MC1479503 - Microsoft Defender for Cloud Apps: Permission changes for select App Governance Entra roles
Microsoft 365 Message Center announcement MC1479503.
MS Message Center's Summary
Microsoft is updating App Governance permissions for select Microsoft Entra roles to align with Defender XDR Unified role based access control between mid October and late October 2026. Compliance roles will lose certain management capabilities, while Cloud App Security administrators will gain policy management rights. Administrators must review current role assignments and reassign permissions to affected personnel to maintain proper operational access.
- Administrator impact
- Administrators must review and update Microsoft Entra role assignments and custom Defender XDR roles before the rollout completes.
- End user impact
- Selected administrators may experience changes in their ability to manage App Governance policies and settings.
- Importance
- 5/10: This change modifies administrative permissions and requires proactive review of role assignments to prevent access disruptions.
Microsoft Summary
Microsoft Defender for Cloud Apps is updating App Governance permissions for select Microsoft Entra roles to align with Defender XDR Unified RBAC. Changes affect Cloud App Security, Compliance Administrator, and Compliance Data Administrator roles starting mid-October 2026. Admins should review and adjust role assignments accordingly.
- Message Center ID
- MC1479503
- Category
- plan For Change
- Severity
- normal
- Services
- Microsoft Defender XDR
- Tags
- Feature update, Admin impact
- Published
- 2026-09-25
- Last updated
- 2026-09-25
- Expires
- 2026-12-30
[What and Why:] We are introducing Microsoft Defender XDR Unified role-based access control (Unified RBAC) support for App Governance. As part of this rollout, App Governance permissions associated with select Microsoft Entra roles will change. This update helps align App Governance access with Defender XDR role management and provides more consistent permission handling for organizations using Microsoft Defender for Cloud Apps. [Rollout Schedule:] General Availability (Worldwide): We will begin rolling out in mid-October 2026 and expect to complete by late October 2026. [Impact on Your Organization:] Who is affected: Admins who manage App Governance in Microsoft Defender for Cloud Apps. Users assigned Cloud App Security Administrator, Compliance Administrator, Compliance Data Administrator, or custom Microsoft Defender XDR Unified RBAC roles for Microsoft Defender for Cloud Apps. Platforms/Services: Microsoft Defender XDR. Microsoft Defender for Cloud Apps. App Governance. What will happen: Cloud App Security Administrator: Users with this Microsoft Entra role will gain permission to view and manage App Governance policies. Compliance Administrator: Users with this Microsoft Entra role will no longer be able to manage App Governance policies or enable and disable App Governance in Settings. Compliance Data Administrator: Users with this Microsoft Entra role will no longer be able to enable and disable App Governance in Settings. Custom Defender XDR Unified RBAC roles: Users assigned a custom role in Defender XDR Unified RBAC for Microsoft Defender for Cloud Apps will also get access to App Governance features. [Action Required/Recommendations:] Before the enforcement date, we recommend that admins: Review users who access App Governance through the Compliance Administrator, Compliance Data Administrator, or Cloud App Security Administrator role. Review custom roles in Microsoft Defender XDR Unified RBAC for Microsoft Defender for Cloud Apps. Assign another supported Microsoft Entra role or a custom Defender XDR Unified RBAC role to affected users, following least-privilege principles. Update internal role assignment guidance and administrator documentation as needed. [Compliance considerations:] Does the change include an admin control, and can it be controlled through Entra ID group membership? This change affects App Governance permissions for selected Microsoft Entra roles and custom Microsoft Defender XDR Unified RBAC roles. Admins should review affected role assignments and update them as needed. Does the change alter how admins can monitor, report on, or demonstrate compliance activities? The change affects which admin roles can access and manage App Governance policies and settings.