CIPP's drift management fixes deviations without touching a schedule
A walkthrough for MSPs using CIPP standards who need to catch and remediate tenant configuration drift as it happens, not on a nightly run
The short version
This tutorial covers CIPP release v8.3.0, nicknamed Tokyo Drift, and its headline feature: drift management. It walks through creating drift templates, choosing automatic or manual remediation, accepting or denying deviations, and the improved audit log format that standardises fields across Microsoft's inconsistent logging. Useful for anyone running CIPP standards against client tenants who wants to catch unauthorised changes without waiting for a scheduled run.
What you'll take away
-
Drift management explained
CIPP now monitors deployed standards continuously and flags any unauthorised change instead of waiting for the next scheduled run.
-
Automatic vs manual remediation
Ticking automatic remediation reverts unauthorised changes back to the template straight away. Leaving it off just sends an email or web hook so you can review first.
-
Accept, deny, or ignore a deviation
You can accept a deviation for one customer, accept it for the whole policy, or deny it and CIPP fixes the setting back immediately.
-
No schedule needed
Drift templates run on detection, not on a timer, so there is no daily or hourly interval to configure like a standard standard.
-
Two new standards worth checking
This release adds a SharePoint and OneDrive file request link standard and an authentication methods policy migration standard, both with drift monitoring built in.
-
Audit logs finally behave
CIPP now enriches Microsoft's inconsistent audit log fields into its own consistent format, so username and object ID data is reliable across log types.
Key insights from the episode
-
Find new standards fast by going to standards.app with new equals true, or clicking the new button on the standards page.
-
The web hook still fires under manual remediation even though CIPP's own description only mentions email notifications.
-
On a drift template's dropdown, ticking automatically remediate or deploy when drift is detected reverts changes the moment they are found.
-
The tenant history timeline under standards management only shows five days by default, but a load more button extends it, one tester got to 40 days.
-
Accepting a deviation for the whole policy allows that same change to happen again in future without triggering another alert.
-
Denying a deviation on a conditional access template gives you the extra option to delete the policy entirely rather than just remediate it.
-
Use the drift template's web hook URL to feed alerts straight into a HaloPSA runbook rather than relying on email.
Questions people actually ask
What is drift management in CIPP?
Drift management in CIPP monitors tenant configurations against a deployed template and flags any change that does not match, called a deviation. You can then accept the deviation for one customer, accept it for the whole policy, or deny it so CIPP reverts the setting back to the template.
How do I set up automatic remediation in a CIPP drift template?
Open the standard within your drift template, hit the dropdown, and tick automatically remediate or deploy when drift is detected. This immediately reverts any unauthorised change back to the template configuration as soon as it is picked up, rather than waiting for you to review it.
Does CIPP drift management run on a schedule?
No. Unlike standard standards which run on a set interval, drift templates run when a change is detected. There is no schedule field to configure for a drift template.
How do I find new standards added in a CIPP release?
Go to the standards page and click the new button, or visit standards.app with new equals true in the URL. This filters the list down to only the standards introduced in that specific release.
What changed with CIPP audit logs in this release?
CIPP now enriches audit log entries with consistent fields such as username and object ID, rather than relying on Microsoft's inconsistent formatting across different log types. This makes searching and filtering audit logs far more reliable.
Can I send CIPP drift alerts to HaloPSA?
Yes, if you leave automatic remediation off, CIPP can send a web hook alongside the email notification. You can point that web hook at a HaloPSA runbook to raise tickets or trigger further automation on detected drift.
Full transcript
3,336 words
Read full transcript
Collapse
Full transcript
3,336 words
CIPP had an update. Let's talk about it.
