Methodology: Configuration drift detection is a continuous posture loop — the third OODA loop running at a different tempo than incident detection. See Detection Engineering for how detection tiers map to different cycle times.
Shift Down, Not Shift Left. Don't hand people a security policy and wish them luck. Wire security into the platform so teams get it for free. The consulting diagnostic: "What security controls require someone to remember to do something?" Each answer is a drift candidate.
This playbook is built from post-breach forensics, not theory. Every setting below was found misconfigured in real incident investigations by Sophos (661 cases, 70 countries), Mandiant (M-Trends), CISA/NSA (AA23-278A), Verizon DBIR, and CrowdStrike. These are the specific configurations that were wrong when the breach happened.
The 15 Settings That Actually Get You Breached
Prioritized by breach frequency and impact. P0 = found in the majority of breaches. P1 = common attack enabler. P2 = amplifies blast radius. Every setting has a specific breach outcome.
P0 — Critical (found in majority of breaches)
| # | Setting | Breach Evidence | Check Command |
|---|---|---|---|
| 1 | Legacy auth protocols enabled (BAV2ROPC, SMTP AUTH, POP3, IMAP4) |
99% of password spray, 97% of credential stuffing uses legacy auth. 9,000+ Exchange login attempts in 3 weeks via legacy protocols (Guardz 2025). Orgs that disabled legacy auth saw 67% fewer compromises. | Get-MgIdentityConditionalAccessPolicy | Where {$_.Conditions.ClientAppTypes -contains "exchangeActiveSync"} |
| 2 | MFA coverage gaps (users, apps, service principals) |
MFA not configured in 59% of breached organizations (Sophos, 661 cases). Three failure modes: believed enabled but wasn't, enabled but misconfigured, known gap never addressed. One user missing = entire control trivial. | Get-MgUser -All | Where {$_.StrongAuthenticationMethods.Count -eq 0} |
| 3 | AD CS template misconfigs (ESC1: ENROLLEE_SUPPLIES_SUBJECT + Client Auth EKU) |
Mandiant: attackers exploit misconfigured certificate templates to create admin accounts that bypass MFA and survive password rotation. UNC5330 used this to impersonate domain admins after Ivanti exploitation (April 2024). | certutil -v -dstemplate | findstr "msPKI-Certificate-Name-Flag" "ENROLLEE_SUPPLIES_SUBJECT" |
| 4 | Backup server domain-joined or using default/shared credentials |
CVE-2025-23120: any domain user can RCE on domain-joined Veeam server. 94% of ransomware attacks attempt to compromise backups, 57% succeed (Sophos). Storm-0501: exfiltrate → delete backups → encrypt. | Check: Is backup server in AD? Does backup admin = domain admin? Can domain admin delete backups? |
P1 — High (common attack enabler)
| # | Setting | Breach Evidence | Check Command |
|---|---|---|---|
| 5 | RDP exposed to internet | RDP involved in 66% of cases (internal use), still the most-abused tool though down from prior years (Sophos AAR 2026). Logistics firm hit via exposed RDP with no authentication. | Get-NetTCPConnection -LocalPort 3389 -State Listen+ external Shodan/Nmap scan |
| 6 | VPN/firewall default creds or no MFA | 71% of cases: attackers entered via external remote services (Sophos 2026). 37% of mid-market had at least one firewall with unchanged defaults in pen tests. Brute-force (15.6%) nearly matched exploitation (16%). | Manual: check VPN MFA config, verify no default admin passwords remain |
| 7 | SMB signing not enforced | CISA/NSA Top 10: enables NTLM relay attacks leading to complete domain takeover. Not enforced by default even in latest Windows versions. | Get-SmbServerConfiguration | Select RequireSecuritySignature |
| 8 | LLMNR/NBT-NS enabled | CISA/NSA Top 10: enabled by default, allows hash capture via spoofing/poisoning/relay. Combined with disabled SMB signing = domain compromise chain. | Get-NetAdapter | Get-DnsClient | Select InterfaceAlias, EnableMulticast |
| 9 | Conditional Access exclusions (stale, excessive, bypassable) |
CA policies targeting "all resources" bypassable via OIDC-only requests (Microsoft fixing March 2026). Device enrollment bypasses "Require compliant device." MFA exceptions accumulate and never expire. | Get-MgIdentityConditionalAccessPolicy | ForEach { $_.Conditions.Users.ExcludeUsers } |
| 10 | MFA method is push/OTP instead of FIDO2/passkeys |
