Drift detection: catch the change the day it happens
Every Microsoft 365 tenant drifts. Admins make daily changes, exceptions outlive their reason, and Microsoft moves defaults under you. Drift detection is the discipline of comparing the live tenant against your secure baseline continuously, so a loosened sharing setting or a quiet new role assignment is a same-day alert, not a next-audit surprise.
Siemserva by Senserva detects drift across Microsoft 365, Intune, Defender, and Entra ID, ranks what actually weakens security, and pairs every finding with a remediation path. Detection is the front end of continuous drift management; this page is about doing the detection half right.
Open the watch page for this webinar, or see all Senserva videos.
What good drift detection looks like
- A real baseline. Detection is only as good as the definition of intended state: map it to CIS-aligned baselines, Microsoft cloud security benchmark, or CISA SCuBA, not to "whatever it was last month".
- Continuous comparison, not quarterly scans. Drift compounds: a detection cycle measured in hours keeps one bad change from becoming the new normal.
- Risk ranking. Most changes are noise. Detection that pages you for everything gets ignored; rank by what weakens a control (MFA, Conditional Access, privileged roles, sharing).
- A remediation path on every finding. Detection without a fix path just documents decay. Every Senserva drift finding carries a reviewed remediation or routes into your ticketing.
Where drift hides in Microsoft 365
The changes that matter are rarely dramatic. A Conditional Access exclusion added for one user and never removed. An Intune compliance policy edited during an incident. A SharePoint sharing default loosened to close a ticket. An Entra role assignment granted for a project that ended. Each is invisible in isolation; drift detection makes the pattern visible.
For estate operators the problem multiplies: an MSP managing dozens of tenants needs detection that watches every tenant against a standardized baseline. That is what Senserva Drift Manager runs continuously, and what Siemserva gives a single tenant on demand with find-and-fix depth.
Detection is only half of it. Here is the whole loop.
Most drift tools stop at the alert: something changed, go look. That leaves you with a second backlog on top of the one you already have. Senserva reads your configuration, your patches and CVEs, and your logs as one connected model, so a change is not just detected, it is ranked against everything else that is true about your tenant, fixed, and then proven closed on the next scan.
That last dotted line is the part that matters for drift. A finding that closes and stays closed is worth more than a hundred alerts, and the only way to know it stayed closed is to look again tomorrow.
Why drift detection needs more than a config diff
A configuration diff tells you a setting moved. It cannot tell you whether the move mattered, and that is the whole question. A relaxed sharing setting on a site nobody uses is noise. The same change on a site holding finance data, made by an account with no Conditional Access coverage, that the logs show being accessed from a new country, is the incident you will read about later.
Real risk lives in the overlap, so that is where we look:
Configuration, patching, and logs in one model. Three separate tools cannot see the middle.
Every drift finding arrives with its fix
This is the difference between drift detection and drift management, and it is where the time goes. Detection without remediation just moves work from "notice it" to "figure out what to do", which is the expensive half.
A drift finding comes with a plain-language explanation, the users or objects affected, the control it satisfies, the rollback, and a ready-to-run fix. You review it and you apply it. How the remediation works.
Ask Claude what drifted, and whether it mattered
Drift is a question about time, which is why a console showing only the present cannot answer it. Senserva keeps the dated trail and ships a market-leading MCP, so Claude, or the AI you already use, can walk that trail with you and draft the fix at the end of it.
You can do exactly this today without registering: the MCP demo mode runs on the same sample data, no tenant and no key required.
Demonstration conversation against the built-in sample tenant, not live customer data.
Frequently asked
Drift detection is the continuous comparison of your live configuration against the secure baseline you intended, so any divergence (a loosened sharing policy, a new Conditional Access exclusion, a role assignment that appeared) is flagged the day it happens instead of at the next audit.
Detection is the sensing half: find the divergence fast. Drift management is the whole loop: baseline, detect, rank what matters, and remediate. Senserva provides detection as the always-on front end of that loop.
Yes, and it is the complement IaC needs. IaC declares intended state but cannot see portal edits, support-ticket changes, or Microsoft default shifts made outside the pipeline. Drift detection catches exactly that gap.
Identity (Entra ID roles, Conditional Access, MFA settings), device configuration (Intune profiles, compliance policies, update rings), Defender settings, and sharing controls in SharePoint and Teams. Every one of those drifts independently.