Summary
Details
[What and Why:]
We are introducing Microsoft Defender XDR Unified role-based access control (Unified RBAC) support for App Governance. As part of this rollout, App Governance permissions associated with select Microsoft Entra roles will change.
This update helps align App Governance access with Defender XDR role management and provides more consistent permission handling for organizations using Microsoft Defender for Cloud Apps.
[Rollout Schedule:]
General Availability (Worldwide): We will begin rolling out in mid-October 2026 and expect to complete by late October 2026.
[Impact on Your Organization:]
Who is affected:
- Admins who manage App Governance in Microsoft Defender for Cloud Apps.
- Users assigned Cloud App Security Administrator, Compliance Administrator, Compliance Data Administrator, or custom Microsoft Defender XDR Unified RBAC roles for Microsoft Defender for Cloud Apps.
Platforms/Services:
- Microsoft Defender XDR.
- Microsoft Defender for Cloud Apps.
- App Governance.
What will happen:
- Cloud App Security Administrator: Users with this Microsoft Entra role will gain permission to view and manage App Governance policies.
- Compliance Administrator: Users with this Microsoft Entra role will no longer be able to manage App Governance policies or enable and disable App Governance in Settings.
- Compliance Data Administrator: Users with this Microsoft Entra role will no longer be able to enable and disable App Governance in Settings.
- Custom Defender XDR Unified RBAC roles: Users assigned a custom role in Defender XDR Unified RBAC for Microsoft Defender for Cloud Apps will also get access to App Governance features.
[Action Required/Recommendations:]
Before the enforcement date, we recommend that admins:
- Review users who access App Governance through the Compliance Administrator, Compliance Data Administrator, or Cloud App Security Administrator role.
- Review custom roles in Microsoft Defender XDR Unified RBAC for Microsoft Defender for Cloud Apps.
- Assign another supported Microsoft Entra role or a custom Defender XDR Unified RBAC role to affected users, following least-privilege principles.
- Update internal role assignment guidance and administrator documentation as needed.
[Compliance considerations:]
| Does the change include an admin control, and can it be controlled through Entra ID group membership? | This change affects App Governance permissions for selected Microsoft Entra roles and custom Microsoft Defender XDR Unified RBAC roles. Admins should review affected role assignments and update them as needed. |
| Does the change alter how admins can monitor, report on, or demonstrate compliance activities? | The change affects which admin roles can access and manage App Governance policies and settings. |
Change History
Never Miss a Microsoft 365 Update
Join thousands of IT professionals who rely on DeltaPulse for real-time Microsoft 365 change intelligence, automated notifications, and community insights.