79% of BEC victims had correctly implemented MFA and were still breached via AiTM token theft (FRSecure 2024-2025, 65 incidents). AiTM surged 46% in 2025. Only FIDO2/passkeys/hardware tokens stop it. | Get-MgUserAuthenticationMethod -UserId [admin] | Select AdditionalProperties |
P2 — Medium (amplifies blast radius)
| # | Setting | Breach Evidence | Check Command |
|---|---|---|---|
| 11 | Cloud storage publicly accessible | Over 80% of cloud breaches from basic misconfigs: open storage, broad access policies, poor segmentation (Verizon DBIR 2025). 50% of S3 buckets potentially misconfigured. | prowler aws -c s3_bucket_public_access or check AWS S3 Block Public Access setting |
| 12 | Service accounts with excessive privileges | Service accounts outnumber humans 5:1. Compromised service accounts enabled lateral movement across cloud environments (Mandiant M-Trends). 35% of cloud incidents via valid accounts (CrowdStrike 2026). | Audit: list all service accounts with Owner/Contributor/Global Admin roles |
| 13 | No 24/7 monitoring coverage | 88% of ransomware payloads and 79% of data exfiltration occur outside business hours (Sophos 2026). Without 24/7 coverage, you miss the actual attack. | Question: who gets alerted at 2 AM Saturday when encryption starts? |
| 14 | Flat network / no segmentation | Nearly 40% of breaches involved privilege escalation or lateral movement (DBIR 2025). "Allow all" rules created for troubleshooting never removed. CISA/NSA Top 10 #4. | Get-NetFirewallRule -Direction Inbound -Action Allow | Where {$_.RemoteAddress -eq "Any"} |
| 15 | Infostealer-exposed creds not monitored | 73% of ransomware victims had a prior infostealer or credential leak in the year before the attack — and half of those were ransomwared within 95 days of the leak (DBIR 2026). Nobody checked. | Search HIBP domain search + check if exposed passwords are still active |
Entry Point: Forensic Configuration Assessment
Not a generic CIS benchmark scan. Check the 15 specific settings that show up in breach investigations. Score each. Fix what's red.
1–2 days
Entry point
Assessment Script (P0 checks)
# P0-1: Legacy auth — any CA policy still allowing it?
Get-MgIdentityConditionalAccessPolicy | Select DisplayName, State,
@{N='ClientApps';E={$_.Conditions.ClientAppTypes -join ','}}
# P0-2: MFA gaps — users without any strong auth method
Get-MgUser -All -Property StrongAuthenticationMethods |
Where-Object { $_.StrongAuthenticationMethods.Count -eq 0 } |
Select DisplayName, UserPrincipalName
# P0-3: AD CS — find vulnerable templates (ESC1)
# Run from domain-joined machine:
certutil -v -dstemplate | findstr /i "ENROLLEE_SUPPLIES_SUBJECT"
# P0-4: Backup server domain membership
Get-ADComputer -Filter {Name -like "*backup*" -or Name -like "*veeam*"} |
Select Name, DistinguishedName
# P1-5: RDP listeners
Get-NetTCPConnection -LocalPort 3389 -State Listen
# P1-7: SMB signing
Get-SmbServerConfiguration | Select RequireSecuritySignature
# P1-9: Conditional Access exclusions
Get-MgIdentityConditionalAccessPolicy | ForEach-Object {
[PSCustomObject]@{
Policy = $_.DisplayName
State = $_.State
ExcludedUsers = ($_.Conditions.Users.ExcludeUsers -join ',')
ExcludedGroups = ($_.Conditions.Users.ExcludeGroups -join ',')
}
} | Where { $_.ExcludedUsers -or $_.ExcludedGroups }
Output
Scorecard against the 15 settings: Exposed Partially configured Hardened. Each finding maps to the specific breach outcome it enables.
1 Containment — Fix What's Actively Exploitable
The assessment may reveal settings that represent active risk right now. These get fixed today, not next sprint.
Quick Wins (Day 0, Free)
- Block legacy auth protocols — create a CA policy that blocks Exchange ActiveSync, POP3, IMAP4, SMTP AUTH. This single change eliminates 99% of password spray.
- Revoke all MFA exceptions older than 30 days — if the user hasn't re-requested, they don't need it
- Enforce CA policies stuck in "report-only" — report-only = not protecting anything
- Close RDP to internet — disable on all machines where not needed, require VPN+MFA where needed
- Enable SMB signing via GPO:
Microsoft network server: Digitally sign communications (always) = Enabled - Disable LLMNR via GPO:
Turn off multicast name resolution = Enabled. Disable NBT-NS via DHCP or registry. - Disable stale admin accounts (90+ days inactive)
- Check HIBP for your domain — any exposed corporate credentials still active?
