Microsoft Defender for Cloud Apps: App Governance support for the Cloud Application Administrator role is being retired
🚨 The Signal: Microsoft Defender for Cloud Apps will remove Cloud Application Administrator role access to App Governance from September 2026. This change aligns App Governance access with standard Defender roles, requiring review and re-assignment of permissions for affected administrators.
The Impact
Security administrators using the Cloud Application Administrator role for App Governance will lose access, posing a risk of operational disruption if roles are not updated.
- Security administrators: Loss of access to App Governance if roles are not updated.
- Security operations: Potential disruption to App Governance monitoring and policy management.
- Compliance teams: Need to verify updated role assignments for audit purposes.
The Action
- Review current administrator assignments for App Governance in Microsoft Defender for Cloud Apps.
- Identify administrators who rely solely on the Cloud Application Administrator role for App Governance access.
- Assign an appropriate supported role (e.g., Security Administrator) to these administrators.
- Verify continued access for reassigned administrators before September 26, 2026.
Domain: Defender · Impact: medium · Workload: Microsoft Defender · Essential Eight: Restrict Administrative Privileges · ISM: ISM-0445, ISM-1175, ISM-1380, ISM-1507, ISM-1508, ISM-1509, ISM-1647, ISM-1648, ISM-1650, ISM-1686, ISM-1688, ISM-1689, ISM-1883, ISM-1897, ISM-1898