How a State Government Agency Closed Microsoft 365 Security Gaps Across Eight Tenants with CoreView

How a State Government Agency Closed Microsoft 365 Security Gaps Across Eight Tenants with CoreView
SUMMARY
  • A U.S. state government agency needed to manage Microsoft 365 security and compliance across eight separate tenants covering more than 68,000 users.
  • Manual configuration across multiple admin portals created operational drag and increased the risk of inconsistent security controls.
  • CIS Benchmark alignment had to be checked tenant by tenant, leaving configuration drift difficult to detect until a manual review or audit.
  • CoreView Configuration Manager now helps the agency push configuration changes across all eight tenants, assess posture against CIS Benchmarks, and detect deviations from required baselines.
  • The agency is also using CoreView for Entra App management and User Templates, with Access Review and Configuration History planned as part of its next phase.
Download case study

Background: A State Government Agency Managing Microsoft 365 Across Eight Tenants

This U.S. state government agency runs Microsoft 365 across eight separate tenants covering more than 68,000 users. Like many large public-sector organizations, its Microsoft 365 environment reflects how government IT often evolves over time, with different departments and functions accumulating their own environments.

Challenge: Fragmented Tenants Created More Room for Drift

That structure had created a complex operating model for the IT team. Security, compliance, and configuration management had to be applied consistently across multiple Microsoft 365 tenants, each with its own admin portal and configuration state.

Every configuration change had to be executed separately, with operators logging in and repeating the same steps manually across each environment. Not only was this slow, but each repetition created another opportunity for human error. In Microsoft 365, a missed configuration can become a gap in access control, security baseline alignment, or compliance posture.

The agency also operates under CIS Benchmark requirements. For a government organization handling public data, falling out of alignment is a compliance issue, not just an operational inconvenience. But the only way the team could verify alignment was to check each tenant by hand.

With no automated monitoring in place, configuration drift could go undetected until someone noticed it manually or an audit flagged it. The risk was structural, and the workload made it worse.

Manual Checks Were Not a Repeatable Security Control

The agency’s IT team understood the CIS Benchmark requirements and was implementing the right security controls. The problem was the way those controls had to be applied and verified. Manual implementation at scale is not a repeatable, auditable control. It depends on every operator applying every change correctly, every time, across every tenant.

When a new security control needed to be deployed, an operator had to apply it across each environment in sequence. If any step was missed or applied inconsistently, there was no system in place to detect it automatically. Again, that gap could then remain unnoticed until the next manual review.

This model did not scale with the standards government IT environments are expected to meet. As CIS Benchmarks changed and Microsoft 365 configurations evolved, the manual surface area continued to grow. The agency needed a way to enforce configuration consistency as a system, rather than manage it as a checklist.

Quote top graphic

Solution: Configuration Enforcement Across All Eight Microsoft 365 Tenants

The agency deployed CoreView Configuration Manager to push changes across all eight tenants from a single operation. A configuration that previously required repeated manual execution can now be deployed once, reducing one of the main ways configuration drift was entering the environment.

The team was also able to assess each tenant’s current posture against CIS Benchmarks and receive alerts when any tenant deviated from the required baseline. This gave the agency clearer visibility into where its environment stood and allowed the team to act before a gap became an audit finding or incident.

The agency also added two further capabilities:

  • Entra App management: The agency now uses CoreView to track API key secret expiration dates in Entra applications and govern renewals before expired secrets cause application outages.
  • User Templates: The team has implemented User Templates to standardize how new user objects are configured at the point of cre

Result: Security Posture That Is Enforced, Not Assumed

The agency’s Microsoft 365 environment has moved toward a model where configuration consistency is enforced rather than assumed.

The core benefits the agency has seen are:

  • Configuration changes across eight tenants from one operation: CoreView Configuration Manager reduces the need for operators to repeat the same configuration work manually in each tenant.
  • Reduced configuration drift risk: Applying changes consistently across tenants removes a major source of manual inconsistency.
  • CIS Benchmark monitoring: The team can assess tenant posture against CIS Benchmarks and detect deviations from required baselines.
  • Earlier detection of compliance gaps: Drift can surface through alerts rather than waiting for a manual review or audit.
  • Better Entra App continuity: Tracking API key secret expiration dates helps the agency manage renewals before expired secrets disrupt applications.
  • More consistent user creation: User Templates help standardize new user configuration and reduce privilege inconsistencies from the start.

Ultimately, this means the agency can manage its Microsoft 365 tenants as a governed whole, rather than as separate environments each carrying its own drift risk.

Why CoreView

CoreView gave the agency a way to move from manual tenant-by-tenant configuration toward centralized Microsoft 365 configuration governance.

With CoreView Configuration Manager, the team can push changes across all eight tenants, assess posture against CIS Benchmarks, and receive alerts when tenants drift from the required baseline. CoreView also supports the agency’s broader governance work through Entra App management, User Templates, and planned Access Review and Configuration History capabilities.

For a state government agency managing public-sector risk across more than 68,000 users, that shift matters. Microsoft 365 security posture becomes easier to enforce, easier to monitor, and easier to demonstrate.

Next Step: Building a Stronger Audit Trail

The agency’s planned use of Access Review and Configuration History points to the next stage of its Microsoft 365 governance maturity: building a documented, auditable record of what changed, when, and by whom, across all tenants. For a government organization, that audit trail is the foundation of demonstrable compliance.  

The agency has moved from a model where security posture depended on operators not making mistakes to one where the environment can help enforce the standard itself.

Get a personalized demo today

Created by M365 experts, for M365 experts.