Tenant configuration management: snapshot your Entra config and catch drift
New APIs let you snapshot tenant configuration as JSON and monitor it for drift. Configuration as code for Entra just got much more practical.
Most Entra tenants are configured by hand, one portal click at a time. That works until someone changes a setting nobody wrote down, and the question becomes "what was it before?"
Tenant configuration management APIs, now generally available, let you take a snapshot of tenant configuration as JSON and set up monitors that detect drift from a known-good baseline. An admin center experience for managing monitors is in preview.
Ways to use it
- Baseline after a change. When a CAB-approved change goes in, snapshot the result. That becomes the reference.
- Drift alerts. Monitor the settings that matter most, such as authentication methods, Conditional Access and external collaboration, and alert on unexpected changes.
- Multi-tenant consistency. Compare test and production tenants, or several production tenants, against the same baseline.
- Store snapshots in Git. A JSON snapshot in source control gives you a readable history of your tenant over time.
How it fits with backup
Entra Backup and Recovery restores directory objects from the last few days. Configuration snapshots answer a different question: is my tenant still configured the way I intended? Use both.
Backup and Recovery
Can I undo a recent change?
- Automatic daily backups
- Seven days of history
- Restores objects and properties
Configuration management
Is my tenant still how I intended?
- Snapshots you choose to take
- Monitors that detect drift
- JSON you can keep in Git for years
What to monitor first
- Authentication methods policy
- Conditional Access policies and named locations
- External collaboration and cross-tenant access settings
- User consent and app registration settings
- Privileged role settings
Will a monitor stop someone making a change?
No. It detects and reports. Prevention is still Conditional Access, PIM and change control.
How do I handle approved changes?
Update the baseline as the last step of the change. If a monitor fires and there's no matching change record, that's worth a look.
This post was last checked against Microsoft's documentation over six months ago. The approach should still hold, but check the linked sources for anything that has changed before you act on it.