Why your readiness score drops when nobody did anything wrong

Microsoft 365 security posture drift explained: why a tenant that scored 78 in January will not in June, and how to fix the source rather than the symptom.

LogiSam · 5 October 2026 · 4 min read
A Copilot readiness score sagging over time between scans

A tenant that scored 78 in January will not score 78 in June. Nobody will have done anything wrong, and the number will still be lower.

This is the part of tenant security that one-off assessments are structurally unable to describe: posture is not a state you reach, it is a state you maintain, and the default direction is downward.

Why it decays without anyone misbehaving

Four mechanisms, all of them ordinary.

New containers inherit old habits

Every new team creates a SharePoint site. If your template still has permissive sharing — or if the people creating teams have never been told otherwise — each new site starts from the configuration you spent last quarter fixing elsewhere. Remediation applies to what exists; it does not change what gets created next.

People accumulate

Guests get added for projects and are almost never removed when the project ends. Employees change role and keep the access from the old one. An administrator leaves and their account lingers through a notice period, a handover and then simple inattention. None of this is a breach. All of it widens what Copilot can reach on somebody's behalf.

Labels and policies stop being applied

A sensitivity label rollout has a launch, a training session and a compliance rate that is excellent in month one. By month six the new joiners were never trained, and the proportion of documents correctly labelled falls — not because anything broke, but because adoption is not self-sustaining.

Exceptions become permanent

Someone breaks inheritance on a site for a legitimate two-week reason. The two weeks pass. The exception does not. Multiply across a few hundred sites and a few years, and you have the permission model you set out to fix in the first place.

Drift is the argument for cadence

If posture were static, an annual assessment would be fine. It is not, so it is not.

The practical cadence most organisations land on is quarterly, with the two adjustments that matter: rescan after any significant tenant change — a migration, an acquisition, a new business unit — and rescan before anyone asks you to prove something, not after.

What you are watching for is not the absolute number. It is the direction and the rate. A tenant drifting two points a quarter is normal and manageable. One drifting ten points a quarter has a process problem that no amount of remediation will fix, because something is creating exposure faster than you are closing it.

Measuring the rate, not just the number

Two scans give you a score. Three give you a gradient, which is the thing worth managing.

Track the delta between consecutive scans rather than the absolute value, and the picture gets much more actionable. A tenant at 68 that was 66 last quarter is improving. A tenant at 74 that was 81 is in trouble, despite the better number. The absolute score tells you where you are; the gradient tells you whether your controls are working.

Watch the per-domain gradients too, because they drift at different speeds. Exposure degrades fastest, since it is driven by everyday behaviour — new sites, new links, new guests. Identity degrades in steps rather than smoothly, usually around joiners and leavers. Compliance barely drifts at all once configured, which is why it is worth getting right early: it is the one domain where the work stays done.

If exposure is sliding and the others are flat, the problem is provisioning, not security. If identity steps down every quarter, the problem is your joiner-mover-leaver process. The gradient points at the owner.

Fixing the source, not the symptom

The useful response to drift is to stop treating it as a remediation backlog and start treating it as a provisioning problem.

  • Change the template, not just the sites. If new sites start permissive, every cleanup is temporary.
  • Put an expiry on guest access rather than relying on anyone remembering to remove it.
  • Make labelling part of how documents are created, not an annual reminder.
  • Give permission exceptions a review date at the moment they are granted.

Each of those converts a recurring cleanup into a one-off change. That is the only way the score stops sliding between scans.

Why this matters more once Copilot is live

Before Copilot, drift was a slow-burning risk that mostly stayed theoretical — the overshared site sat there, and nobody stumbled across it.

Copilot answers questions using the content the asking user can already reach, which Microsoft sets out in its Copilot data privacy documentation. It does not widen permissions. It does make what those permissions allow immediately visible, to anyone, in a sentence. Drift that used to take years to surface now surfaces the first time somebody asks the right question.

Microsoft's own sharing reports will show you the current state. What they will not show you is the trend, which is the thing that tells you whether you are winning.

Keeping a line on the chart

Copilot SafeScan keeps scan history per tenant, so a rescan produces a comparison rather than another snapshot — which checks changed verdict, which findings are new, and whether the score is moving the way you think it is. Read-only, under five minutes, and the first scan is free.

Related: what moving the score is worth, what to fix first, and why governance starts with content hygiene.

Copilot SafeScanCopilot ReadinessCopilot SecurityMicrosoft 365

Want to apply this in your tenant?

Book a free call with a LogiSam consultant — we will show you the quickest, safest way to do it on Microsoft 365.

LogiSam Assistant Guided help & instant answers

Answers come from this website. Privacy policy

↑↓ to navigate ↵ to open