Microsoft 365 configuration drift

Catch Baseline Mismatches and Know What Happens Next

An agreed setting can change after onboarding. Compare supported Microsoft 365 and Entra controls with the customer baseline, review the mismatch, and follow the correction or ticket workflow through to verification.

For administrators and MSP technicians. Scheduled checks and available actions depend on configuration, installed version, connected services, permissions and Microsoft licensing.

CompareRead the supported setting against its expected value.

ReviewCheck scope, data freshness and customer intent.

RespondUse a supported correction or route a configured ticket.

VerifyConfirm the effective setting and the next comparison result.

What Is Microsoft 365 Configuration Drift?

Microsoft 365 configuration drift is a difference between the configuration you expect and the state you observe. MSPControl compares a defined set of security-compliance baseline controls during its configured scheduled workflow. It records match state and can attempt limited automatic correction or route ConnectWise follow-up. It does not compare every Microsoft 365 object or provide a complete configuration-change history.

The operating workflow

Handle the Mismatch, Not Just the Alert

Confirm the expected customer baseline

Start with the global policy and supported organization-specific values. Confirm that an intentional customer difference is reflected in the expected configuration before treating it as a fault.

Run the configured comparison

Enable baseline synchronization in the security-compliance scheduled workflow for the intended scope. Check when it ran, which services were available and whether collection reported errors.

Review current and expected state

Inspect the supported control and the saved comparison result. A mismatch can reflect an unintended change, an outdated expectation or missing prerequisites. It does not identify who made a change.

Choose the appropriate correction path

When enabled, automatic correction is limited to four controls listed below. Other mismatches require review and an approved action through the setting’s owning administrative surface.

Route the customer follow-up

With ConnectWise synchronization enabled and routing configured, a nonmatching setting can create a ticket if no open ticket for that setting exists. Matching state enters the configured closure workflow.

Verify the result and retain context

Check task errors, the effective Microsoft setting, the next comparison and the ticket result. Record the decision and change context in your operating process; saved match state is not a complete audit trail.

What MSPControl supports

Know the Automatic-Correction Boundary

The current baseline workflow has four gated correction paths. Enabling auto-remediation is not a promise that the write will succeed or that all compared settings will be changed.

User application registration

Can attempt to bring the supported user application-registration setting into alignment with the expected value.

Non-admin Entra portal access

Can attempt to correct the supported non-admin portal-access setting. This is not a universal restriction on every management API or identity action.

Unified Audit Log ingestion

Can attempt to correct the enabled state. It does not raise the audit-retention period; retention remains a separate comparison and review.

User consent settings

Can attempt to correct the supported consent value and read the policy back. Other consent and application-permission scenarios need their own review.

Current boundary: Coverage is limited to the listed controls and available data. No real-time or fixed-interval detection guarantee, universal tenant remediation, complete configuration history, approved-exception lifecycle or compliance guarantee is claimed. Organization-specific values are not an exception approval system.

Interpretation and coverage

What the Baseline Comparison Covers

Compared control Automatic correction in this workflow Review boundary
Safe Links; spam filtering; Standard Protection No Compare supported state when Exchange Online is available; inspect detailed policy scope separately.
MFA through Conditional Access; legacy authentication No A supported control comparison is not a diff of every Conditional Access policy.
Diagnostic settings; device-join MFA; Intune MDM user scope No Review supported state and service prerequisites; no universal Intune configuration diff.
Entra license No A license mismatch requires a licensing decision, not an automatic purchase.
User application registration; non-admin Entra portal access Can attempt, when enabled Inspect write results and effective settings.
Unified Audit Log state and minimum retention Enabled state only Retention is compared but not automatically increased.
User consent settings Can attempt, when enabled Readback and task results must confirm the outcome.

Configuration and next actions

Open the Guide That Owns the Next Step

Common questions

Microsoft 365 configuration drift FAQ

Does MSPControl detect every Microsoft 365 configuration change?

No. It compares a defined set of supported baseline controls with expected values. It does not provide a universal object-level configuration diff, identify every change actor or retain a complete version history of the tenant.

How often does drift detection run?

Baseline comparison runs through the configured security-compliance scheduled workflow when baseline synchronization is enabled. The selected schedule, customer scope and successful data collection determine the actual checks. This page does not promise real-time monitoring or a fixed interval.

Can MSPControl automatically fix drift?

For four supported controls, the workflow can attempt correction when auto-remediation is enabled: user application registration, non-admin Entra portal access, Unified Audit Log ingestion and user consent. Other compared controls remain review items. A write attempt can fail and must be verified.

Can a mismatch create a ConnectWise ticket?

Yes, when baseline ticket synchronization and the required integration settings are configured. The workflow can create a ticket for a nonmatching setting without an existing open ticket, and process matching settings for closure. Check routing, closure status, task errors and the resulting ConnectWise ticket.

Can customers have different expected settings?

The baseline supports global settings and defined organization-level overrides. These values let you represent supported customer differences. They do not constitute a general approval workflow with exception owners, expiry and a complete audit history.

How is this different from security baseline management?

Baseline management defines the expected configuration and supported control scope. Drift review is the recurring operational work of comparing available state, investigating mismatches, choosing a correction and verifying follow-up. The two pages link to each other because both are needed.