Feels like only last week that we were talking about a CIPP update, but we've been graciously handed another one. This one is called Tokyo Drift. As you can see here, it does have quite a few Fast and Furious puns. Um, the first of which being that we're a CIPP family. I don't have friends, I got family. And my first thought was, if we're a CIPP family, that must mean Kelvin's dad. So, in this case, dad has given us a new update. Our first thing to talk about, other than all the Fast and Furious puns, which we've done, there's drift management being the big thing of this release. It's like standards plus+. We've got the standards with all of our templates and policies that we're applying to our customers and drift management is the new thing that's helping us monitor and actually remediate those problems when they happen. Or if we decide that, you know, the change that's happened, the drift that's occurred, we're happy with, we can choose to ignore or apply a customer specific deviation to that template and leave it there.
Another big thing for these release notes is not necessarily anything part of the release itself, but a new sort of documentation video demos that that CIPP have started doing. And you can see there's a few links to those here. So, we've got two here, another two links here, and I've got them in tabs which we can have a look at. So, the specific drift one, we've got some feature showcases that you can see here. Same goes for audit which is further down and I'll show you when we get there but I thought worth mentioning now because if there's anything I say now or you want a bit more of a in-depth hands-on tutorial I suggest having a look at those outside of what I show you here but to get going drift management like I said first one here kind of read through it in a way but I'll show you what we've got as well you can read these notes yourself but just sort of glancing through it restore config remove policies that have been added on accident or possible drift management we receive emails or webhooks. Uh you can set up a template. You can approve accept like I mentioned with deviations or deny using the portal. Uh when you set up drift management template start monitoring the environment.
So if we jump into our standards here. So obviously tenant administration standards and drift and then standard management. And if I just open one of these I'll pick it's only showing my classic standards at the minute. You'll see here if you click on the actions, if it's not a drift template, the removed drift and manage drift are greyed out. But if you view the tenant report, it's going to take you to the tenant report page of this standard regardless. Um, and we'll be able to see some of the new things. So, no drift data is available. Um, we'll create one of those in a minute and show you uh that stuff there. But there's also these new UI features, I guess, that have been added to drift and standards and standards and drift, I guess it's called. You've got the policies and settings deployed. So, this should list a bunch, but the one I've picked happens to not have any in it.
The history of a standard. So, let me find a better one. We'll try this one. Drift. It's going to be empty again, but you can see this drift overview current deviations. We'll see policies and settings. Here you go. So, 26 security standards are applied to this specific policy. And you can see the status of them when they were last modified, the category that they're a part of, which is going to mirror typically uh security standards here in tune policies. These would be the categories. It's it's a helpful way to see quickly where there is deviation. None of these are actually applied, so they're all deviating, but we'll pretend it's not that way. If I go to the history, this is a cool big one. Is the actual timeline of uh actions taken on the tenant by CIPP in the last 5 days. So obviously it's only 5 days worth. But it is very handy to see things like that. And if there are errors in this case, you can investigate what that is. There must have been an outage at this point cuz obviously it then worked again later. And apparently there's a load more button to show 12 days. So I did not know that. And that updated as well. That's quite cool. So if you scroll down to the bottom, looks like you can load a bunch more. I wonder how long this goes on for. Whoever wants to scroll down repeatedly for the end of days and then tell us how long it goes for, be my guest. But I'm going to stop at 40 days. Although that is cool. History activity timeline. Really big thing for me. I've had a quite a few different people talk about it. Similar to the thing I said last time about tenant alignment reports. This is really handy to see uh these things here. And the drift is going to be really helpful. the alignment as well as well as the tenant report which already existed previously. I think it was just under a report rather than the UI or it might have been like this as well. I can't actually remember specifically but nonetheless let's go back. Let's go to templates. So standards management just the templates tab. We'll create a drift template now. So I don't actually have any of these in my instance at the minute but we'll start creating one here. So gives us a little bit of information about them. Remediation options. So, automatic remediation immediately alert uh reverts unauthorised changes back to the template configuration and manual remediation sends email notifications for review allowing you to accept or deny detected changes. I believe this manual remediation one it says email notifications but it should still do the webhook as well. So if you want to in our case uh HaloPSA runbook or something you want to get the alerts directly to the uh runbook you can use that webhook URL and then work with it further for whatever needs you want. Same thing goes with included tenants for standards as you would typically do. So I could do all tenants and then exclude my YouTube tenants or something or I could do it the other way around and only do my YouTube tenants and exclude demo tenants or something. Right? Give it a name. So drift. So, if we add a standard to the template, um, and I'm just going to double check what Kelvin's added previously. So, disable exchange online and de-mark. Um, if I do that one and de-mark, it's going to give us a couple of good examples. Um, and default sharing link settings. Sharing link settings.
