto-populating it for that tenant, so include every app the tenant needs (check the EWS usage report in the Microsoft 365 admin center). Changes can take up to 24 hours to apply. Keep \"Include the dedicated Exchange hybrid app\" on for hybrid organisations so Free/Busy and MailTips keep working.",
"executiveText": "Keeps the business applications that still rely on Exchange Web Services working as Microsoft retires unrestricted EWS access, by maintaining the approved-application list for each tenant. Existing approvals are preserved and applications known to be used in attacks are never approved.",
"docsDescription": "When EWS is enabled, Exchange Online only allows EWS access from the application IDs on the organization's EwsAllowedAppIDs list, and an empty list blocks all EWS. Microsoft populates that list from recent usage only while the admin has never set it, so the list CIPP writes must be complete. This standard reads the current list and adds the selected presets, the custom application IDs (tenant variables are supported, invalid IDs are skipped with a warning) and, optionally, every app that holds the Exchange Online full_access_as_app application permission or a delegated EWS permission, plus the dedicated Exchange hybrid app (ExchangeServerApp-*) that hybrid Free/Busy, MailTips, profile photos and archive moves depend on. IDs already on the list are never removed; the only exception is known-malicious apps (CIPP's curated list), which are removed only when that option is enabled and are reported as drift otherwise. Known-malicious apps are never added. This conflicts with the \"Disable Exchange Web Services\" standard. Changes can take up to 24 hours to take effect. See Microsoft's guidance on the deprecation of EWS in Exchange Online: https://learn.microsoft.com/en-us/exchange/clients-and-mobile-in-exchange-online/deprecation-of-ews-exchange-online",
"impactColour": "danger",
"addedDate": "2026-09-28",
"powershellEquivalent": "Set-OrganizationConfig -EwsEnabled $true -EwsAllowedAppIDs",
"recommendedBy": [],
"requiredCapabilities": [
"EXCHANGE_S_STANDARD",
"EXCHANGE_S_ENTERPRISE",
"EXCHANGE_S_STANDARD_GOV",
"EXCHANGE_S_ENTERPRISE_GOV",
"EXCHANGE_LITE"
],
"disabledFeatures": {
"report": false,
"warn": false,
"remediate": false
},
"secureScoreImpact": 0,
"compare": "subset",
"variables": {
"presets": {
"type": "autoComplete",
"multiple": true,
"creatable": false,
"label": "Known applications to allow",
"options": [
{
"label": "Microsoft Office",
"value": "MicrosoftOffice"
},
{
"label": "Microsoft Power Query for Excel",
"value": "PowerQuery"
},
{
"label": "Power BI Data Refresh",
"value": "PowerBIDataRefresh"
},
{
"label": "Apple Mail/Calendar (macOS)",
"value": "AppleMail"
},
{
"label": "AvePoint Cloud Backup / Fly / Cloud Governance (hosted)",
"value": "AvePointCloud"
},
{
"label": "AvePoint Fly Server",
"value": "AvePointFlyServer"
}
],
"default": [
"MicrosoftOffice",
"PowerQuery",
"PowerBIDataRefresh",
"AppleMail"
]
},
"customAppIds": {
"type": "autoComplete",
"multiple": true,
"creatable": true,
"required": false,
"label": "Additional application (client) IDs, tenant variables such as %veeam_ews_appid% are supported",
"default": []
},
"includeEwsPermissionApps": {
"type": "switch",
"label": "Include apps holding EWS permissions (full_access_as_app, EWS.AccessAsUser.All, full_access_as_user)",
"default": false
},
"includeHybridApp": {
"type": "switch",
"label": "Include the dedicated Exchange hybrid app (ExchangeServerApp-*)",
"default": true,
"recommended": true
},
"removeMaliciousApps": {
"type": "switch",
"label": "Remove known-malicious apps from the list",
"default": false
}
},
"read": {},
"prepare": "Get-CIPPBaselineEWSAllowedAppIdsState",
"remediate": {
"executor": "EWSAllowedAppIds"
}
}
10 changes: 10 additions & 0 deletions Config/CIPPTimers.json
Original file line number Diff line number Diff line change
Expand Up @@ -218,6 +218,16 @@
"TZOffset": true,
"IsSystem": true
},
{
"Id": "9792e664-002b-475e-a1c2-fd5d04b19a3f",
"Command": "Start-ReportAttachmentRetentionCleanup",
"Description": "Timer to cleanup report attachments uploaded to blob storage based on retention policy",
"Cron": "0 30 2 * * *",
"Priority": 23,
"RunOnProcessor": true,
"TZOffset": true,
"IsSystem": true
},
{
"Id": "5e8a9b4c-2d6f-4a3e-b7c1-9d0e5f3a8b2c",
"Command": "Start-IntuneReportExportOrchestrator",
Expand Down
25 changes: 21 additions & 4 deletions Config/LicenseCatalog.json
Original file line number Diff line number Diff line change
Expand Up @@ -204,14 +204,31 @@
]
},
{
"id": "windows",
"label": "Windows upgrade rights",
"description": "Upgrading Windows Pro to Enterprise or Business edition.",
"id": "windowsEnterprise",
"label": "Windows Enterprise upgrade rights",
"description": "Upgrading Windows Pro to Enterprise edition.",
"signal": null,
"servicePlanIds": [
"21b439ba-a0ca-424f-a6cc-52f954a5b111"
]
},
{
"id": "windowsBusiness",
"label": "Windows Business upgrade rights",
"description": "Upgrading Windows Pro to Business edition.",
"signal": null,
"servicePlanIds": [
"21b439ba-a0ca-424f-a6cc-52f954a5b111",
"8e229017-d77b-43d5-9305-903395523b99"
]
},
{
"id": "virtualDesktop",
"label": "Azure Virtual Desktop rights",
"description": "Rights to run Windows in Azure Virtual Desktop.",
"signal": null,
"servicePlanIds": [
"e7c91390-7625-45be-94e0-e16907e03118"
]
}
],
"families": [
Expand Down
Loading