← Back to all sparks
M

ManageEngine M365 Security Plus

ANALYTICS
Velocity5.0

Microsoft 365 security monitoring, auditing, and threat protection tool.

An on-prem M365 auditing tool whose releases are mostly dependency hygiene.

microsoft-365security-auditingon-premisesdependency-upgradesbackupcompliance
Current state
M365 Security Plus is an on-premises Java application for auditing and alerting on Microsoft 365 activity, shipped as numbered builds a few times a year. The last two builds are typical of the pattern: 4821 upgrades the bundled JRE from Java 8 to 11 and refreshes 7-Zip and Jackson libraries, while 4820 carries the only real functional work in the window — mailbox backups to local, shared, or NAS repositories, PST splitting for large exports, bulk mailbox selection from CSV, and audit logs that show object names instead of GUIDs. Security fixes appear in nearly every build.
Where it's heading
Two forces set the release agenda, and neither is a roadmap. The first is Microsoft: deprecated cmdlets forced an audit rewrite onto Get-MessageTraceV2, and a tenant configuration change broke onboarding until build 4817 patched around it. The second is the supply chain — Log4j, Tomcat, Bouncy Castle, Zulu JRE, and now the Java 8 to 11 jump, all tracked build by build because on-premises customers inherit whatever the vendor bundles. The product work that does land clusters around the Backup module, which is the one area growing rather than being maintained.
Prediction
With the JRE finally past Java 8, Tomcat 9 is the next end-of-life dependency in the bundle, and the Backup module's steady additions suggest export and retention options continue there.

Recent moves

  1. 20d ago

    Build 4821: bundled JRE moves to Java 11

    The bundled runtime moves from Java 8 to Java 11, with 7-Zip and Jackson refreshed alongside. Overdue platform hygiene for an on-prem deployment, but nothing an administrator sees in the product.

  2. 1mo ago

    Build 4820: NAS backup targets, PST splitting, readable audits

    The only build in this window with substantial functional work: mailbox backups can target local, shared, or NAS repositories, PST exports can be split, mailbox selections import in bulk from CSV, and audit reports show object names rather than GUIDs. A path-traversal file-deletion flaw is fixed in the same release.

  3. 2mo ago

    Build 4817: tenant configuration unblocked

    A single fix for a Microsoft-side change that blocked organizations from completing tenant configuration. Blocking for new deployments, invisible to everyone already running.

  4. 4mo ago

    Build 4816: Export Graph data-access fix and Log4j upgrade

    A security-focused build: an unauthorized data access issue in the dashboard's Export Graph is fixed, Log4j moves to 2.25.3, Tomcat to 9.0.115, and legacy JARs are removed. Housekeeping, but the kind on-prem customers must act on because they own the deployment.

  5. 6mo ago

    Build 4814: Duo SDK update before certificate expiry

    A time-boxed update: the Duo Universal Java SDK moves to 1.3.1 for Duo's new certificate authority bundle, with a hard deadline before technician authentication starts failing. Dependency work with an operational cost attached to ignoring it.

  6. 7mo ago

    Build 4811: proxy, scheduler, and SSL launch fixes

    Tomcat and Zulu JRE bumps plus four fixes, including Exchange Online connections failing behind an authenticated proxy and a scheduler showing the wrong time. Routine maintenance across unrelated corners.