๐Ÿ“‹ GRC compliance for CMMC 2.0, CPCSC, CPA Canada, IIROCโ€ฆSaaS discovery for data governanceFree enriched web chat widget๐Ÿš€ Enriched remote support without your laptop

Configuration Changes

See every change detected in your Microsoft 365 configuration, who made it and exactly what changed.

Where to find it
Opened from Microsoft 365 โ€บ Microsoft 365 (configuration change section)
Who can use it
Anyone who can see the page; creating a rollback plan needs an administrator role
Plan
Microsoft 365 configuration change monitoring (rollback needs the Microsoft 365 backup and rollback add-on)
For
Everyone

What the page is for

Changes to Microsoft 365 settings, such as conditional access policies, can weaken your security without anyone noticing. Lavawall takes regular snapshots of your tenant's configuration and records every difference it finds. This page lists those changes so you can see what changed, when, by whom, and how serious it is.

Each change shows the type of object, its name, whether it was added, modified or deleted, a severity, and who made the change. Open a change to see the before and after values of each field. If you have the rollback add-on, you can plan a rollback of that single change from the same window.

MSPs can view one company, or all monitored companies at once by choosing all companies in the header.

What you see

The Configuration Changes page, with the filters, changes table, pager and change details numbered 1 to 4.
The Configuration Changes page. Numbers match the list below.
  1. Filters: Object Type, Severity (min), Change Type, User UPN, Last (days) and a search button.
  2. Changes table: Detected, Company (all-companies view only), Object Type, Object, Change (with how many fields changed), Severity, By, Status (notified or rolled back) and Details.
  3. Pager: the number of changes and โ€น Prev / Next โ€บ.
  4. Change Details: the object, change type, severity, detected time, who changed it and from where, the fields changed, and a line-by-line list of old and new values. Includes Plan Rollback of This Change or View Rollback.

How to find a change

  1. Choose an Object Type, or leave All types.
  2. Set Severity (min). The default is medium, which hides info and low changes.
  3. Choose a Change Type (added, modified or deleted) if needed.
  4. To see one person's changes, type their address in User UPN, for example jane@example.com.
  5. Choose how far back to look in Last (days): 1 day, 7 days, 30 days, 90 days or 1 year.
  6. Click the search button.

How to see exactly what changed

  1. Click Details on the row.
  2. Review Changed By, including the IP address and country if recorded.
  3. Read the list of operations. Removed values are marked with a minus sign and new values with a plus sign.

How to roll back one change

  1. Open the change with Details.
  2. Click Plan Rollback of This Change.
  3. Click Create plan. Nothing changes in your tenant yet.
  4. You are taken to Rollbacks, where the plan must be approved before it runs.

Tips

  • Set Severity (min) to Any to see every change, including minor ones.
  • A notified status means an alert was sent for the change. rolled back means it has already been reversed.
  • Hover over the Detected age (for example "3h ago") to see the exact time.
  • Use Back to M365 dashboard and Rollbacks at the bottom of the page to move between related pages.

Troubleshooting

  • "Configuration change monitoring is not enabled for this company." Turn on the add-on with Manage subscription.
  • "No changes match these filters." Lower Severity (min) or widen Last (days).
  • There is no Plan Rollback button. The rollback add-on is not enabled for the company, or the change has already been rolled back.

Task guides that use this page

Still need help?

Search the support centre, or contact our support team and tell us which page you were on.

Names, companies, devices and figures in the pictures are examples. Other product and company names are trademarks of their respective owners.