Identity drift happens when password resets in AD or Entra ID don’t instantly update everywhere. Cached credentials and sync delays can leave old passwords active, creating a short but dangerous window attackers can exploit. Updating cached credentials and enforcing MFA helps close the gap and reduce the risk of compromised identities