Loading...

Microsoft Defender for Cloud Apps: Permission changes for select App Governance Entra roles

Microsoft Defender for Cloud Apps: Permission changes for select App Governance Entra roles

Microsoft Defender for Cloud Apps is updating App Governance permissions for select Microsoft Entra roles to align with Defender XDR Unified RBAC. Changes affect Cloud App Security, Compliance Administrator, and Compliance Data Administrator roles starting mid-October 2026. Admins should review and adjust role assignments accordingly. What and Why: We are introducing Microsoft Defender XDR Unified role-based access control (Unified RBAC) support for App Governance. As part of this rollout, App Governance permissions associated with select Microsoft Entra roles will change. This update helps align App Governance access with Defender XDR role management and provides more consistent permission handling for organizations using Microsoft Defender for Cloud Apps. Rollout Schedule: General Availability (Worldwide): We will begin rolling out in mid-October 2026 and expect to complete by late October 2026. Impact on Your Organization: Who is affected: Admins who manage App Governance in Microsoft Defender for Cloud Apps. Users assigned Cloud App Security Administrator, Compliance Administrator, Compliance Data Administrator, or custom Microsoft Defender XDR Unified RBAC roles for Microsoft Defender for Cloud Apps. Platforms/Services: Microsoft Defender XDR. Microsoft Defender for Cloud Apps. App Governance. What will happen: Cloud App Security Administrator: Users with this Microsoft Entra role will gain permission to view and manage App Governance policies. Compliance Administrator: Users with this Microsoft Entra role will no longer be able to manage App Governance policies or enable and disable App Governance in Settings. Compliance Data Administrator: Users with this Microsoft Entra role will no longer be able to enable and disable App Governance in Settings. Custom Defender XDR Unified RBAC roles: Users assigned a custom role in Defender XDR Unified RBAC for Microsoft Defender for Cloud Apps will also get access to App Governance features. Action Required/Recommendations: Before the enforcement date, we recommend that admins: Review users who access App Governance through the Compliance Administrator, Compliance Data Administrator, or Cloud App Security Administrator role. Review custom roles in Microsoft Defender XDR Unified RBAC for Microsoft Defender for Cloud Apps. Assign another supported Microsoft Entra role or a custom Defender XDR Unified RBAC role to affected users, following least-privilege principles. Update internal role assignment […]

The post Microsoft Defender for Cloud Apps: Permission changes for select App Governance Entra roles appeared first on M365 Admin.

Published on:

Learn more
Need help with this product?

We can help you with Microsoft Defender for Cloud Apps: Permission changes for select App Governance Entra roles

If you want help implementing, troubleshooting, or improving this product, contact us and we’ll point you in the right direction.

M365 Admin
M365 Admin

by João Ferreira

Share post:

Related posts

Newsletter

Get the latest Dynamics 365 and Power Platform content in your inbox

A curated digest of community blogs, product news, videos, and podcasts — delivered without the noise.

Weekly updates Unsubscribe anytime Fresh community picks
We use your email only for the newsletter and you can unsubscribe at any time.
By subscribing, you agree to the privacy policy.