Configuration Drift Package

The 15 Settings That Actually Get You Breached — From Post-Incident Forensics

59%
of breached orgs had MFA gaps (Sophos)
99%
of password spray uses legacy auth
3.4h
initial access to AD compromise
79%
of BEC victims HAD MFA (wrong kind)
Methodology: Configuration drift detection is a continuous posture loop — the third OODA loop running at a different tempo than incident detection. See Detection Engineering for how detection tiers map to different cycle times.
Shift Down, Not Shift Left. Don't hand people a security policy and wish them luck. Wire security into the platform so teams get it for free. The consulting diagnostic: "What security controls require someone to remember to do something?" Each answer is a drift candidate.
This playbook is built from post-breach forensics, not theory. Every setting below was found misconfigured in real incident investigations by Sophos (661 cases, 70 countries), Mandiant (M-Trends), CISA/NSA (AA23-278A), Verizon DBIR, and CrowdStrike. These are the specific configurations that were wrong when the breach happened.

The 15 Settings That Actually Get You Breached

Prioritized by breach frequency and impact. P0 = found in the majority of breaches. P1 = common attack enabler. P2 = amplifies blast radius. Every setting has a specific breach outcome.

P0 — Critical (found in majority of breaches)

#SettingBreach EvidenceCheck Command
1 Legacy auth protocols enabled
(BAV2ROPC, SMTP AUTH, POP3, IMAP4)
99% of password spray, 97% of credential stuffing uses legacy auth. 9,000+ Exchange login attempts in 3 weeks via legacy protocols (Guardz 2025). Orgs that disabled legacy auth saw 67% fewer compromises. Get-MgIdentityConditionalAccessPolicy | Where {$_.Conditions.ClientAppTypes -contains "exchangeActiveSync"}
2 MFA coverage gaps
(users, apps, service principals)
MFA not configured in 59% of breached organizations (Sophos, 661 cases). Three failure modes: believed enabled but wasn't, enabled but misconfigured, known gap never addressed. One user missing = entire control trivial. Get-MgUser -All | Where {$_.StrongAuthenticationMethods.Count -eq 0}
3 AD CS template misconfigs
(ESC1: ENROLLEE_SUPPLIES_SUBJECT + Client Auth EKU)
Mandiant: attackers exploit misconfigured certificate templates to create admin accounts that bypass MFA and survive password rotation. UNC5330 used this to impersonate domain admins after Ivanti exploitation (April 2024). certutil -v -dstemplate | findstr "msPKI-Certificate-Name-Flag" "ENROLLEE_SUPPLIES_SUBJECT"
4 Backup server domain-joined
or using default/shared credentials
CVE-2025-23120: any domain user can RCE on domain-joined Veeam server. 94% of ransomware attacks attempt to compromise backups, 57% succeed (Sophos). Storm-0501: exfiltrate → delete backups → encrypt. Check: Is backup server in AD? Does backup admin = domain admin? Can domain admin delete backups?

P1 — High (common attack enabler)

#SettingBreach EvidenceCheck Command
5 RDP exposed to internet RDP involved in 66% of cases (internal use), still the most-abused tool though down from prior years (Sophos AAR 2026). Logistics firm hit via exposed RDP with no authentication. Get-NetTCPConnection -LocalPort 3389 -State Listen
+ external Shodan/Nmap scan
6 VPN/firewall default creds or no MFA 71% of cases: attackers entered via external remote services (Sophos 2026). 37% of mid-market had at least one firewall with unchanged defaults in pen tests. Brute-force (15.6%) nearly matched exploitation (16%). Manual: check VPN MFA config, verify no default admin passwords remain
7 SMB signing not enforced CISA/NSA Top 10: enables NTLM relay attacks leading to complete domain takeover. Not enforced by default even in latest Windows versions. Get-SmbServerConfiguration | Select RequireSecuritySignature
8 LLMNR/NBT-NS enabled CISA/NSA Top 10: enabled by default, allows hash capture via spoofing/poisoning/relay. Combined with disabled SMB signing = domain compromise chain. Get-NetAdapter | Get-DnsClient | Select InterfaceAlias, EnableMulticast
9 Conditional Access exclusions
(stale, excessive, bypassable)
CA policies targeting "all resources" bypassable via OIDC-only requests (Microsoft fixing March 2026). Device enrollment bypasses "Require compliant device." MFA exceptions accumulate and never expire. Get-MgIdentityConditionalAccessPolicy | ForEach { $_.Conditions.Users.ExcludeUsers }
10 MFA method is push/OTP
instead of FIDO2/passkeys
79% of BEC victims had correctly implemented MFA and were still breached via AiTM token theft (FRSecure 2024-2025, 65 incidents). AiTM surged 46% in 2025. Only FIDO2/passkeys/hardware tokens stop it. Get-MgUserAuthenticationMethod -UserId [admin] | Select AdditionalProperties

