MC1462464 - Microsoft Defender for Cloud Apps: App Governance support for the Cloud Application Administrator role is being retired

Message Center

Summary

Support for the Cloud Application Administrator role in Microsoft Defender for Cloud Apps' App Governance will retire on September 26, 2026. Organizations must reassign affected administrators to supported roles like Security Administrator to maintain access when URBAC is enabled. Review role assignments by September 25, 2026.

Published

Aug 26, 2026

Service

Microsoft Defender XDR

Tag

Major change
User impact
Admin impact
Retirement

Act by

Sep 25, 2026

More information

What and why

Microsoft Defender for Cloud Apps is updating the Microsoft Entra roles that grant access to App Governance when Unified Role-Based Access Control (URBAC) is enabled. As part of this change, support for the Cloud Application Administrator role will be retired for App Governance access.

This change aligns App Governance access with the standard supported role set used across Microsoft Defender services and supports future role-based access enhancements.

Rollout schedule

  • Retirement (Worldwide): Beginning in late September 2026
  • Enforcement date: September 26, 2026

Impact on your organization

Who is affected

  • Organizations that use App Governance in Microsoft Defender for Cloud Apps and have administrators who access App Governance using only the Cloud Application Administrator Microsoft Entra role

Platforms and services

  • Microsoft Defender for Cloud Apps
  • App Governance
  • Microsoft Entra ID

What will happen

After September 26, 2026:

  • Administrators assigned only the Cloud Application Administrator role will no longer be able to access App Governance when URBAC is enabled for Defender for Cloud Apps.
  • Administrators assigned one of the supported roles will continue to have access based on their permissions.
  • No user experience changes are expected.

Action required and recommendations

Review administrator assignments by September 25, 2026.

Assign an appropriate supported role to any administrator who requires App Governance access. Supported roles include:

  • Security Administrator
  • Compliance Administrator
  • Compliance Data Administrator
  • Security Operator
  • Security Reader
  • Application Administrator
  • Global Reader

We recommend assigning the role with the minimum permissions required for each administrator's responsibilities.

Compliance considerations

QuestionAnswer
Does this change modify administrative access to a Microsoft 365 service?Yes. This change removes App Governance access for administrators who are assigned only the Cloud Application Administrator Microsoft Entra role when URBAC is enabled for Microsoft Defender for Cloud Apps.
Does this change require organizations to review or update role assignments?Yes. Organizations should review current administrator role assignments and assign a supported role to administrators who require App Governance access before September 26, 2026.
Does this change affect how administrators control or access the service?Yes. Access to App Governance will be governed by a revised set of supported Microsoft Entra roles, changing how some administrators obtain access to the service.
Does this change involve an administrative control or permissions change?Yes. The change retires support for one administrative role and requires use of one of the supported roles to maintain App Governance access.