Configuration drift: why your audit was right, and no longer is

An audit report describes an environment on a date. Six months later it describes something else. What moves, how fast, and what can be done about it.

The scenario is always the same. A serious audit, a solid report, a prioritized action list. The actions get done. Everyone moves on. Eighteen months later, a new audit, and some of the same gaps are back — sometimes exactly the same ones.

This is not an execution problem. It is that the security of a configuration is not a state you reach, it is a state you hold, and nothing was in place to hold it.

What moves, and why

A Microsoft 365 environment changes constantly, and for good reasons.

People. An administrator adds an exception to unblock something on a Friday evening. It is never removed. A contractor gets access for a migration; the migration ends, the access stays.

Projects. A new SaaS tool is wired into email. External sharing is opened for a tender. A connector is created for a subsidiary.

The vendor. Microsoft regularly changes defaults, services and settings. Most of those changes improve security — but they do not always apply to existing tenants, and some alter behavior you were relying on.

The organization itself. An acquisition brings a directory, domains, habits. A reorganization redistributes roles.

None of these events is a mistake. All of them move the configuration away from the state described in the report.

Why periodic audits cannot answer this

This is not a criticism of auditing: it is a limit of the format.

It measures a moment. A report dated 15 March describes 15 March. It says nothing about the 16th, and certainly nothing about 20 September.

It cannot see the trajectory. A tenant that just degraded and a tenant stable for two years produce the same snapshot. They are very different situations, and it is the second piece of information an insurer or an auditing customer cares about.

It arrives too late. Seventeen months can pass between a gap appearing and the next audit. That is how long the door stays open with nobody knowing.

It is expensive to repeat. Which is precisely why it is not repeated often — and the reasoning eats its own tail.

What continuous measurement changes

The shift is not technological, it is temporal. The same measurement, repeated, produces three things a snapshot cannot.

Detection. A gap that appears on Monday is flagged on Monday, not seventeen months later. On sensitive changes — a privileged role assigned, a forwarding rule created, a policy disabled — that is the difference between an incident avoided and an incident endured.

Qualification. Not all changes are equal. External sharing opened on a communications folder is not sharing opened on HR. Monitoring that alerts on everything stops being read after three weeks; the real work is triage, not detection.

Evidence. This is the use our clients mention first, and the one we did not anticipate. A dated history of gaps and fixes answers customer questionnaires, insurance files and justification requests directly. It turns a compliance cost into a reusable asset.

What it does not replace

Configuration monitoring replaces neither incident detection, nor a SOC, nor a penetration test. It answers a different question: is the environment configured the way we decided it should be, today?

Nor does it replace the initial audit. You need a starting point: a full assessment, a prioritization, a remediation. Monitoring comes after, and exists precisely so that the work does not have to be redone in eighteen months.

David PekmezTwenty years securing Microsoft environments and corporate email, from the endpoint to tenants with several thousand accounts. LinkedIn
Share on LinkedIn

And where does your configuration stand?

Thirty minutes to look at your actual situation. If this article applies to you, we will tell you frankly how much.