Microsoft 365 Message Center item MC1462464
MC1462464 - Microsoft Defender for Cloud Apps: App Governance support for the Cloud Application Administrator role is being retired
Support for the Cloud Application Administrator role in Microsoft Defender for Cloud Apps' App Governance will retire on September 26, 2026. Organizations must reassign affected administrators to supported roles like Security Administrator to maintain access when URBAC is enabled. Review role assignments by September 25, 2026.
- Message Center ID
- MC1462464
- Category
- plan For Change
- Severity
- normal
- Services
- Microsoft Defender XDR
- Tags
- User impact, Admin impact, Retirement
- Published
- 2026-08-26
- Last updated
- 2026-08-26
- Expires
- 2026-11-02
- Action required by
- 2026-09-25
[What and why]Microsoft Defender for Cloud Apps is updating the Microsoft Entra roles that grant access to App Governance when Unified Role-Based Access Control (URBAC) is enabled. As part of this change, support for the Cloud Application Administrator role will be retired for App Governance access.This change aligns App Governance access with the standard supported role set used across Microsoft Defender services and supports future role-based access enhancements.[Rollout schedule]Retirement (Worldwide): Beginning in late September 2026Enforcement date: September 26, 2026[Impact on your organization]Who is affectedOrganizations that use App Governance in Microsoft Defender for Cloud Apps and have administrators who access App Governance using only the Cloud Application Administrator Microsoft Entra rolePlatforms and servicesMicrosoft Defender for Cloud AppsApp GovernanceMicrosoft Entra IDWhat will happenAfter September 26, 2026:Administrators assigned only the Cloud Application Administrator role will no longer be able to access App Governance when URBAC is enabled for Defender for Cloud Apps.Administrators assigned one of the supported roles will continue to have access based on their permissions.No user experience changes are expected.[Action required and recommendations]Review administrator assignments by September 25, 2026.Assign an appropriate supported role to any administrator who requires App Governance access. Supported roles include:Security AdministratorCompliance AdministratorCompliance Data AdministratorSecurity OperatorSecurity ReaderApplication AdministratorGlobal ReaderWe recommend assigning the role with the minimum permissions required for each administrator's responsibilities.[Compliance considerations]QuestionAnswerDoes this change modify administrative access to a Microsoft 365 service?Yes. This change removes App Governance access for administrators who are assigned only the Cloud Application Administrator Microsoft Entra role when URBAC is enabled for Microsoft Defender for Cloud Apps.Does this change require organizations to review or update role assignments?Yes. Organizations should review current administrator role assignments and assign a supported role to administrators who require App Governance access before September 26, 2026.Does this change affect how administrators control or access the service?Yes. Access to App Governance will be governed by a revised set of supported Microsoft Entra roles, changing how some administrators obtain access to the service.Does this change involve an administrative control or permissions change?Yes. The change retires support for one administrative role and requires use of one of the supported roles to maintain App Governance access.