https://store-images.s-microsoft.com/image/apps.2710.7ef04050-692b-40c5-9a00-2869313baeb2.e1cf0266-68e0-4f5d-9cee-a8df77d39e59.a003f422-feb2-4534-adcb-43fd0c844409

Compliance Drift And Configuration Deviation

by People Tech Group Inc

Detects and prioritizes deviations from baseline configurations across Azure and managed endpoints.

Search results summary

Automatically detects and prioritizes security misconfigurations and non-compliant devices to fix compliance drift.

Description

The Compliance Drift & Configuration Deviation Agent acts as a virtual compliance manager, continuously scanning your environment for deviations from your security baseline.

This agent proactively hunts for two distinct types of "drift":

  1. Cloud Configuration Drift: It ingests recommendations from Microsoft Defender for Cloud to find unhealthy or misconfigured Azure resources.

  2. Endpoint Compliance Drift: It analyzes Entra ID sign-in logs to identify users who are successfully accessing corporate resources from non-compliant devices.

The agent's primary goal is to provide a single, prioritized report of all security deviations, allowing you to fix misconfigurations and enforce device compliance before they become a critical risk.

Key Features

  • Dual-Focus: Correlates both cloud infrastructure posture (from Defender for Cloud) and endpoint device posture (from Entra ID).

  • Prioritized Alerts: Automatically groups findings by severity, helping you focus on high-priority recommendations first.

  • Event-Driven: Can be triggered in real-time when a new critical recommendation is generated by Defender for Cloud, enabling rapid response.

  • Reduces Posture Debt: Provides a daily report of deviations, helping you measurably improve your Secure Score and compliance.

How It Works

On a daily schedule and when triggered by new critical alerts, the agent runs a series of KQL queries against your Microsoft Sentinel workspace. It queries the table for cloud drift and the table for device drift, then aggregates the findings into a single, actionable report.

At a glance

https://store-images.s-microsoft.com/image/apps.7617.7ef04050-692b-40c5-9a00-2869313baeb2.e1cf0266-68e0-4f5d-9cee-a8df77d39e59.e95beec1-3487-4ee7-a962-f80bda325469
https://store-images.s-microsoft.com/image/apps.58232.7ef04050-692b-40c5-9a00-2869313baeb2.e1cf0266-68e0-4f5d-9cee-a8df77d39e59.f43cf007-dfa2-4516-83be-c90f3737a8c8