P2 — Medium (amplifies blast radius)

#SettingBreach EvidenceCheck Command
11 Cloud storage publicly accessible Over 80% of cloud breaches from basic misconfigs: open storage, broad access policies, poor segmentation (Verizon DBIR 2025). 50% of S3 buckets potentially misconfigured. prowler aws -c s3_bucket_public_access or check AWS S3 Block Public Access setting
12 Service accounts with excessive privileges Service accounts outnumber humans 5:1. Compromised service accounts enabled lateral movement across cloud environments (Mandiant M-Trends). 35% of cloud incidents via valid accounts (CrowdStrike 2026). Audit: list all service accounts with Owner/Contributor/Global Admin roles
13 No 24/7 monitoring coverage 88% of ransomware payloads and 79% of data exfiltration occur outside business hours (Sophos 2026). Without 24/7 coverage, you miss the actual attack. Question: who gets alerted at 2 AM Saturday when encryption starts?
14 Flat network / no segmentation Nearly 40% of breaches involved privilege escalation or lateral movement (DBIR 2025). "Allow all" rules created for troubleshooting never removed. CISA/NSA Top 10 #4. Get-NetFirewallRule -Direction Inbound -Action Allow | Where {$_.RemoteAddress -eq "Any"}
15 Infostealer-exposed creds not monitored 73% of ransomware victims had a prior infostealer or credential leak in the year before the attack — and half of those were ransomwared within 95 days of the leak (DBIR 2026). Nobody checked. Search HIBP domain search + check if exposed passwords are still active

Entry Point: Forensic Configuration Assessment

Not a generic CIS benchmark scan. Check the 15 specific settings that show up in breach investigations. Score each. Fix what's red.
1–2 days Entry point

Assessment Script (P0 checks)

# P0-1: Legacy auth — any CA policy still allowing it?
Get-MgIdentityConditionalAccessPolicy | Select DisplayName, State,
  @{N='ClientApps';E={$_.Conditions.ClientAppTypes -join ','}}

# P0-2: MFA gaps — users without any strong auth method
Get-MgUser -All -Property StrongAuthenticationMethods |
  Where-Object { $_.StrongAuthenticationMethods.Count -eq 0 } |
  Select DisplayName, UserPrincipalName

# P0-3: AD CS — find vulnerable templates (ESC1)
# Run from domain-joined machine:
certutil -v -dstemplate | findstr /i "ENROLLEE_SUPPLIES_SUBJECT"

# P0-4: Backup server domain membership
Get-ADComputer -Filter {Name -like "*backup*" -or Name -like "*veeam*"} |
  Select Name, DistinguishedName

# P1-5: RDP listeners
Get-NetTCPConnection -LocalPort 3389 -State Listen

# P1-7: SMB signing
Get-SmbServerConfiguration | Select RequireSecuritySignature

# P1-9: Conditional Access exclusions
Get-MgIdentityConditionalAccessPolicy | ForEach-Object {
  [PSCustomObject]@{
    Policy = $_.DisplayName
    State = $_.State
    ExcludedUsers = ($_.Conditions.Users.ExcludeUsers -join ',')
    ExcludedGroups = ($_.Conditions.Users.ExcludeGroups -join ',')
  }
} | Where { $_.ExcludedUsers -or $_.ExcludedGroups }