Cool. I wonder actually there's some new ones. So, let's check that. We'll have a quick look at these as well while we're there. So, if we hit the little drop down on a standard, we can see there's an automatically remediate or deploy when drift is detected. And if we tick that, we know that immediate automatic remediation is going to happen. It's going to immediately revert unauthorised changes back to the template configuration. So, effectively the same as a standard, it's going to remediate and apply that immediately for us. Can hit save on that and it's going to configure it for us. And then when I save the template, it's obviously then going to apply to these tenants. So that that's a I guess a key difference between standards and drift templates. You'll notice that there's no schedule. They will run when detected effectively. Detection unauthorised remediated. Pretty straightforward rather than, you know, once a day or or whatever it's set to for the standard. The next one here, so de-mark in this case, the reason he's picked it is because of this dropdown. So it's to show off obviously selecting a drop down. If we don't hit this switch, it will instead report and it will send us an email or if we have configured an alert webhook or both and that will tell us any information about it. We can come back in here and decide whether or not we want to accept or deny those changes for that customer or for the policy as a whole. Similar here, default sharing link. We can select the type. So either internal or only. And then we can enable it to always set it to internal only. And outside of that, save that one as well. These are the two new ones that we've got. So if you're unaware, we'll go back to the release here. There's some things. One of them mentions standard. So that one mentions a standard and the other one mustn't be mentioned as a standard. So I'll ignore that. But in this case, if it's listed here and you're not sure or you're not sure in general, you can come to standards.app new equals true or just click the new button here and it will show us the two new standards that are applied to this specific release. Um, and you can see that these there's the set SharePoint and OneDrive file requests as per this one here or additionally the complete authentication methods policy migration which I definitely saw somewhere. I spend too long looking for it. Let's control F again. So, I'm going to assume that's it. But, nonetheless, check the standards app website um for some more information about new standards. So, if the last thing you do or the the minimal thing that you do for each CIPP release is come here and check if there's a new one that applies to you, do that because that's helpful nonetheless to to keep your standards up to date and any new features that might be beneficial for your business. But, of those two standards, they're both here. So we can enable auto disable file request and I want you to create secure upload only links set the maximum number of days for the link to remain active. So yeah, I guess you could configure link expiration if you want that to be a set time or if you don't want them at all, you can turn it off that sort of thing and enable this to drift management if if you so please. Same goes for authentication policy migration and that one you can just monitor drift. There's no additional settings. So, pretty straightforward on those. And that's pretty much it for drift. I wanted to show the actual drift information itself. So, can we pull that up? Let's have a look see.
