azureblog.co.uk
← cd ~/posts

Tenant configuration management: snapshot your Entra config and catch drift

New APIs let you snapshot tenant configuration as JSON and monitor it for drift. Configuration as code for Entra just got much more practical.

2 min read⚠ checked 8 Apr 2026Entra ID · Governance · What's new
On this page
  1. Ways to use it
  2. How it fits with backup
  3. What to monitor first

Most Entra tenants are configured by hand, one portal click at a time. That works until someone changes a setting nobody wrote down, and the question becomes "what was it before?"

AdminConfig management APITenantGit / alertsTake a snapshot afteran approved change1Read configuration asJSON2Store as the baseline3Monitor runs on aschedule4Compare with the baselineDrift found: raise an alert6
Baseline, monitor, alert.

Tenant configuration management APIs, now generally available, let you take a snapshot of tenant configuration as JSON and set up monitors that detect drift from a known-good baseline. An admin center experience for managing monitors is in preview.

Ways to use it

  • Baseline after a change. When a CAB-approved change goes in, snapshot the result. That becomes the reference.
  • Drift alerts. Monitor the settings that matter most, such as authentication methods, and external collaboration, and alert on unexpected changes.
  • Multi-tenant consistency. Compare test and production tenants, or several production tenants, against the same baseline.
  • Store snapshots in Git. A JSON snapshot in source control gives you a readable history of your tenant over time.

How it fits with backup

Entra Backup and Recovery restores directory objects from the last few days. Configuration snapshots answer a different question: is my tenant still configured the way I intended? Use both.

Backup and Recovery

Can I undo a recent change?

  • Automatic daily backups
  • Seven days of history
  • Restores objects and properties

Configuration management

Is my tenant still how I intended?

  • Snapshots you choose to take
  • Monitors that detect drift
  • JSON you can keep in Git for years
Two tools, two questions.

What to monitor first

  • Authentication methods policy
  • Conditional Access policies and
  • External collaboration and cross-tenant access settings
  • User consent and settings
  • Privileged role settings
Will a monitor stop someone making a change?

No. It detects and reports. Prevention is still Conditional Access, and change control.

How do I handle approved changes?

Update the baseline as the last step of the change. If a monitor fires and there's no matching change record, that's worth a look.

This post was last checked against Microsoft's documentation over six months ago. The approach should still hold, but check the linked sources for anything that has changed before you act on it.