Output

Scorecard against the 15 settings: Exposed Partially configured Hardened. Each finding maps to the specific breach outcome it enables.
1 Containment — Fix What's Actively Exploitable
The assessment may reveal settings that represent active risk right now. These get fixed today, not next sprint.
Quick Wins (Day 0, Free)
  • Block legacy auth protocols — create a CA policy that blocks Exchange ActiveSync, POP3, IMAP4, SMTP AUTH. This single change eliminates 99% of password spray.
    30 minFreeFixes P0-1
  • Revoke all MFA exceptions older than 30 days — if the user hasn't re-requested, they don't need it
    1 hourFreeFixes P0-2
  • Enforce CA policies stuck in "report-only" — report-only = not protecting anything
    30 minFreeFixes P1-9
  • Close RDP to internet — disable on all machines where not needed, require VPN+MFA where needed
    1 hourFreeFixes P1-5
  • Enable SMB signing via GPO: Microsoft network server: Digitally sign communications (always) = Enabled
    30 minFreeFixes P1-7
  • Disable LLMNR via GPO: Turn off multicast name resolution = Enabled. Disable NBT-NS via DHCP or registry.
    30 minFreeFixes P1-8
  • Disable stale admin accounts (90+ days inactive)
    30 minFree
  • Check HIBP for your domain — any exposed corporate credentials still active?
    15 minFreeFixes P2-15
Core Engagement (1–2 days)
  • AD CS template audit: Identify and remediate ESC1-ESC8 misconfigurations. Remove ENROLLEE_SUPPLIES_SUBJECT where not required. Restrict enrollment rights.
  • Backup infrastructure separation: Remove backup server from AD domain. Create separate backup admin credentials. Verify immutability.
  • Full exception inventory: Every CA exclusion, MFA exception, firewall rule exception gets: owner, justification, expiry date.
  • Emergency baseline lock: Export current (corrected) config as the known-good state for drift monitoring.
Target State
All 15 settings hardened. Zero legacy auth. Zero exposed RDP. Zero undocumented exceptions. AD CS templates audited. Backup infrastructure separated from AD.
2 Detection — Know When Settings Drift Back
You fixed the 15 settings. How do you know when someone re-enables legacy auth, creates a new MFA exception, or opens an RDP port?
Quick Wins (Day 0, Free)
  • Enable Entra audit log alerts for: CA policy changes, MFA method changes, role assignments, app consent grants
    30 minFree
  • Schedule weekly PingCastle scan: PingCastle.exe --healthcheck — tracks AD health score trend
    30 min setupFree
  • Schedule monthly ScubaGear scan — M365 config vs CISA baselines
    1 hour setupFree
  • Alert on new firewall rules that allow inbound from Any/0.0.0.0/0
    30 minFree
  • Track Secure Score weekly — score should never decrease without documented exception
    10 min/weekFree
Core Engagement (2–3 days)
  • Deploy Maester — 360+ Pester-based M365 security tests in GitHub Actions. Weekly automated runs. Alerts on failure.
  • Deploy Microsoft365DSC — export desired M365 config as code. LCM monitors continuously. Three modes: detect, alert, or auto-revert drift.
  • Build drift dashboard: M365 Secure Score trend, PingCastle AD score trend, exception count trend, P0 setting status.
  • Increase log retention to 365 days — don't rely on defaults (Windows Event Log defaults = 20MB, overwrites in hours). 1TB disk costs less than a coffee per day. Store logs on-host AND forward to central logging. On-host logs are your forensic backup if central is compromised.
Target State
Configuration-as-code for M365. Every P0/P1 setting change detected within 24 hours. 365-day log retention on all servers + central logging. Dashboard shows posture trajectory.
3 Posture — Lock the Baseline
Turn the 15 settings from "things we check" into "things the platform enforces." Make drift require deliberate action, not neglect.
Quick Wins (Day 0, Free)
  • Enable Standard Preset Security Policy in M365 Defender — one toggle, 15 minutes, activates dozens of settings
    15 minFree
  • Enable Microsoft-managed CA policies — auto-created in report-only, switch to enforcing
    30 minFree
  • Set MFA exception expiry policy: max 30 days, requires owner + justification. No permanent exceptions.
    Policy decisionFree
  • Deploy Microsoft LAPS — unique local admin password per machine, eliminates shared local admin
    4–8 hoursFree
  • Run Lynis on Linux servers: lynis audit system --cronjob
    1 hourFree
Core Engagement (2–3 days)
  • M365 config-as-code: Export desired state via Microsoft365DSC, commit to Git. Any drift = alert or auto-revert. PR-based change process for intentional modifications.
  • AD hardening baseline: Tiered admin model, GPO security settings, LLMNR/NBT-NS disabled org-wide, SMB signing enforced, AD CS templates remediated, Kerberos delegation restrictions.
  • Firewall rule cleanup: Remove rules older than 12 months with no traffic. Document remaining rules. Block new allow-rules without change ticket.
