MC1462464: Microsoft Defender for Cloud Apps Retires App Governance Access for Cloud Application Administrator Role

MWPRO IMPACT SCORE
OPERATIONAL IMPACT
60
0 25 50 75 100
HIGH IMPACT • REVIEW RECOMMENDED
Recommended Action:
Review the update and plan any required actions before rollout.
What is MWPro Impact Score? Watch our 60‑second explainer

Primary Audience

Tenant AdminsMicrosoft 365 AdminsSecurity TeamsCompliance TeamsIT ManagersService Owners
Why this score?
AI Confidence
HIGH
Enough detail is available to trust this assessment.
Assessment Reasoning
This update removes App Governance access for the Cloud Application Administrator role as of 26 September 2026, requiring admins to reassign supported roles. No user-facing changes are noted, but the retirement impacts administrative permissions and governance, posing access risks if not addressed. Admins must review role assignments and implement updates before the enforcement date, making planning and configuration necessary.
78
🛡️ Admin Impact
5
👥 User Impact
70
Urgency
65
🔧 Effort
ℹ️ WHAT YOU NEED TO KNOW
📌

AT A GLANCE

Support for the Cloud Application Administrator role in App Governance is being retired. Access will require a different supported Entra role from late September 2026.
👥

END USERS

No major end-user change expected.
🛡️

IT ADMINS

Review current admin roles and reassign supported roles for App Governance access before enforcement.
📅

ROLLOUT TIMELINE

Upcoming:
Late September 2026

📢 Official Microsoft Message Center Announcement


Microsoft Defender for Cloud Apps: App Governance support for the Cloud Application Administrator role is being retired
Message ID: MC1462464

[What and why]

Microsoft Defender for Cloud Apps is updating the Microsoft Entra roles that grant access to App Governance when Unified Role-Based Access Control (URBAC) is enabled. As part of this change, support for the Cloud Application Administrator role will be retired for App Governance access.

This change aligns App Governance access with the standard supported role set used across Microsoft Defender services and supports future role-based access enhancements.

[Rollout schedule]

  • Retirement (Worldwide): Beginning in late September 2026
  • Enforcement date: September 26, 2026

[Impact on your organization]

Who is affected

  • Organizations that use App Governance in Microsoft Defender for Cloud Apps and have administrators who access App Governance using only the Cloud Application Administrator Microsoft Entra role

Platforms and services

  • Microsoft Defender for Cloud Apps
  • App Governance
  • Microsoft Entra ID

What will happen

After September 26, 2026:

  • Administrators assigned only the Cloud Application Administrator role will no longer be able to access App Governance when URBAC is enabled for Defender for Cloud Apps.
  • Administrators assigned one of the supported roles will continue to have access based on their permissions.
  • No user experience changes are expected.

[Action required and recommendations]

Review administrator assignments by September 25, 2026.

Assign an appropriate supported role to any administrator who requires App Governance access. Supported roles include:

  • Security Administrator
  • Compliance Administrator
  • Compliance Data Administrator
  • Security Operator
  • Security Reader
  • Application Administrator
  • Global Reader

We recommend assigning the role with the minimum permissions required for each administrator’s responsibilities.

[Compliance considerations]

QuestionAnswer
Does this change modify administrative access to a Microsoft 365 service?Yes. This change removes App Governance access for administrators who are assigned only the Cloud Application Administrator Microsoft Entra role when URBAC is enabled for Microsoft Defender for Cloud Apps.
Does this change require organizations to review or update role assignments?Yes. Organizations should review current administrator role assignments and assign a supported role to administrators who require App Governance access before September 26, 2026.
Does this change affect how administrators control or access the service?Yes. Access to App Governance will be governed by a revised set of supported Microsoft Entra roles, changing how some administrators obtain access to the service.
Does this change involve an administrative control or permissions change?Yes. The change retires support for one administrative role and requires use of one of the supported roles to maintain App Governance access.

Source: Microsoft Message Center • Analysed by MWPro

Share This Update