When should you run a configuration audit?

After an incident, before a critical go-live, to validate CIS or ANSSI hardening, or at the request of a cyber insurer or large-account client. The audit measures the gap between a security baseline and the real state of your systems (Active Directory, servers, network equipment, applications).