Okay. So, I've got a drift template configured now. And I just want to show you what the drift management page sort of looks like. We've already seen the other three. Previously, this was just no data, but I've got one working and ready. Now if I open this one as an example, you can see sort of more information about the template that's applied to this drift standard drift template itself. Description of it, it's expected value, its current value, and whether or not it is a deviation. As an example here, if I hit the actions, I get three options. In this case, accepting the deviation for this specific customer. I can accept a deviation for the policy as a whole. So this is allowed to happen in future for this policy. And I can deny the deviation where it essentially will fix this for us as soon as I hit that button. So in this case, I will deny this. I'm going to say PowerShell shouldn't be needed for non-admin users. And because I'm special, I'm going to change that S cuz it's going to annoy me. I'll hit confirm. That loads. It says it successfully set the drift deviation status for standards. I'm really going to mess up a lot of these words. Drift deviation. I did it right the second time to be fair. This one here is a conditional access template which I've set. The name probably could be a bit improved there, but for whatever reason it's showing like that. That's going to be the specific GUID of the template I selected, I guess. And same thing here. I can accept the deviation customer specific for the whole policy. I can remediate it to align with the template or I can delete the policy as a whole if I just don't think it should be applied anymore or there's a change in the future or whatever the case may be. In this case, I'm going to accept it because I just have decided I I want to. Um, interestingly, it says mandatory and it wasn't in that case, but I wonder if that applies for denied deviations as well. Let's open this one and we'll remediate it and ignore that. Interesting. Maybe I'll get in and sneakily do my uh my first update to to the repo. But that's how that works. Obviously at this case it's going to show us accepted deviations customer specific there would be one the whole thing and denied deviations here as well as current deviations if there's any outstanding and I think if I set this to delete wonder what that's going to do it's just going to oh I don't know it's going to say it's denied and then obviously it won't exist anymore in that policy specifically but that is the big piece of the cake um for this release note anyway for standards and drift the next thing on my list was the audit logging. So it kind of looks like a small release but obviously as you've seen so far there's a lot of stuff in it and like I mentioned there there's two more of those demos here and what Kelvin said is that Microsoft's audit logging is the formats they use weird with places underscores entid username blah blah improve that we enrich the data in the audit logs with CIPP versions CIPP username 100% guaranteed to be actual username so that's good so effectively they're filtering on the different types of audit logs and putting into its own sort of I guess CIPP custom field on that side of things and and making it a lot better. So if I go to this tab um I can see it's obviously under tenant administration audit logs um and I've got a list of saved logs. So specifically let's look at this one. If I hit the three dots and then view log I can see more information about this log as a whole what it's sort of done. So actions taken in this case the webhook rule and the the big sort of improvement here is the audit data itself. So things like where is a good example object ID will be the expected one. I'm not seeing any of the specific fields but effectively this data here is going to be more consistent with what you would expect rather than all the different types of things that you would see typically in the log book from different parts of the Microsoft UI. There's obviously search options in here and you can do a full log search too if you wanted to by using the new search button here. And all of the different information that you want to try and filter by can be done here. Like I said as well, there's these two demo videos that you can go through and look at some more information or get a bit more of a hands-on with it um by clicking through with this new new thing that that CIPP have done. Now, other than that, I think that's pretty much all I wanted to say. We've got obviously this line here is talking about the history that I showed you under standards management. There was one thing I remember want to say. Oh, yep. So, as per usual, Kelvin has updated the Microsoft licences again. Three times, I think. Yep. Yeah, three times. So, keep an eye on him. I think we might start a Kelvin update licence counter or something for for these release notes. I think I'd have to check the last one, but we're probably at like five at this point and it's only been two videos, so that's that's enough a fun one. I guess it's called chore for a reason, right? So, the other one that I wanted to list and these ones are all just in these what's changed kind of like less impactful or times very impactful but less of a big feature and more of like a a fix or a small addition. Um the other one would be the bulk add mailbox permissions which is here where Zack has enhanced mailbox permission modification and bulk request tracking. So we can now bulk add mailbox permissions which is very very handy to say the least. And I think that is all I really wanted to talk about today. Um, yeah, there's obviously, like I say normally, go and have a look at this if you've got any real interest in deep diving into different commits yourselves. If there's anything interesting you want to want to tell us about this release that you've found yourself, you've noticed, or you just want to talk to someone, you're a bit lonely, let us know in the comments, and we'll go from there. I will see you probably next week for another release. Bye.
Author
Related tutorials
Our Core Services
Offering support to enable sustainable success for your organisation.