Drift detection: catch the change the day it happens

Every Microsoft 365 tenant drifts. Admins make daily changes, exceptions outlive their reason, and Microsoft moves defaults under you. Drift detection is the discipline of comparing the live tenant against your secure baseline continuously, so a loosened sharing setting or a quiet new role assignment is a same-day alert, not a next-audit surprise.

Siemserva by Senserva detects drift across Microsoft 365, Intune, Defender, and Entra ID, ranks what actually weakens security, and pairs every finding with a remediation path. Detection is the front end of continuous drift management; this page is about doing the detection half right.

Always-on detection across every tenant: Senserva Drift Manager Detect same-day, against a real baseline How every finding is scored in one risk model Rank what actually weakens security Closing the loop: continuous drift management Remediate a reviewed fix on every finding the next scan proves it stayed fixed

Open the watch page for this webinar, or see all Senserva videos.

What good drift detection looks like

  • A real baseline. Detection is only as good as the definition of intended state: map it to CIS-aligned baselines, Microsoft cloud security benchmark, or CISA SCuBA, not to "whatever it was last month".
  • Continuous comparison, not quarterly scans. Drift compounds: a detection cycle measured in hours keeps one bad change from becoming the new normal.
  • Risk ranking. Most changes are noise. Detection that pages you for everything gets ignored; rank by what weakens a control (MFA, Conditional Access, privileged roles, sharing).
  • A remediation path on every finding. Detection without a fix path just documents decay. Every Senserva drift finding carries a reviewed remediation or routes into your ticketing.

Where drift hides in Microsoft 365

The changes that matter are rarely dramatic. A Conditional Access exclusion added for one user and never removed. An Intune compliance policy edited during an incident. A SharePoint sharing default loosened to close a ticket. An Entra role assignment granted for a project that ended. Each is invisible in isolation; drift detection makes the pattern visible.

For estate operators the problem multiplies: an MSP managing dozens of tenants needs detection that watches every tenant against a standardized baseline. That is what Senserva Drift Manager runs continuously, and what Siemserva gives a single tenant on demand with find-and-fix depth.

Detection is only half of it. Here is the whole loop.

Most drift tools stop at the alert: something changed, go look. That leaves you with a second backlog on top of the one you already have. Senserva reads your configuration, your patches and CVEs, and your logs as one connected model, so a change is not just detected, it is ranked against everything else that is true about your tenant, fixed, and then proven closed on the next scan.

From three inputs to one model to ranked, remediated, and verified Configuration, patching and CVEs, logs, and third party data feed one connected model, with Senserva AI analysis and the Senserva MCP. The model produces AI-enhanced assessment ranked by real risk, AI-enhanced reports and validated remediation you approve and apply, compliance and audit evidence, and output to your SIEM and other workflows. The next scan proves the gap is closed, feeding the next cycle. Configuration Patching & CVEs Logs Third Party Data One connected model Senserva Analysis Senserva AI + Senserva MCP AI-enhanced assessment ranked by real risk AI reports & remediation validated, you apply Compliance & Audit SIEM & other workflows the next scan proves the gap is closed

That last dotted line is the part that matters for drift. A finding that closes and stays closed is worth more than a hundred alerts, and the only way to know it stayed closed is to look again tomorrow.

Why drift detection needs more than a config diff

A configuration diff tells you a setting moved. It cannot tell you whether the move mattered, and that is the whole question. A relaxed sharing setting on a site nobody uses is noise. The same change on a site holding finance data, made by an account with no Conditional Access coverage, that the logs show being accessed from a new country, is the incident you will read about later.

Real risk lives in the overlap, so that is where we look:

Configuration, patching, and logs overlap Three overlapping circles, configuration, patching and CVEs, and logs. Real risk and grounded AI live where all three overlap. Configuration Patching & CVEs Logs Real risk + grounded AI

Configuration, patching, and logs in one model. Three separate tools cannot see the middle.

Every drift finding arrives with its fix

This is the difference between drift detection and drift management, and it is where the time goes. Detection without remediation just moves work from "notice it" to "figure out what to do", which is the expensive half.

