This demo of a config remediation prototype shows how you can peg a configuration (or "freeze it") so if a resource detects a config change, it'll immediately go back to the frozen config - but it will log the config change in the audit trail. This is otherwise known as "configuration remediation".
(Download)