Security posture can change with a single configuration update.
An administrator is added. MFA is disabled. A firewall rule is modified. A security policy changes. Any one of these changes may be legitimate or it may introduce risk that needs immediate attention.
Liongard continuously inspects supported systems and maintains historical configuration data, giving MSPs visibility into what changed across customer environments. By combining Change Detection with Asset Inventory, Actionable Alerts, and Roar Assistant, teams can build a repeatable workflow for identifying, investigating, and responding to security-relevant changes.
This helps MSPs:
Identify unexpected security changes
Investigate changes with before-and-after context
Prioritize changes that require attention
Route high-risk findings to the appropriate team
Maintain evidence for security and compliance reviews
Reduce reliance on manual configuration checks
What security changes should you track?
Start with changes that could materially affect access, exposure, or security posture.
Depending on the systems you manage, this may include:
Identity & access
New privileged accounts
Administrator role changes
MFA configuration changes
Privileged group membership changes
Unexpected account activation or creation
Network & infrastructure
Firewall rule changes
VPN configuration changes
DNS changes
Network configuration changes
Changes that could expose previously restricted services
Security controls
Security policy changes
Endpoint protection configuration changes
Conditional Access changes
Security tooling or monitoring configuration changes
The goal isn't to treat every configuration change as a security incident. Focus on changes that could introduce meaningful risk or warrant validation.
Step 1 — Establish your security baseline
Before you can identify meaningful changes, establish what the expected state looks like.
Use Liongard's continuously collected configuration and asset data to understand:
Who currently has privileged access
Which accounts have MFA enabled
Existing security policies and configurations
Current firewall and network settings
Expected security controls across managed environments
This gives your team a known state against which future changes can be evaluated.
For identity-related reviews, Asset Inventory → Identities & Accounts can provide a centralized view of accounts, privileges, MFA status, and other available identity data.
Step 2 — Review Change Detection
When Liongard detects differences between inspection runs, Change Detection provides the before-and-after context needed to understand what actually changed.
Use Change Detection to determine:
What changed?
What was the previous value?
What is the current value?
When did the change occur?
Is the change expected?
Does it require investigation or remediation?
This helps technicians move beyond simply knowing that something is different and determine whether that difference creates operational or security risk.
Step 3 — Use Roar Assistant to investigate
Roar Assistant can help teams investigate security posture and configuration data conversationally without manually navigating through individual systems.
Questions might include:
Which users currently have privileged access?
Which privileged accounts don't have MFA enabled?
Are there unexpected administrator accounts in this environment?
What security configuration should I review for this customer?
Show me the relevant configuration data for this system.
Use Roar Assistant to accelerate investigation and gather context, then validate findings against the underlying Liongard data when remediation decisions are required.
Step 4 — Operationalize high-risk changes with Actionable Alerts
Not every change needs to become a ticket.
For security conditions that require consistent attention, use Actionable Alerts to turn Liongard data into trackable work.
Depending on your workflow, alerts can be routed to:
Your PSA
Security or SOC queues
Microsoft Teams
Email
Liongard
Examples might include:
MFA disabled
Unexpected privileged access
Security configuration falling outside an approved state
High-risk identity conditions
Start with a small set of high-value alerts and validate them before expanding your security alerting workflow. This helps prevent alert fatigue and keeps technician attention focused on meaningful findings.
Step 5 — Investigate and document the response
When a security-relevant change requires attention:
Review the detected condition or configuration.
Use historical context to understand the previous state.
Determine whether the change was authorized.
Identify the potential security impact.
Remediate the issue when necessary.
Document the investigation and outcome through your established operational workflow.
Liongard's historical visibility helps preserve context that can also be useful during future investigations, security reviews, and audits.
Build a recurring security review process
Change tracking should support both immediate response and recurring security reviews.
Teams can periodically review areas such as:
Privileged access
MFA coverage
Identity and account changes
Firewall and network configurations
Security policy configurations
Recurring Actionable Alerts
Visual Insights can also be used to visualize applicable Liongard data for security reviews, helping teams present the current state of security controls without manually reviewing individual records.
Best practices
Prioritize changes based on security impact rather than total change volume.
Establish an expected state before creating alerting workflows.
Separate routine operational changes from security-sensitive changes.
Validate high-risk changes before assuming they are unauthorized.
Route findings according to operational ownership.
Use Actionable Alerts for conditions that consistently require action.
Review privileged access and MFA separately from standard identity changes.
Preserve historical context for investigations and compliance evidence.
Operational outcomes
A repeatable security change tracking workflow helps MSPs:
Detect security posture changes earlier
Reduce security blind spots
Improve investigation speed
Strengthen privileged access oversight
Standardize security response across customers
Reduce manual configuration reviews
Improve audit and compliance readiness
Maintain stronger evidence around security changes