Core Engagement (1–2 days)
- AD CS template audit: Identify and remediate ESC1-ESC8 misconfigurations. Remove ENROLLEE_SUPPLIES_SUBJECT where not required. Restrict enrollment rights.
- Backup infrastructure separation: Remove backup server from AD domain. Create separate backup admin credentials. Verify immutability.
- Full exception inventory: Every CA exclusion, MFA exception, firewall rule exception gets: owner, justification, expiry date.
- Emergency baseline lock: Export current (corrected) config as the known-good state for drift monitoring.
Target State
All 15 settings hardened. Zero legacy auth. Zero exposed RDP. Zero undocumented exceptions. AD CS templates audited. Backup infrastructure separated from AD.
2 Detection — Know When Settings Drift Back
You fixed the 15 settings. How do you know when someone re-enables legacy auth, creates a new MFA exception, or opens an RDP port?
Quick Wins (Day 0, Free)
- Enable Entra audit log alerts for: CA policy changes, MFA method changes, role assignments, app consent grants
- Schedule weekly PingCastle scan:
PingCastle.exe --healthcheck— tracks AD health score trend - Schedule monthly ScubaGear scan — M365 config vs CISA baselines
- Alert on new firewall rules that allow inbound from Any/0.0.0.0/0
- Track Secure Score weekly — score should never decrease without documented exception
Core Engagement (2–3 days)
- Deploy Maester — 360+ Pester-based M365 security tests in GitHub Actions. Weekly automated runs. Alerts on failure.
- Deploy Microsoft365DSC — export desired M365 config as code. LCM monitors continuously. Three modes: detect, alert, or auto-revert drift.
- Build drift dashboard: M365 Secure Score trend, PingCastle AD score trend, exception count trend, P0 setting status.
- Increase log retention to 365 days — don't rely on defaults (Windows Event Log defaults = 20MB, overwrites in hours). 1TB disk costs less than a coffee per day. Store logs on-host AND forward to central logging. On-host logs are your forensic backup if central is compromised.
Target State
Configuration-as-code for M365. Every P0/P1 setting change detected within 24 hours. 365-day log retention on all servers + central logging. Dashboard shows posture trajectory.
3 Posture — Lock the Baseline
Turn the 15 settings from "things we check" into "things the platform enforces." Make drift require deliberate action, not neglect.
Quick Wins (Day 0, Free)
- Enable Standard Preset Security Policy in M365 Defender — one toggle, 15 minutes, activates dozens of settings
- Enable Microsoft-managed CA policies — auto-created in report-only, switch to enforcing
- Set MFA exception expiry policy: max 30 days, requires owner + justification. No permanent exceptions.
- Deploy Microsoft LAPS — unique local admin password per machine, eliminates shared local admin
- Run Lynis on Linux servers:
lynis audit system --cronjob
Core Engagement (2–3 days)
- M365 config-as-code: Export desired state via Microsoft365DSC, commit to Git. Any drift = alert or auto-revert. PR-based change process for intentional modifications.
- AD hardening baseline: Tiered admin model, GPO security settings, LLMNR/NBT-NS disabled org-wide, SMB signing enforced, AD CS templates remediated, Kerberos delegation restrictions.
- Firewall rule cleanup: Remove rules older than 12 months with no traffic. Document remaining rules. Block new allow-rules without change ticket.
- FIDO2/passkeys for admins: Upgrade from push/OTP to phishing-resistant MFA for all privileged accounts. This fixes P1-10 (79% of BEC victims had MFA but wrong kind).
- CIS Benchmark alignment: Run OpenSCAP or CIS-CAT against servers. Remediate to Level 1 minimum.
Target State
Desired state is code. Drift is a build failure. All 15 settings have locked baselines with automated monitoring. Exceptions require approval workflow with mandatory expiry. The platform IS the control.
4 Vulnerability Management — Prevent Re-Drift
Drift is entropy. The cadence below keeps the 15 settings hardened permanently.
