You can patch every endpoint on the largest Patch Tuesday in history and still leave the fleet exposed — because endpoint configuration drift is the half of exposure a patch never touches. July 2026 brought that record: Microsoft shipped fixes for a record 570 CVEs, driven by a new AI vulnerability-discovery system. But the sharper lesson wasn’t the volume. It was how the exploited flaws were handled: not with a patch alone.
When attackers began exploiting a SharePoint zero-day, CISA didn’t just tell teams to patch — it urged them to harden: enable additional request scanning, block external access to admin interfaces, rotate keys, and hunt for signs of intrusion, warning that a patch alone may not evict an attacker who is already inside. That advice was for on-premises servers, but the principle is universal. Exposure is patches plus configuration. And across the endpoint fleet, the configuration side is what most teams can’t see.
Why Patching Only Closes Half the Exposure
Patching answers one question: which known flaws are unremediated? It’s essential — and at that volume, deciding which to fix first is a discipline of its own. But even a perfectly patched, perfectly prioritized fleet can sit in an insecure state.
Configuration drift is the gradual movement of devices away from a secure baseline, even when they are fully patched. A firewall switched off during troubleshooting and never re-enabled. Disk encryption disabled on a reimaged laptop. A Windows Update service paused “temporarily.” A local policy exception that outlived its reason. None of these is a missing patch, so patch reports show green while the device quietly stays part of your attack surface. Drift builds one small change at a time, and it stays exploitable long after the last update installed.
Making Endpoint Configuration Drift Visible
CapaOne Security Monitor surfaces the configuration side from one console. Alongside CVE exposure, it shows the signals that reveal drift — firewall state, encryption status, Windows Update posture — across every endpoint, so IT can see where devices have wandered from a secure baseline instead of assuming a green patch report means a hardened fleet. Security Monitor is a visibility and evidence layer, not a SIEM or an EDR — it doesn’t chase threats; it shows you where you’re exposed and lets you prove it.
That evidence matters beyond operations. Modern frameworks increasingly expect organizations to show that controls stay effective over time — not merely that patches are installed. When an auditor or a cyber-insurer asks you to demonstrate hardening rather than assert it, Security Monitor exports audit-ready evidence on demand — what drifted, where, and when — in a GDPR-first, NIS2-aligned posture.
One View of the Fleet, With or Without Intune
Security Monitor covers the whole fleet on its own, in one console with no dependency on Intune. If you already patch through Intune or Windows Autopatch, CapaOne adds what they don’t cover: fleet-wide configuration and drift visibility, with or without Intune, targeting your existing Entra ID groups. The patch pipeline stays where it is; the configuration side becomes something you can finally see.
Exposure Is Bigger Than Your Patch Queue
AI-driven discovery means patch volumes will keep climbing — a month like July’s is a floor, not a ceiling. The teams that stay ahead won’t be the ones who patch fastest. They’ll be the ones who can also see where configuration has drifted, and prove they’ve closed it. Patching will always be half the job. The other half is visibility.
Book a demo of the CapaOne platform — or start a free trial and see where your own fleet has drifted from a secure baseline, not just which patches it’s missing.