sqlcmd without -I causes the filtered index on ExternalId to fail silently,
leaving the schema half-applied. Reported by Firdous Parray.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Addresses external review feedback on the project.
- Add SecretProtector (Windows DPAPI, machine scope) and encrypt SMTP
password and Teams/Slack/generic webhook URLs at rest in the database.
Values are decrypted only in memory at send time; SMTP password is
never returned by the API. Legacy plaintext rows are read transparently.
- Rewrite README "Security & Maturity" section: honest beta positioning,
read-only/least-privilege scope, credential handling, and a host
hardening checklist (dedicated low-priv host, BitLocker, no public
exposure, rotation). Notes certificate auth as recommended next step.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Full-stack Microsoft 365 security monitoring dashboard built with
ASP.NET Core 8 + React 18 + TypeScript. Aggregates security signals
from Microsoft Graph API across Defender XDR, Entra ID Protection,
Intune, Exchange Online, and M365 Compliance into a single
self-hosted dashboard.
Features:
- 13 monitoring pages: Identity, Devices, Email, Incidents, Compliance,
Service Health, Licenses, Conditional Access, Audit Log, Sign-in Locations,
M365 Connectivity, Alert Center, Overview
- Alert Policy Engine with 9 pre-built templates and custom policy builder
- Detail modals with direct M365 portal deep links per item type
- Per-page search, filter, sort, CSV export, saved filter presets
- Dark/light mode, collapsible sidebar, toast notifications
- Responsive layout, sticky filter bars, sortable table columns
All credentials must be supplied via .NET User Secrets (dev) or
appsettings.Production.json (prod) — never committed to source.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>