TrueState
TrueState goes beyond a one-time scan. It locks your secure configuration once as a baseline, then watches every change in your environment and catches drift on its own.
Two stages
First you turn on monitoring. At this stage your configuration is visible but not yet protected. Then you lock TrueState. The configuration you approved is frozen as the baseline. From that point every addition, removal or change is reported with its before and after.
Without a baseline, no workload shows as "Protected". As long as you have not locked it, the state is shown honestly as "Monitored".
What it watches
Conditional Access policies, privileged roles, device and app settings, sensitivity labels, Defender configuration and more. Every drift is written to a permanent record with a Ticket ID, and an email goes to the alert recipients.
Monitoring frequency
Monitoring runs continuously, but not every check shares the same rhythm. Deviations from your locked baseline are checked hourly, and an alert goes out without delay when a change is caught. The full scan of all 233 controls refreshes every four hours. This interval balances the load on Microsoft Graph and keeps the control results you see in the dashboard at most four hours old. Critical VIP identity events (a new admin assignment, a change to an MFA method) are watched separately in near real time, roughly every 15 minutes.
Living configuration and the "Flexible" exception
Some fields change by design. An automation might add a user to a Conditional Access exclusion list, for example. So that this does not raise a constant false alarm, you can mark that policy's exclusion list as "Flexible". Only that inner field drops out of monitoring; the rest of the policy stays watched.
Dual control
Any change to the secure baseline needs approval from at least two administrators, and one of them must be a Global Administrator. A drift cannot be quietly folded into the baseline, and every change stays auditable.
Trend: your posture over time
TrueState shows not only your current state but how your security posture moves over time. The "Trend" tab charts your overall security score across months in a single view, answering the question "you were here six months ago, you are here today".
You can pick two dates and compare what changed between them: which controls improved and which regressed. Alongside the chart are summary indicators for open drift, VIP deviations and baseline status. For the detail behind each change (who, when, before and after) you drill into the Security Movements records.
The trend is derived from daily posture snapshots kept server-side. These accumulate in the background even when you do not open the app; they hold only counts and status, never user or VIP identity. That keeps them privacy-safe and suitable for long retention. History starts accumulating from the moment you turn on monitoring.