| Cadence | Action | Detects Drift In | Tool |
|---|---|---|---|
| Continuous | M365 config drift monitoring | P0-1, P0-2, P1-9, P1-10 | Microsoft365DSC |
| Weekly | M365 security test suite | All M365-related settings | Maester (GitHub Actions) |
| Weekly | AD security health check | P0-3, P1-7, P1-8, service accounts | PingCastle |
| Weekly | Secure Score trend tracking | Any M365 posture regression | Graph API + script |
| Daily | Cloud posture scan | P2-11, P2-12 | Prowler |
| Monthly | Full CISA baseline check | All M365 settings | ScubaGear |
| Monthly | Exception list review | P0-2, P1-9 (MFA + CA exceptions) | PowerShell + manual |
| Monthly | Credential exposure check | P2-15 | HIBP domain search |
| Quarterly | Full CIS benchmark | Server/endpoint drift | OpenSCAP / CIS-CAT |
| Quarterly | AD CS template audit | P0-3 | certutil + manual review |
| Quarterly | Firewall rule cleanup | P2-14 | Export + diff vs baseline |
| Quarterly | Privilege access review | P2-12 (service accounts) | BloodHound + AD audit |
Target State
Every P0 setting monitored continuously or weekly. P1 settings checked weekly or monthly. P2 quarterly. Drift never accumulates beyond one review cycle. Exception lists shrink over time.
5 Structural — Make Drift Architecturally Difficult
Remove humans from the loop. If the platform enforces the baseline, drift requires deliberate action.
Core Engagement (3–5 days)
- Config-as-code pipeline: M365 desired state in Git (Microsoft365DSC). PR-based changes. Auto-revert unauthorized modifications. Full audit trail. Graduate each setting detect → alert → auto-revert only after it has run clean in alert mode; a setting that keeps flipping back and forth means another tool or admin process is fighting the pipeline — find it before auto-revert turns the fight into an outage.
- Exception workflow automation: Exceptions submitted via form/ticket → auto-approved max 30 days → auto-expired → auto-reported to management. No permanent exceptions possible.
- Separate management AD: All privileged accounts (backup admin, hypervisor admin, network admin) in a separate AD forest. Production trusts management (one-way). Attackers who compromise production AD cannot see or target the real admins — they don't exist in that directory.
- Log retention architecture: 365 days on every server (increase Windows Event Log to 1GB+ per channel). Forward to central logging on isolated infrastructure. On-host logs survive central compromise. Disks are cheap; missing forensic evidence is not.
- Board reporting: Quarterly posture report showing the 15 settings status, drift incidents, exception trends, Secure Score trajectory. One page.
- NIS2 mapping: Continuous posture monitoring satisfies "appropriate and proportionate measures." Drift monitoring IS the compliance evidence. The cadence table above maps directly to Article 21 requirements.
- Insurance evidence: Insurers want proof controls are "implemented AND enforced" — not just configured. MFA exception logs, CA enforcement evidence, automated drift reports with timestamps. This is what gets claims approved.
Target State
Security controls don't require someone to remember to do something. The platform IS the control. Admin accounts invisible to attackers via management AD. Logs retained 365 days. Compliance is continuous. The organization can prove its posture at any moment.
Program Economics (200-seat reference)
| Engagement | Duration | Investment |
|---|---|---|
| Forensic Configuration Assessment | 1–2 days | €1,250 – 2,500 |
| 1 Containment (fix P0s) | 1–2 days | €1,250 – 2,500 |
| 2 Detection (monitoring setup) | 2–3 days | €2,500 – 3,750 |
| 3 Posture (baseline lock) | 2–3 days | €2,500 – 3,750 |
| 4 Vuln Mgmt (cadence setup) | 1 day + cadence | €1,250 + €5,000/yr |
| 5 Structural (architecture) | 3–5 days | €3,750 – 6,250 |
| Full program | 10–16 days | €12,500 – 20,000 + retainer |
ROI: 61% of security leaders say they suffered a breach because of failed or misconfigured controls (Panaseer, 2025). The assessment alone finds the settings that were wrong in 59% of real breaches. All monitoring tools are free. The investment is the expertise to fix the right things.
Free Monitoring Stack
| Domain | Tool | Cadence |
|---|---|---|
| M365 config | Microsoft365DSC | Continuous |
| M365 tests | Maester | Weekly (CI) |
| M365 CISA | ScubaGear | Monthly |
| Active Directory | PingCastle | Weekly |
| AD attack paths | BloodHound CE | Quarterly |
| AD + Entra | Purple Knight | Monthly |
| Cloud | Prowler | Daily |
| Linux | Lynis | Weekly |
| Credentials | TruffleHog | CI + quarterly |
| GWS | ScubaGoggles | Monthly |
Sources
- Sophos Active Adversary 2025 — 400+ IR/MDR cases
- Sophos Active Adversary 2026 — 661 cases, 70 countries
- CISA/NSA Top 10 Misconfigs (AA23-278A)
- Mandiant M-Trends 2026 — AD CS, cloud misconfig
- Verizon DBIR 2025 — 80% cloud = misconfig
- CrowdStrike Global Threat Report 2026
- Guardz Legacy Auth Exploitation 2025
- FRSecure Token Theft / MFA Defeat 2025