# Security Baselines — Microsoft 365 Configuration Drift | Cyflow

> Hold a desired state for Microsoft 365 configuration, catch every setting that drifts away from it with its CIS reference and previous value, and remediate in dry-run, request or apply mode.

Canonical URL: https://cyflow.ai/security-baselines/
Last updated: 2026-07-30T00:00:00.000Z

---
![](/background-theme.webp)

Security Baselines

# Configuration drifts back

A setting gets loosened for one project and never gets put back. Baselines hold the state you decided on, compare it against live Microsoft 365, and show every difference with what it was, what it is now, and the CIS control behind it.

[Schedule a Demo](/schedule-demo/)[AI Readiness Assessment](/ai-readiness/)

Baselines — configuration drift

![Cyflow Baselines showing Microsoft 365 policies with aligned, drifted and exception status against CIS references](/screenshots/home/channel-config.webp)

Why it matters here

## Drift widens what AI can reach

Configuration sits upstream of everything else. A sharing default that flips open does not produce one finding — it produces thousands, one file at a time, through people doing their jobs normally.

### Sharing defaults

Anonymous link sharing re-enabled at tenant level means the next person to share a file gets an Anyone link without choosing one. The oversharing arrives quietly, through ordinary work.

### What an assistant may search

Restrictions on content discovery decide how much of the tenant Copilot can reach for an answer. Relaxed during a rollout and never restored is the most common way exposure grows after go-live.

### Identity posture

Conditional access and MFA coverage decide who reaches the tenant at all. A gap here sits upstream of every other control on this page, including the ones already working.

How it runs

## Compare, decide, put it back

Coverage is what the policy catalog holds rather than every setting Microsoft ships, and it grows as the catalog does. What is in the catalog is checked against live tenant state on every scan.

01

### Set the desired state

Start from the catalog of desired-state policies, adjust it to the decisions your organization actually made, and carry the same baseline across managed tenants instead of rebuilding it per client.

02

### Scan against live configuration

Each policy comes back aligned, drifted or excepted, with its previous and current value and its CIS reference. Settings you diverge from deliberately go on the allowlist or get marked safe, so they stop reappearing as noise.

03

### Remediate at the depth you trust

Dry-run shows what would change without changing it. Request sends the change for approval. Apply makes it. The mode is set per policy, and the record of what changed stays behind either way.

Keep reading

## Upstream and downstream

-   [AI ExposureConfiguration drift is one of six paths AI follows into sensitive data. This is the rest.Read more](/ai-exposure/)
-   [Autonomous remediationThe agents that correct drift, and how far each one is allowed to go before asking.Read more](/autonomous-remediation/)
-   [MSP programRunning one baseline across a book of client tenants, with white-label proof at the end.Read more](/msp/)

Scope and safety

## What it checks, and what it will change.

Which settings are covered?

The ones in the policy catalog — the settings Cyflow maintains a desired state and a remediation path for. It is deliberately not a claim to cover every setting in Microsoft 365; coverage grows as the catalog does.

Is this a CIS certification?

No. Policies carry CIS references so a finding traces back to a recognized control, but the output is a drift report and a remediation record — not a certification or an audit opinion.

Will it change our tenant without asking?

Only if you set it to. Remediation runs as dry-run, request or apply, and the first two change nothing until a person decides.

What about settings we diverge from on purpose?

Mark them safe or add them to the allowlist. They stay visible as a deliberate exception rather than returning as drift on every scan.

Does this work across multiple tenants?

Yes. A baseline can be applied to the managed tenants you select, which is the point for an MSP holding the same standard across a book of clients.

Decide the state once

## The cheapest place to fix exposure

Book a demo and we will run a baseline scan — the drift, the CIS references behind it, and a dry-run of the fix.

[Schedule a Demo](/schedule-demo/)[AI Readiness Assessment](/ai-readiness/)
