- Run with the least privilege that exposes the required readiness signals.
- Do not commit exported state: it may contain device names, usernames, paths, IDs, or management configuration.
- Review JSON/CSV output before sharing and redact organizational identifiers.
- Validate suggested steps against current Microsoft documentation and local change controls.
- This toolkit does not store credentials or contact cloud services.
Report vulnerabilities with a private GitHub security advisory. Do not submit real endpoint exports or client information in public issues.