Microsoft Defender for Cloud Apps: App Governance support for the Cloud Application Administrator role is being retired
In brief
Support for the Cloud Application Administrator role in Microsoft Defender for Cloud Apps' App Governance will retire on September 26, 2026. Organizations must reassign affected administrators to supported roles like Security Administrator to maintain access when URBAC is enabled. Review role assignments by September 25, 2026.
Message Center announcement
What and why
Microsoft Defender for Cloud Apps is updating the Microsoft Entra roles that grant access to App Governance when Unified Role-Based Access Control (URBAC) is enabled. As part of this change, support for the Cloud Application Administrator role will be retired for App Governance access.
This change aligns App Governance access with the standard supported role set used across Microsoft Defender services and supports future role-based access enhancements.
Rollout schedule
- Retirement (Worldwide): Beginning in late September 2026
- Enforcement date: September 26, 2026
Impact on your organization
Who is affected
- Organizations that use App Governance in Microsoft Defender for Cloud Apps and have administrators who access App Governance using only the Cloud Application Administrator Microsoft Entra role
Platforms and services
- Microsoft Defender for Cloud Apps
- App Governance
- Microsoft Entra ID
What will happen
After September 26, 2026:
- Administrators assigned only the Cloud Application Administrator role will no longer be able to access App Governance when URBAC is enabled for Defender for Cloud Apps.
- Administrators assigned one of the supported roles will continue to have access based on their permissions.
- No user experience changes are expected.
Action required and recommendations
Review administrator assignments by September 25, 2026.
Assign an appropriate supported role to any administrator who requires App Governance access. Supported roles include:
- Security Administrator
- Compliance Administrator
- Compliance Data Administrator
- Security Operator
- Security Reader
- Application Administrator
- Global Reader
We recommend assigning the role with the minimum permissions required for each administrator's responsibilities.
Compliance considerations
| Question | Answer |
| Does this change modify administrative access to a Microsoft 365 service? | Yes. This change removes App Governance access for administrators who are assigned only the Cloud Application Administrator Microsoft Entra role when URBAC is enabled for Microsoft Defender for Cloud Apps. |
| Does this change require organizations to review or update role assignments? | Yes. Organizations should review current administrator role assignments and assign a supported role to administrators who require App Governance access before September 26, 2026. |
| Does this change affect how administrators control or access the service? | Yes. Access to App Governance will be governed by a revised set of supported Microsoft Entra roles, changing how some administrators obtain access to the service. |
| Does this change involve an administrative control or permissions change? | Yes. The change retires support for one administrative role and requires use of one of the supported roles to maintain App Governance access. |
