Skip to main content

Build a Security Change Tracking Workflow

Security posture can change with a single configuration update.

An administrator is added. MFA is disabled. A firewall rule is modified. A security policy changes. Any one of these changes may be legitimate or it may introduce risk that needs immediate attention.

Liongard continuously inspects supported systems and maintains historical configuration data, giving MSPs visibility into what changed across customer environments. By combining Change Detection with Asset Inventory, Actionable Alerts, and Roar Assistant, teams can build a repeatable workflow for identifying, investigating, and responding to security-relevant changes.

This helps MSPs:

  • Identify unexpected security changes

  • Investigate changes with before-and-after context

  • Prioritize changes that require attention

  • Route high-risk findings to the appropriate team

  • Maintain evidence for security and compliance reviews

  • Reduce reliance on manual configuration checks

What security changes should you track?

Start with changes that could materially affect access, exposure, or security posture.

Depending on the systems you manage, this may include:

Identity & access

  • New privileged accounts

  • Administrator role changes

  • MFA configuration changes

  • Privileged group membership changes

  • Unexpected account activation or creation

Network & infrastructure

  • Firewall rule changes

  • VPN configuration changes

  • DNS changes

  • Network configuration changes

  • Changes that could expose previously restricted services

Security controls

  • Security policy changes

  • Endpoint protection configuration changes

  • Conditional Access changes

  • Security tooling or monitoring configuration changes

The goal isn't to treat every configuration change as a security incident. Focus on changes that could introduce meaningful risk or warrant validation.

Step 1 — Establish your security baseline

Before you can identify meaningful changes, establish what the expected state looks like.

Use Liongard's continuously collected configuration and asset data to understand:

  • Who currently has privileged access

  • Which accounts have MFA enabled

  • Existing security policies and configurations

  • Current firewall and network settings

  • Expected security controls across managed environments

This gives your team a known state against which future changes can be evaluated.

For identity-related reviews, Asset Inventory → Identities & Accounts can provide a centralized view of accounts, privileges, MFA status, and other available identity data.

Step 2 — Review Change Detection

When Liongard detects differences between inspection runs, Change Detection provides the before-and-after context needed to understand what actually changed.

Use Change Detection to determine:

  • What changed?

  • What was the previous value?

  • What is the current value?

  • When did the change occur?

  • Is the change expected?

  • Does it require investigation or remediation?

This helps technicians move beyond simply knowing that something is different and determine whether that difference creates operational or security risk.

Step 3 — Use Roar Assistant to investigate

Roar Assistant can help teams investigate security posture and configuration data conversationally without manually navigating through individual systems.

Questions might include:

  • Which users currently have privileged access?

  • Which privileged accounts don't have MFA enabled?

  • Are there unexpected administrator accounts in this environment?

  • What security configuration should I review for this customer?

  • Show me the relevant configuration data for this system.

Use Roar Assistant to accelerate investigation and gather context, then validate findings against the underlying Liongard data when remediation decisions are required.

Step 4 — Operationalize high-risk changes with Actionable Alerts

Not every change needs to become a ticket.

For security conditions that require consistent attention, use Actionable Alerts to turn Liongard data into trackable work.

Depending on your workflow, alerts can be routed to:

  • Your PSA

  • Security or SOC queues

  • Microsoft Teams

  • Email

  • Liongard

Examples might include:

  • MFA disabled

  • Unexpected privileged access

  • Security configuration falling outside an approved state

  • High-risk identity conditions

Start with a small set of high-value alerts and validate them before expanding your security alerting workflow. This helps prevent alert fatigue and keeps technician attention focused on meaningful findings.

Step 5 — Investigate and document the response

When a security-relevant change requires attention:

  1. Review the detected condition or configuration.

  2. Use historical context to understand the previous state.

  3. Determine whether the change was authorized.

  4. Identify the potential security impact.

  5. Remediate the issue when necessary.

  6. Document the investigation and outcome through your established operational workflow.

Liongard's historical visibility helps preserve context that can also be useful during future investigations, security reviews, and audits.

Build a recurring security review process

Change tracking should support both immediate response and recurring security reviews.

Teams can periodically review areas such as:

  • Privileged access

  • MFA coverage

  • Identity and account changes

  • Firewall and network configurations

  • Security policy configurations

  • Recurring Actionable Alerts

Visual Insights can also be used to visualize applicable Liongard data for security reviews, helping teams present the current state of security controls without manually reviewing individual records.

Best practices

  • Prioritize changes based on security impact rather than total change volume.

  • Establish an expected state before creating alerting workflows.

  • Separate routine operational changes from security-sensitive changes.

  • Validate high-risk changes before assuming they are unauthorized.

  • Route findings according to operational ownership.

  • Use Actionable Alerts for conditions that consistently require action.

  • Review privileged access and MFA separately from standard identity changes.

  • Preserve historical context for investigations and compliance evidence.

Operational outcomes

A repeatable security change tracking workflow helps MSPs:

  • Detect security posture changes earlier

  • Reduce security blind spots

  • Improve investigation speed

  • Strengthen privileged access oversight

  • Standardize security response across customers

  • Reduce manual configuration reviews

  • Improve audit and compliance readiness

  • Maintain stronger evidence around security changes

Did this answer your question?