Security drift: the slow leak in your security posture
Security drift is configuration drift that weakens your defenses: the MFA requirement that got an exclusion, the sharing control loosened for one meeting, the admin role that stayed permanent. No alert fires, because every change was made on purpose by someone with the rights to make it. The posture you audited is simply no longer the posture you have.
Security drift vs configuration drift
All security drift is configuration drift, but not all configuration drift is a security problem. A renamed group is drift; nobody cares. An admin excluded from Conditional Access is security drift: the change directly weakens a control. The distinction matters because the volume of harmless change in a busy tenant is enormous, and the discipline is separating the changes that weaken security from the noise. That triage is the heart of configuration drift management.
The most common security drift we see across tenants:
- A Conditional Access exclusion added under pressure and never restored, so MFA quietly stops covering the excluded group.
- A privileged role granted permanently during an outage because PIM activation felt slow.
- SharePoint external sharing flipped to "Anyone" for one file, tenant-wide, forever.
- A service principal secret that has not rotated in years while the app registration accumulated permissions.
- A baseline control switched off during a migration, with the ticket to re-enable it closed as done.
Why security drift beats point-in-time reviews
A security review is a photograph. Drift is a film that keeps running after the camera stops. A tenant that passed its assessment in January is not that tenant by March: admins changed things, projects created exceptions, Microsoft moved defaults. This is why security drift is called the silent killer: each individual change was reasonable, no alarm ever fired, and the accumulated gap only becomes visible when someone goes looking, or when someone breaks in.
The counter is baseline drift monitoring: define the secure baseline once, mapped to a standard such as CISA SCuBA or the Microsoft cloud security benchmark, then compare the live tenant against it continuously. The sensing half of that loop is drift detection; the full practice, including ranking and remediation, is drift management. across every tenant, Senserva Drift Manager runs it continuously across every tenant you manage.
The five ways a hardened tenant drifts
Nobody sets out to weaken a tenant. Drift is what accumulates when ordinary work meets a configuration nobody owns end to end, and each of these five leaves a different fingerprint.
The reason drift needs a model rather than a report is that four of these five look completely normal in isolation. You only see them by comparing a dated baseline against what is true today, and by reading the logs beside the configuration so you know which changes actually got used. That is what continuous drift management means, and it is why one connected model is the thing that makes it possible.
Ask Claude what changed, and whether it mattered
Drift is a question about time, which is why it is so hard to answer from a console that only shows now. Senserva keeps the dated trail, and its MCP lets Claude, or the AI you already use, walk it with you.
You can do exactly this today without registering: the MCP demo mode runs on the same sample data, no tenant and no key required.
Demonstration conversation against the built-in sample tenant, not live customer data.
Frequently asked questions
Security drift is the gradual weakening of your security posture through configuration changes: exclusions, loosened controls, standing privileges, and disabled policies that accumulate after your last review. Each change is deliberate and authorized, which is why no alert fires and why it goes unnoticed until enumerated.
A misconfiguration is a wrong setting at a point in time. Security drift is the process that produces misconfigurations continuously: a correct configuration decaying into a wrong one through everyday changes. Fixing today's Microsoft 365 misconfigurations without monitoring drift means the same list grows back.
Set a baseline mapped to a recognized standard, compare the live tenant against it continuously rather than quarterly, rank the diverging changes by security impact, and route each one to a fix. Senserva runs this loop with nearly 700 checks across Microsoft 365, Entra ID, Intune, and Defender.
Directly: drift is how a tenant that passed an audit falls out of compliance before the next one. Continuous monitoring keeps you on baseline between assessments and produces the evidence that you stayed there.
Free registration is all it takes, no card. Want it always on? Summer Special: unlimited use, up to 50 tenants, $600/mo or $6,500/yr.