80%
less hardening effort, reported by a customer running Senserva against their tenants. One scan and one workflow instead of three tools and manual hand-offs.
Validated first
Each fix is checked against your real findings before it is offered, and a person approves before anything runs. Senserva Trustworthy AI.
Proven closed
The next scan confirms the setting held, which is what turns a fix into evidence an auditor accepts.

A drift finding comes with a plain-language explanation, the users or objects affected, the control it satisfies, the rollback, and a ready-to-run fix. You review it and you apply it. How the remediation works.

Ask Claude what drifted, and whether it mattered

Drift is a question about time, which is why a console showing only the present cannot answer it. Senserva keeps the dated trail and ships a market-leading MCP, so Claude, or the AI you already use, can walk that trail with you and draft the fix at the end of it.

You can do exactly this today without registering: the MCP demo mode runs on the same sample data, no tenant and no key required.

You
Did anything drift away from our baseline this week?
AI
Four changes moved risk the wrong way out of 63 total. Ranked: a Conditional Access policy requiring compliant devices went to report-only on Tuesday; external sharing on two SharePoint sites went from Existing guests to Anyone; one account was added to Global Administrator; and mailbox auditing was turned off on a shared mailbox. The other 59 changes were neutral or improvements, including nine device-compliance fixes.
You
Which of those is actually being used against us right now?
AI
The report-only policy. The sign-in logs show 38 of the 214 affected users reaching Exchange and SharePoint from non-compliant devices since Tuesday, six from countries you have never signed in from. The sharing change is exposure without evidence of use yet: no anonymous link on either site has been opened. The admin addition was your own change ticket, and mailbox auditing matters for the investigation you would run later, not for today.
You
Fix the first two and show me the blast radius before I approve.
AI
Ready to review. Policy back to enforced: nine devices currently fail compliance and would lose access, all nine belonging to three users, all failing the same disk-encryption requirement, so fix those three and enforcement costs nobody anything. Sharing back to Existing guests: four active guest links keep working, two anonymous links stop, both created this week and never opened. Each carries its rollback and its control mapping (SCuBA MS.AAD.3.1v1 and MS.SHAREPOINT.1.1v1). Nothing runs until you approve, and the next scan proves both held.

Demonstration conversation against the built-in sample tenant, not live customer data.

Everything Claude and the Senserva MCP can do The SDK, for your own workflows

Frequently asked

What is drift detection?

Drift detection is the continuous comparison of your live configuration against the secure baseline you intended, so any divergence (a loosened sharing policy, a new Conditional Access exclusion, a role assignment that appeared) is flagged the day it happens instead of at the next audit.

How is drift detection different from drift management?

Detection is the sensing half: find the divergence fast. Drift management is the whole loop: baseline, detect, rank what matters, and remediate. Senserva provides detection as the always-on front end of that loop.

Can drift detection work with Infrastructure as Code?

Yes, and it is the complement IaC needs. IaC declares intended state but cannot see portal edits, support-ticket changes, or Microsoft default shifts made outside the pipeline. Drift detection catches exactly that gap.

What should drift detection cover in Microsoft 365?

Identity (Entra ID roles, Conditional Access, MFA settings), device configuration (Intune profiles, compliance policies, update rings), Defender settings, and sharing controls in SharePoint and Teams. Every one of those drifts independently.

Senserva
Three Free Unlimited Audits
1 scan to find, 2 to review your fixes.
Setup and running in minutes. Your data stays local, in a results database only you hold. Someone from Senserva will work with you.
Everything Siemserva by Senserva does: every missing patch ranked by real attacks, all 650+ security checks, and full reports.
All users · All settings · All patches · All tenants · Rich Claude MCP support
Includes our extensive Claude MCP: everything you need to run full audits.
SoftwareOne's team of experts will work with you to assure success.

Free registration is all it takes, no card. Want it always on? Summer Special: unlimited use, up to 50 tenants, $600/mo or $6,500/yr.