
How configuration drift can quietly weaken your security posture—and what continuous Microsoft 365 assurance should look like
Live Webinar | Wednesday 30 September 2026
10:30am Adelaide Time
Presented by Aiden Clifford
Register Now
Your Microsoft 365 environment does not stand still.
New employees join. Roles and permissions change. Devices are added. Applications are connected. Security policies are updated. Microsoft continues to introduce new features and controls.
Each individual change may appear routine. Over time, however, they can cause your Microsoft 365 environment to drift away from the security standards your organisation originally established.
An environment that was securely configured six months ago may not provide the same protection today.
Join Subnet and Microsoft 365 security specialist Inforcer for a practical webinar exploring how configuration drift occurs, the risks it can introduce and how organisations can move beyond point-in-time security reviews towards continuous assurance.
When secure configurations begin to drift
Many organisations invest considerable time establishing Microsoft 365 security controls across Entra ID, Intune, Defender, Exchange, Teams, SharePoint and other services.
But establishing a secure baseline is only the beginning. Configuration drift can occur when:
- Security policies are changed or disabled
- New users receive unnecessary privileges
- Administrative roles accumulate over time
- Devices or applications are introduced without the expected controls
- Microsoft adds or modifies security capabilities
- Temporary exceptions remain in place longer than intended
- Different areas of the environment become inconsistently configured
These changes may happen gradually and without creating an obvious warning. Unless the environment is continually assessed against an agreed baseline, security and compliance gaps can remain unnoticed.
What you will learn
During this webinar, we will explore:
- What configuration drift means in a Microsoft 365 environment
- Why a securely configured tenant does not necessarily remain secure
- Common areas where settings, permissions and policies can drift
- The limitations of annual and point-in-time security assessments
- How security baselines can provide a consistent standard for Microsoft 365
- How organisations can detect and respond to unwanted configuration changes
- Why policy backup and recovery should form part of your security planning
- What continuous Microsoft 365 assurance can provide to IT teams and business leaders
Attendees will leave with a clearer understanding of how to determine whether their current Microsoft 365 configuration still reflects the security posture their organisation expects.
Who should attend?
This webinar is designed for professionals responsible for managing, securing or overseeing Microsoft 365, including:
- IT and ICT Managers
- CIOs and CTOs
- Microsoft 365 Administrators
- Infrastructure and Systems Managers
- Cybersecurity and Information Security professionals
- Risk, Governance and Compliance leaders
- CEOs, Managing Directors and executives responsible for organisational risk
The session will combine practical Microsoft 365 security insights with a broader discussion of governance, assurance and business risk. Deep technical expertise is not required.
Meet Your Speaker
Aidan Clifford
Head of Business Development, Australia & New Zealand | Inforcer
Aidan Clifford will join Subnet to explore how Microsoft 365 environments change over time, where configuration drift can introduce risk and how organisations can maintain greater visibility and control across their security settings.
Drawing on Inforcer’s specialist experience in Microsoft 365 policy management, Aidan will discuss practical approaches to establishing security baselines, identifying gaps and maintaining ongoing assurance as users, technologies and organisational requirements evolve.

Is your Microsoft 365 security keeping pace with change?
A security review can provide confidence in your Microsoft 365 environment at a particular point in time. The more difficult question is whether that environment remains secure as your organisation continues to change.
Register for this webinar to learn how configuration drift occurs—and what your organisation can do to identify and address it before it becomes a security or compliance issue.
