Workstation
- Windows 11 x64 with current security updates
- A supported HILOP 1.0 MSI installation
- At least 8 GB RAM and 1 GB free disk space recommended
- Working DNS, time synchronization, and trusted TLS certificate chains
- A Windows account with the AD, Entra, Intune, and Exchange rights required for each operation
The production MSI is self-contained. Installing a separate .NET runtime is not required.
Network access
HILOP requires outbound HTTPS access on TCP 443 to Little Innovation Tech licensing and documentation services and to the Microsoft identity, Graph, Intune, and Exchange endpoints for the selected cloud. Commercial uses Microsoft commercial endpoints; GCC High uses the corresponding US Government endpoints.
Proxies, TLS inspection, endpoint controls, and Conditional Access must permit HILOP interactive sign-in and provider traffic. HILOP does not require an inbound public listener.
Active Directory
- Network line of sight to a writable domain controller in the target forest, or a trusted route to the configured server
- Working AD-integrated DNS and Kerberos
- LDAP or LDAPS connectivity as required by local policy
- SMB, RPC endpoint mapping, and the organization's allowed dynamic RPC range where required
- Delegated AD permissions for every requested read or write; HILOP does not elevate the operator
- A valid default user container or OU distinguished name for creation workflows
Common ports include DNS 53, Kerberos 88, LDAP 389 or LDAPS 636, SMB 445, RPC endpoint mapper 135, and the domain's configured dynamic RPC range. Local firewall policy remains authoritative.
PowerShell
- PowerShell 7 is preferred for Exchange Online operations
- Windows PowerShell 5.1 is required when an Exchange On-Premises session or organization module requires it
- The Microsoft Exchange Online Management module must be installed and available to the signed-in operator for Exchange Online
- Execution policy, application control, and endpoint security must permit Microsoft management modules and approved HILOP scripts
Microsoft Entra application permissions
Interactive delegated access requires a public-client Entra application configured for the profile's cloud and tenant. Grant and administratively consent only the permissions required by enabled HILOP features.
User.Read: signed-in identity and interactive sessionUser.Read.All: user lookup and profile dataDirectory.Read.All: directory objects, licenses, and relationshipsAuditLog.Read.All: sign-in and directory audit factsUserAuthenticationMethod.Read.All: authentication methods and postureRoleManagement.Read.Directory: directory and PIM role informationIdentityRiskyUser.Read.All: user risk stateDeviceManagementManagedDevices.Read.All: Intune managed-device dataDeviceManagementManagedDevices.PrivilegedOperations.All: supported Intune device operationsBitLockerKey.Read.All: BitLocker recovery key revealDeviceLocalCredential.Read.All: Windows LAPS credential reveal and rotation support
Graph permissions do not replace Microsoft Entra roles, Intune RBAC, licensing, Conditional Access, or resource ownership requirements. Restart HILOP and sign in again after changing consent so the new token contains the updated grants.
Exchange Online
- Exchange Online Management module available in PowerShell
- Interactive sign-in permitted by Conditional Access
- An Exchange role group sufficient for each requested operation
- Commercial or GCC High selected correctly in the runtime profile
Exchange On-Premises
- Exchange remote PowerShell enabled and reachable from the HILOP workstation
- A connection URI such as
https://exchange.example.com/PowerShell/, or the organization's approved HTTP and Kerberos endpoint - Kerberos, Negotiate, or the authentication method required by the Exchange organization
- Exchange RBAC assignments sufficient for recipient reads and writes
- Trusted certificates and WinRM configuration appropriate to the connection URI
In hybrid environments, configure both providers when HILOP must read cloud-managed distribution groups or delegation and manage on-premises-authoritative recipient attributes.
Supported cloud boundary
HILOP 1.0 has been validated for Microsoft Commercial and GCC High environments. Microsoft 365 DoD is not currently validated or supported.
See the HILOP 1.0 Release Notes and Knowledgebase for current product scope.