Confirm the expected customer baseline
Start with the global policy and supported organization-specific values. Confirm that an intentional customer difference is reflected in the expected configuration before treating it as a fault.
Platform capabilities
Manage Microsoft cloud services, Windows devices, security, documentation, backup, and support from one self-hosted platform.
Microsoft 365 configuration drift
An agreed setting can change after onboarding. Compare supported Microsoft 365 and Entra controls with the customer baseline, review the mismatch, and follow the correction or ticket workflow through to verification.
For administrators and MSP technicians. Scheduled checks and available actions depend on configuration, installed version, connected services, permissions and Microsoft licensing.
Microsoft 365 configuration drift is a difference between the configuration you expect and the state you observe. MSPControl compares a defined set of security-compliance baseline controls during its configured scheduled workflow. It records match state and can attempt limited automatic correction or route ConnectWise follow-up. It does not compare every Microsoft 365 object or provide a complete configuration-change history.
The operating workflow
Start with the global policy and supported organization-specific values. Confirm that an intentional customer difference is reflected in the expected configuration before treating it as a fault.
Enable baseline synchronization in the security-compliance scheduled workflow for the intended scope. Check when it ran, which services were available and whether collection reported errors.
Inspect the supported control and the saved comparison result. A mismatch can reflect an unintended change, an outdated expectation or missing prerequisites. It does not identify who made a change.
When enabled, automatic correction is limited to four controls listed below. Other mismatches require review and an approved action through the setting’s owning administrative surface.
With ConnectWise synchronization enabled and routing configured, a nonmatching setting can create a ticket if no open ticket for that setting exists. Matching state enters the configured closure workflow.
Check task errors, the effective Microsoft setting, the next comparison and the ticket result. Record the decision and change context in your operating process; saved match state is not a complete audit trail.
What MSPControl supports
The current baseline workflow has four gated correction paths. Enabling auto-remediation is not a promise that the write will succeed or that all compared settings will be changed.
Can attempt to bring the supported user application-registration setting into alignment with the expected value.
Can attempt to correct the supported non-admin portal-access setting. This is not a universal restriction on every management API or identity action.
Can attempt to correct the enabled state. It does not raise the audit-retention period; retention remains a separate comparison and review.
Can attempt to correct the supported consent value and read the policy back. Other consent and application-permission scenarios need their own review.
Interpretation and coverage
| Compared control | Automatic correction in this workflow | Review boundary |
|---|---|---|
| Safe Links; spam filtering; Standard Protection | No | Compare supported state when Exchange Online is available; inspect detailed policy scope separately. |
| MFA through Conditional Access; legacy authentication | No | A supported control comparison is not a diff of every Conditional Access policy. |
| Diagnostic settings; device-join MFA; Intune MDM user scope | No | Review supported state and service prerequisites; no universal Intune configuration diff. |
| Entra license | No | A license mismatch requires a licensing decision, not an automatic purchase. |
| User application registration; non-admin Entra portal access | Can attempt, when enabled | Inspect write results and effective settings. |
| Unified Audit Log state and minimum retention | Enabled state only | Retention is compared but not automatically increased. |
| User consent settings | Can attempt, when enabled | Readback and task results must confirm the outcome. |
Configuration and next actions
Common questions
No. It compares a defined set of supported baseline controls with expected values. It does not provide a universal object-level configuration diff, identify every change actor or retain a complete version history of the tenant.
Baseline comparison runs through the configured security-compliance scheduled workflow when baseline synchronization is enabled. The selected schedule, customer scope and successful data collection determine the actual checks. This page does not promise real-time monitoring or a fixed interval.
For four supported controls, the workflow can attempt correction when auto-remediation is enabled: user application registration, non-admin Entra portal access, Unified Audit Log ingestion and user consent. Other compared controls remain review items. A write attempt can fail and must be verified.
Yes, when baseline ticket synchronization and the required integration settings are configured. The workflow can create a ticket for a nonmatching setting without an existing open ticket, and process matching settings for closure. Check routing, closure status, task errors and the resulting ConnectWise ticket.
The baseline supports global settings and defined organization-level overrides. These values let you represent supported customer differences. They do not constitute a general approval workflow with exception owners, expiry and a complete audit history.
Baseline management defines the expected configuration and supported control scope. Drift review is the recurring operational work of comparing available state, investigating mismatches, choosing a correction and verifying follow-up. The two pages link to each other because both are needed.
Self-hosted. Free license available. No credit card required.