From Configuration Drift to DevOps Mastery: Managing Azure and Microsoft 365 with DSC
PowerShell Conference EU 2025 hosted a session by Gael Colas and Raimund Andree focused on one recurring enterprise problem: cloud configuration drift in Microsoft 365 and Azure.

If your teams configure tenants mainly through portals, you’ll likely recognise the symptoms:
- Configuration drift over time
- Poor or outdated documentation
- No reliable traceability of changes
- Limited scalability across environments
Watch the session
Watch “Configuring Azure Entra ID and M365 with DSC” on YouTube
The proposed operating model
The session demonstrates how to manage tenant configuration as code with:
Microsoft365DSCexports and authoring- Version control for reviewable change history
- Multi-environment promotion from Dev to Test to Prod
- Pipeline automation for validation and deployment
Pipeline ingredients highlighted in the talk
The walkthrough highlighted a practical stack:
- Azure DevOps pipelines
- YAML-driven configuration
- PSScriptAnalyzer and Pester checks
- Idempotent configuration execution
Why this matters operationally
Treating configuration as code improves reliability and maintainability:
- Teams can review and approve changes through pull requests
- Compliance evidence becomes easier to produce
- Repeatable rollouts scale better from a few tenants to many
Community and real-world application
The approach is grounded in community tooling and practice, including:
The session also showed practical scenarios around group/application management, YAML modeling, and compliance workflows enforced through pull requests and release pipelines.
Going further
If you want to adopt this pattern, start with one scoped configuration domain, export and baseline it, then build an iterative promotion pipeline before expanding coverage.