Security

Security at Driftmark

Driftmark is designed to provide visibility into Microsoft Entra ID configuration while maintaining strict security principles and minimal access requirements.

Driftmark is built by identity and access management practitioners with deep experience designing and securing Microsoft Entra ID environments.

Read-only access to Microsoft Entra ID

Driftmark connects to Microsoft Entra ID using Microsoft Graph APIs with read-only permissions. The platform collects configuration metadata required to capture configuration snapshots and detect configuration drift across identity controls.

Driftmark does not modify Microsoft Entra ID configuration.

Read-only Microsoft Graph access
No policy or role modification
No identity lifecycle changes

Required Microsoft Graph permissions

Driftmark requires Microsoft Graph permissions to read configuration data across key identity control families. Permission scope covers configuration visibility for the following families:

Identity & Access
Security Policies
Privileged Access (PIM)
Identity Governance
Applications & Service Principals
External Collaboration

Configuration data collected by Driftmark

Driftmark collects configuration metadata required to capture configuration snapshots and evaluate drift across identity controls. This includes policy configuration, role assignments, application configuration, access settings, and governance configuration.

Data Driftmark does NOT collect

Passwords
Authentication secrets
User credentials
Sign-in logs
Authentication tokens

Configuration snapshot storage

Driftmark stores configuration snapshots that represent the state of identity configuration at specific points in time. These snapshots allow comparison between states to detect configuration drift and support review workflows.

Only configuration metadata necessary for drift detection and reporting is stored.

Security principles

Least privilege access

Driftmark requests only the permissions required to read configuration state.

Configuration visibility without modification

Driftmark observes configuration state but does not change tenant settings.

Secure communication

All communication with Microsoft Graph and the Driftmark platform occurs over encrypted HTTPS connections.

Responsible disclosure

If you believe you have discovered a security vulnerability in Driftmark, please contact us.

Built by identity security practitioners

Driftmark is developed by identity and access management practitioners with deep experience in Microsoft Entra ID architecture, governance, and security operations.

The platform is designed to reflect real-world identity security challenges faced by enterprise environments.