Skip to main content

Drift Detection for Virtual Desktops

M
Written by Mike Castro

What Drift Detection is

Drift Detection tells you when your Secureframe Virtual Desktops infrastructure has been changed outside of Secureframe. Secureframe deploys and manages a defined set of resources and settings in your Azure Government environment. When someone changes those resources or settings directly in Azure, that change is flagged as a drift. Drift Detection shows you what changed, who changed it and how much it matters. You then decide whether to keep the change or have Secureframe revert it. Every change is visible and traced to who made it, and every decision is logged for your records.

  1. Secureframe regularly checks your Azure environment for changes made outside Secureframe to your virtual desktop infrastructure.

  2. For each changed resource, Secureframe compares it against the configuration it deployed. If anything differs, Secureframe records it as drift, notifies you, and shows a banner on the Virtual Desktops page.

  3. You review each change and choose to keep or revert it, with a short reason.

  4. You redeploy to apply any revert decisions.

  5. Every decision is recorded in the Drift log.

What Drift Detection Monitors

Secureframe deploys your virtual desktops into resource groups it creates and manages in your Azure Government environment. Drift Detection monitors everything Secureframe created in those resource groups, such as the networking and security resources set up when you connected Azure Government, and the host pools, desktops and storage created when you provisioned desktops.

Drift Detection reports three types of change:

  • Change: Someone changed a setting that Secureframe configured.

  • Addition: Someone created a new resource inside a Secureframe resource group, such as a virtual machine built directly in Azure.

  • Removal: Someone deleted a resource that Secureframe manages.

Drift Detection focuses only on what Secureframe deployed. Resources in your own resource groups, settings Secureframe didn't configure, and supporting resources Azure creates.

Reviewing Detected Drift

From the left-hand navigation, select Virtual Desktops. When drift is detected, a Drift detected banner appears at the top of the page. Select Review drift to open the list of changes waiting for a decision.

Each change shows:

  • Change: What changed

  • Type: Change, Addition or Removal.

  • Severity:

    • High: Affects your environment's security posture.

    • Low: Cosmetic or operational changes.

    • Unknown risk: New resources Secureframe can't assess.

  • Applies to: Where the change happened.

    • Infrastructure is the foundation Secureframe created when you connected Azure Government, such as networking and security resources.

    • Virtual desktops covers the desktops and host pools created when you provision desktops.

  • Changed by: Who made the change in Azure. Secureframe users appear by name. For anyone else, Secureframe shows the identity recorded in Azure: an email address for a person, or an ID for an application or automated process.

  • Changed on: When the change was made in Azure.

Select a change to see its full details, including when Secureframe detected it.

Deciding What to Do with a Drift

Review drift works like an inbox. Decide on each change, then redeploy to apply your reverts. Kept changes are logged right away, since there's nothing to apply. Reverted changes stay in the inbox until the redeploy finishes, then move to the Drift log.

For each change, choose Keep or Revert and enter a short reason in the Why? field. Your reason is recorded with the decision.

Keep the change

Choose this when a Change or Addition was intentional and you want it to stay. The change leaves the review list right away and is recorded in the Drift log as kept. Future redeployments leave it in place.

Keep isn't available for Removals. If someone deletes a resource Secureframe manages, Secureframe recreates it at the next redeploy to keep your environment compliant. Choose Revert to record your decision in the Drift log.

Reverting the Change

Choose this when you want Secureframe to restore its configuration. What happens at the next redeploy depends on the type:

  • Change: The setting returns to Secureframe's configuration.

  • Addition: The resource is deleted.

  • Removal: The resource is recreated.

The change stays in the review list, marked Revert, until you redeploy. Select Redeploy on the Review drift page to apply your revert decisions. When the redeploy finishes, the change is recorded in the Drift log as reverted.

Note: Changed settings and added resources that you haven't reviewed are left in place when you redeploy, do until you decide on them. There are two exceptions:

Viewing the Drift Log

The Drift log keeps every keep and revert decision. From the Virtual Desktops page, open Settings and select the Drift log tab.

The log lists each kept or reverted change with its type, severity, what it applies to, who changed it and when. Select an entry to see who made the decision, when, and why.

Reverted entries are kept as history and can't be changed.

Changing a Previous Decision

  • Kept changes: Open the change in the Drift log and select Update decision. The change goes back to the review list, where you choose a new outcome and give a new reason. A new Revert takes effect at your next redeploy.

  • Pending reverts: Changes marked Revert stay in the review list until you redeploy, so you can change the decision there.

Frequently Asked Questions (FAQ)

Will Secureframe change my Azure environment without asking?

  • Drift Detection doesn't change anything on its own. It only reports changes. Changed settings and added resources stay as they are until you choose Revert and redeploy. The exceptions are removed resources and changes marked Reverts on redeploy. Both return to Secureframe's configuration at your next redeploy, because they are needed to keep your environment compliant.

Someone made a change in Azure but I don't see it. Why?

  • Drift Detection covers the resource groups Secureframe manages for your virtual desktops, and the settings Secureframe configures. Changes in your other resource groups aren't flagged. Changes are detected on a regular schedule, so a recent change may not appear right away.

Why does "Changed by" show an email address or an ID instead of a name?

  • The change was made by someone who isn't a Secureframe user, or by an application or automated process. Secureframe shows the identity recorded in your Azure activity log so you can trace the change.

I chose Revert, but the change is still listed. Is something wrong?

  • No. A revert takes effect when you redeploy. The change stays in the review list until the redeploy finishes, then moves to the Drift log.

Why can't I keep a removed resource?

  • Some resources are fundamental to how your virtual desktop environment works. If one is removed, Secureframe can't keep the environment running and compliant, so it rebuilds the resource at the next update.

Questions? Contact [email protected] or reach out to your CSM.

Did this answer your question?