No one decides to turn security off. A template gets refactored, a pipeline is cloned from an old branch, a task version is pinned and abandoned, a variable is renamed — and a build that scanned last month silently stops scanning this month.

Drift is the gap between the security configuration you intend and the configuration that actually runs. In most organizations that gap is invisible, because the intended state was never written down anywhere a machine could check.

Where drift comes from

  • Pipeline YAML edits and template refactors that drop or reorder injected steps.
  • Cloned and migrated pipelines that never inherited security configuration.
  • Variable and variable-group changes that break task parameters.
  • Service connection changes that sever the scanner's authorization.
  • Well-intentioned local 'temporary' disables that outlive the incident that justified them.

Why nobody notices

A pipeline that stops scanning does not fail — it goes green faster. Every incentive in the delivery loop rewards the drifted state. Unless a system compares intended coverage against observed configuration, the first person to notice is usually an auditor or an attacker.

Closing the loop: detect, decide, repair

The fix is a reconciliation loop, the same pattern that made infrastructure-as-code trustworthy: hold desired state centrally, observe actual state continuously, diff them, and repair through a controlled action.

Kangl runs exactly this loop for pipeline security configuration in Azure DevOps: intended enrollment and Security Runtime state live in the control plane, synchronization jobs observe reality, divergence is surfaced as drift, and Force Sync restores the intended state — with the entire cycle recorded in the audit history.

KEEP READING