Maester v2.2 Released!

It's here! I've known this was coming for a little while and been keen to fire up the changes but in case you missed it Maester v2.2 has been officially released out into the wild! I'll keep this bad boy short and cover the main important bits, most of these outlined in the Maester blog post above of course and I am but a parrot.
To outline the highlights from the Maester team directly:
- 269 Active Directory checks across identity, policy, infrastructure, DNS, trusts, replication, and access control
- 5 Microsoft Purview checks to get your data security foundations ready for Copilot and AI
- 12 new SharePoint Online checks across the CIS and CISA baselines, now cross-platform with PnP.PowerShell
- 5 CIS GitHub organization controls and first-class GitHub connectivity
- 9 Global Secure Access checks for Private Access, forwarding profiles, Compliant Network, and Internet Access
- 4 Intune endpoint security checks for LAPS, attack surface reduction, App Control for Business, and Managed Installer
- New Entra ID checks covering agent risk, directory sync safeguards, Conditional Access gaps, legacy MSOnline, and privileged first-party apps
- A sharper report with markdown summaries, per-test durations, and critical findings sorted first
- Contributor credits across maester.dev, so the people writing these tests get the recognition they deserve
From this, for me, the biggest addition is absolutely the 269 Active Directory checks! This is huge. Massive shout out to Mike Soule for these AD test integrations. It's such a fantastic additional layer of coverage. I am absolutely an Entra fanboi for sure, but cutting my teeth on Active Directory when I was in my early days of IT I wish this level of audit existed! Given how many businesses, small and large, still rely on their Active Directory infrastructure you'd be mad not to set this bad boy up alongside the cloud based tests and give yourself full coverage.
269 opt-in Active Directory checks across 19 areas which includes:
- Users, groups, computers, and service principal names
- Password policy and fine-grained password policy
- Domain, forest, domain controller, site, subnet, and replication health
- DNS, trusts, schema, and directory configuration
- Group Policy inventory and state
- DACL and privileged access analysis
And as stated in the release post, it's opt in by design. A default Connect-Maester -Service All is not going to touch domain controllers, you require an explicit Connect-Maester -Service ActiveDirectory to do so.
One of the greatest additions is the integration of a new Maester Contributors page to outline each person who's contributed to the project. It's such a lovely touch and shows that the Maester team are primarily focused on ensuring open source contributions.

Similarly, if you've not been aware, Merill has pivoted to be working on the Maester project full time, pushing towards his new Maester Cloud solution, building upon Maester to provide hosted solutions with a whole bunch of extra features. This is something I'll absolutely be purchasing for not only myself, but for client work to help provide monitored services across the board.
This release also marks a new chapter for me personally. I (Merill) am now working on Maester full time: maintaining the open core, keeping the checks current as Microsoft 365 changes, and giving this community the focus it deserves.
The people and organizations below were the first to back that decision through Maester Cloud. Their support creates the space for me to do this work every day, while keeping Maester's core framework and tests open and available to everyone. Every person who runs Maester benefits from their early belief in what this project can become.
Go check it out. Get that install going. Go run those new tests!