Security drift: the slow leak in your security posture

Security drift is configuration drift that weakens your defenses: the MFA requirement that got an exclusion, the sharing control loosened for one meeting, the admin role that stayed permanent. No alert fires, because every change was made on purpose by someone with the rights to make it. The posture you audited is simply no longer the posture you have.

See where your tenant has drifted, free

Security drift vs configuration drift

All security drift is configuration drift, but not all configuration drift is a security problem. A renamed group is drift; nobody cares. An admin excluded from Conditional Access is security drift: the change directly weakens a control. The distinction matters because the volume of harmless change in a busy tenant is enormous, and the discipline is separating the changes that weaken security from the noise. That triage is the heart of configuration drift management.

The most common security drift we see across tenants:

  • A Conditional Access exclusion added under pressure and never restored, so MFA quietly stops covering the excluded group.
  • A privileged role granted permanently during an outage because PIM activation felt slow.
  • SharePoint external sharing flipped to "Anyone" for one file, tenant-wide, forever.
  • A service principal secret that has not rotated in years while the app registration accumulated permissions.
  • A baseline control switched off during a migration, with the ticket to re-enable it closed as done.

Why security drift beats point-in-time reviews

A security review is a photograph. Drift is a film that keeps running after the camera stops. A tenant that passed its assessment in January is not that tenant by March: admins changed things, projects created exceptions, Microsoft moved defaults. This is why security drift is called the silent killer: each individual change was reasonable, no alarm ever fired, and the accumulated gap only becomes visible when someone goes looking, or when someone breaks in.

The counter is baseline drift monitoring: define the secure baseline once, mapped to a standard such as CISA SCuBA or the Microsoft cloud security benchmark, then compare the live tenant against it continuously. The sensing half of that loop is drift detection; the full practice, including ranking and remediation, is drift management. across every tenant, Senserva Drift Manager runs it continuously across every tenant you manage.

The five ways a hardened tenant drifts

Nobody sets out to weaken a tenant. Drift is what accumulates when ordinary work meets a configuration nobody owns end to end, and each of these five leaves a different fingerprint.

The temporary exception that stayed
Someone is blocked at 4pm on a Friday, so a policy gets an exclusion, a setting gets relaxed, or a group gets a member. The urgency is real and the change is correct for that hour. What is missing is the thing that puts it back, so the exception becomes the configuration.
The test that was never finished
Conditional Access report-only mode, a pilot group, a staged rollout. All good practice, all half-finished states that look deliberate in the console. A tenant can hold a dozen carefully designed policies and be protected by none of them.
Microsoft changed the default
The Microsoft 365 estate moves under you. New features arrive enabled, defaults shift, preview settings graduate, and product names change. Your configuration did not drift; the ground did. This is the category that punishes annual reviews hardest, because nothing in your change log explains it.
Growth without a baseline
New users, new guests, new apps, new devices, each added by someone doing their job. No single addition is a finding. The aggregate is a tenant whose real attack surface has not matched its documented one for a year.
Staff turnover, on both sides
The person who hardened the tenant left. The person who inherited it did not get the reasoning, only the settings, so every setting looks equally load-bearing and nothing is safe to touch. Drift here is not change at all: it is paralysis while the estate keeps moving.

The reason drift needs a model rather than a report is that four of these five look completely normal in isolation. You only see them by comparing a dated baseline against what is true today, and by reading the logs beside the configuration so you know which changes actually got used. That is what continuous drift management means, and it is why one connected model is the thing that makes it possible.

Ask Claude what changed, and whether it mattered

Drift is a question about time, which is why it is so hard to answer from a console that only shows now. Senserva keeps the dated trail, and its MCP lets Claude, or the AI you already use, walk it with you.

You can do exactly this today without registering: the MCP demo mode runs on the same sample data, no tenant and no key required.

You
What changed in my tenant in the last 30 days that made us less secure?
AI
Six changes moved risk the wrong way. Ranked: the SharePoint external sharing setting went from Existing guests to Anyone on July 3; a Conditional Access policy requiring compliant devices was switched to report-only on July 11; two accounts were added to Global Administrator on July 14; a mailbox audit setting was disabled on July 19; and an app registration received a new two-year secret on July 22. The other 41 changes in the window were neutral or improvements.
You
The report-only one. Who did that and what is exposed now?
AI
Changed July 11 by an admin who was testing a related policy the same afternoon, then never switched back, which is the ordinary way this happens. While it sits in report-only, 214 users can reach Exchange and SharePoint from devices that are not compliant, and the sign-in logs show 38 of them doing so, including 6 from outside your usual countries. The policy itself is correct, so the fix is one setting, not a redesign.
You
Set it back and tell me what breaks.
AI
Ready to review: the policy returns to enforced. Nine devices currently fail the compliance check and would lose access, all nine belonging to three users, and each is failing on the same missing disk-encryption requirement. Fix those three first and enforcement costs nobody anything. Baseline restored, and the next scan proves it held.

Demonstration conversation against the built-in sample tenant, not live customer data.

Everything Claude and the Senserva MCP can do The SDK, for your own workflows

Frequently asked questions

What is security drift?

Security drift is the gradual weakening of your security posture through configuration changes: exclusions, loosened controls, standing privileges, and disabled policies that accumulate after your last review. Each change is deliberate and authorized, which is why no alert fires and why it goes unnoticed until enumerated.

How is security drift different from a misconfiguration?

A misconfiguration is a wrong setting at a point in time. Security drift is the process that produces misconfigurations continuously: a correct configuration decaying into a wrong one through everyday changes. Fixing today's Microsoft 365 misconfigurations without monitoring drift means the same list grows back.

How do I monitor for security drift in Microsoft 365?

Set a baseline mapped to a recognized standard, compare the live tenant against it continuously rather than quarterly, rank the diverging changes by security impact, and route each one to a fix. Senserva runs this loop with nearly 700 checks across Microsoft 365, Entra ID, Intune, and Defender.

Does tenant configuration drift affect compliance?

Directly: drift is how a tenant that passed an audit falls out of compliance before the next one. Continuous monitoring keeps you on baseline between assessments and produces the evidence that you stayed there.

Senserva
Three Free Unlimited Audits
1 scan to find, 2 to review your fixes.
Setup and running in minutes. Your data stays local, in a results database only you hold. Someone from Senserva will work with you.
Everything Siemserva by Senserva does: every missing patch ranked by real attacks, all 650+ security checks, and full reports.
All users · All settings · All patches · All tenants · Rich Claude MCP support
Includes our extensive Claude MCP: everything you need to run full audits.
SoftwareOne's team of experts will work with you to assure success.

Free registration is all it takes, no card. Want it always on? Summer Special: unlimited use, up to 50 tenants, $600/mo or $6,500/yr.