  • FIDO2/passkeys for admins: Upgrade from push/OTP to phishing-resistant MFA for all privileged accounts. This fixes P1-10 (79% of BEC victims had MFA but wrong kind).
  • CIS Benchmark alignment: Run OpenSCAP or CIS-CAT against servers. Remediate to Level 1 minimum.
Target State
Desired state is code. Drift is a build failure. All 15 settings have locked baselines with automated monitoring. Exceptions require approval workflow with mandatory expiry. The platform IS the control.
4 Vulnerability Management — Prevent Re-Drift
Drift is entropy. The cadence below keeps the 15 settings hardened permanently.
CadenceActionDetects Drift InTool
ContinuousM365 config drift monitoringP0-1, P0-2, P1-9, P1-10Microsoft365DSC
WeeklyM365 security test suiteAll M365-related settingsMaester (GitHub Actions)
WeeklyAD security health checkP0-3, P1-7, P1-8, service accountsPingCastle
WeeklySecure Score trend trackingAny M365 posture regressionGraph API + script
DailyCloud posture scanP2-11, P2-12Prowler
MonthlyFull CISA baseline checkAll M365 settingsScubaGear
MonthlyException list reviewP0-2, P1-9 (MFA + CA exceptions)PowerShell + manual
MonthlyCredential exposure checkP2-15HIBP domain search
QuarterlyFull CIS benchmarkServer/endpoint driftOpenSCAP / CIS-CAT
QuarterlyAD CS template auditP0-3certutil + manual review
QuarterlyFirewall rule cleanupP2-14Export + diff vs baseline
QuarterlyPrivilege access reviewP2-12 (service accounts)BloodHound + AD audit
Target State
Every P0 setting monitored continuously or weekly. P1 settings checked weekly or monthly. P2 quarterly. Drift never accumulates beyond one review cycle. Exception lists shrink over time.
5 Structural — Make Drift Architecturally Difficult
Remove humans from the loop. If the platform enforces the baseline, drift requires deliberate action.
Core Engagement (3–5 days)
  • Config-as-code pipeline: M365 desired state in Git (Microsoft365DSC). PR-based changes. Auto-revert unauthorized modifications. Full audit trail. Graduate each setting detect → alert → auto-revert only after it has run clean in alert mode; a setting that keeps flipping back and forth means another tool or admin process is fighting the pipeline — find it before auto-revert turns the fight into an outage.
  • Exception workflow automation: Exceptions submitted via form/ticket → auto-approved max 30 days → auto-expired → auto-reported to management. No permanent exceptions possible.
  • Separate management AD: All privileged accounts (backup admin, hypervisor admin, network admin) in a separate AD forest. Production trusts management (one-way). Attackers who compromise production AD cannot see or target the real admins — they don't exist in that directory.
  • Log retention architecture: 365 days on every server (increase Windows Event Log to 1GB+ per channel). Forward to central logging on isolated infrastructure. On-host logs survive central compromise. Disks are cheap; missing forensic evidence is not.
  • Board reporting: Quarterly posture report showing the 15 settings status, drift incidents, exception trends, Secure Score trajectory. One page.
  • NIS2 mapping: Continuous posture monitoring satisfies "appropriate and proportionate measures." Drift monitoring IS the compliance evidence. The cadence table above maps directly to Article 21 requirements.
  • Insurance evidence: Insurers want proof controls are "implemented AND enforced" — not just configured. MFA exception logs, CA enforcement evidence, automated drift reports with timestamps. This is what gets claims approved.
Target State
Security controls don't require someone to remember to do something. The platform IS the control. Admin accounts invisible to attackers via management AD. Logs retained 365 days. Compliance is continuous. The organization can prove its posture at any moment.

Program Economics (200-seat reference)

EngagementDurationInvestment
Forensic Configuration Assessment1–2 days€1,250 – 2,500
1 Containment (fix P0s)1–2 days€1,250 – 2,500
2 Detection (monitoring setup)2–3 days€2,500 – 3,750
3 Posture (baseline lock)2–3 days€2,500 – 3,750
4 Vuln Mgmt (cadence setup)1 day + cadence€1,250 + €5,000/yr
5 Structural (architecture)3–5 days€3,750 – 6,250
Full program10–16 days€12,500 – 20,000 + retainer
ROI: 61% of security leaders say they suffered a breach because of failed or misconfigured controls (Panaseer, 2025). The assessment alone finds the settings that were wrong in 59% of real breaches. All monitoring tools are free. The investment is the expertise to fix the right things.

Free Monitoring Stack

DomainToolCadence
M365 configMicrosoft365DSCContinuous
M365 testsMaesterWeekly (CI)
M365 CISAScubaGearMonthly
Active DirectoryPingCastleWeekly
AD attack pathsBloodHound CEQuarterly
AD + EntraPurple KnightMonthly
CloudProwlerDaily
LinuxLynisWeekly
CredentialsTruffleHogCI + quarterly
GWSScubaGogglesMonthly