TrueState — Drift Detection
TrueState goes beyond a one-time scan. It locks your secure configuration once as a baseline, then watches every change in your environment and catches drift on its own.
Two stages
First you turn on monitoring. At this stage your configuration is visible but not yet protected. Then you lock TrueState. The configuration you approved is frozen as the baseline. From that point every addition, removal or change is reported with its before and after.
Without a baseline, no workload shows as "Protected". As long as you have not locked it, the state is shown honestly as "Monitored".
What it watches
Conditional Access policies, privileged roles, device and app settings, sensitivity labels, Defender configuration and more. Every drift is written to a permanent record with a Ticket ID, and an email goes to the alert recipients.
Living configuration and the "Flexible" exception
Some fields change by design. An automation might add a user to a Conditional Access exclusion list, for example. So that this does not raise a constant false alarm, you can mark that policy's exclusion list as "Flexible". Only that inner field drops out of monitoring; the rest of the policy stays watched.
Dual control
Any change to the secure baseline needs approval from at least two administrators, and one of them must be a Global Administrator. A drift cannot be quietly folded into the baseline, and every change stays auditable.