News

Microsoft to Strip App Governance Access from the Admin Role

4 min read Editorial

Microsoft is set to strip App Governance access from the admin role, and the company is urging administrators to audit their tenant permissions ahead of a deadline to avoid losing access to Microsoft Defender for Cloud Apps.

If your organization depends on App Governance — the SaaS governance module embedded in Defender for Cloud Apps — you’ll need to review which accounts hold elevated permissions and transition affected personnel to an alternative role, such as Security Administrator, before the change takes effect.

Here’s what’s changing, why it matters, and what you should do to stay ahead of the deadline.

Advertisement

What App Governance does

App Governance is a capability built into Microsoft Defender for Cloud Apps (MCAS) that gives organizations visibility and control over their SaaS applications. Rather than focusing on the traditional cloud and on-premises infrastructure, it targets the growing sprawl of third-party cloud services — tools like Salesforce, Workday, Slack, and hundreds of others that employees use with corporate credentials.

The module surfaces risky behavior across these apps, tracks data exposure, and lets security teams enforce policies around app usage. For many security operations centers, it has become a core part of the broader Cloud Access Security Broker (CASB) story that Microsoft has been building around Defender for Cloud Apps.

How App Governance access is changing

According to Neowin’s reporting, Microsoft is removing App Governance access from the admin role. In practice, that means an account that currently holds the admin role — and therefore inherited App Governance permissions — will no longer automatically have access to the module once the change ships.

The company is asking admins to audit their tenant permissions ahead of the deadline so they can proactively reassign access. Personnel who need to continue managing App Governance should be moved to an alternative role, with Microsoft pointing to Security Administrator as one such option.

An IT administrator at a desk reviewing role assignments in a tenant management console, multiple monitors showing secur
Admins should audit which accounts inherit App Governance permissions before the change takes effect.

Why Microsoft is pushing this change

This move fits squarely into a broader push across the Windows and Microsoft 365 ecosystem toward least-privilege access. Over recent years, Microsoft has repeatedly warned that over-broad admin roles — particularly the Global Administrator — are the single biggest risk in a compromised tenant, since they can be leveraged to unlock nearly everything else.

By decoupling App Governance from the general admin role and steering access toward narrower, purpose-built roles like Security Administrator, Microsoft is reinforcing the idea that administrators should hold only the permissions their jobs actually require. The trend mirrors similar hardening steps the company has taken around Entra ID (formerly Azure Active Directory) roles and conditional access.

It’s worth noting that this is a permission-model change rather than a change to how App Governance itself works — the module’s features and policies remain intact; only who can reach them is shifting.

What you should do before the deadline

Because the change means access can be revoked automatically, the safest path is to get ahead of it. Start by auditing your tenant to identify every account that currently has App Governance access through the admin role. Once you’ve mapped those accounts, decide which ones genuinely need ongoing access and transition them to a dedicated role.

Microsoft specifically calls out Security Administrator as a viable alternative, but the right choice depends on what your team actually does. If a user only needs to review App Governance reports, a more limited role may suffice; if they build and enforce policies, a role with broader security permissions makes sense.

What this means for you

For everyday administrators, the practical takeaway is simple: don’t assume that holding the admin role is enough to keep working in App Governance after the change lands. If you wait until the deadline, you risk finding yourself locked out mid-incident — exactly when you’d want that access most.

The good news is that the fix is largely preventive. A focused permissions audit now, followed by targeted role transitions, keeps your team operational without any disruption to the underlying App Governance features.

A close-up of a digital checklist and permission toggle switches on a screen, symbolizing a security permissions audit,
Transitioning affected accounts to dedicated roles keeps teams operational without disruption.

How to audit and transition roles

Begin by listing the accounts and groups that currently inherit App Governance permissions via the admin role. In your Microsoft 365 or Entra admin center, review role assignments and note which users are affected. Then, for each account that needs continued access, assign the appropriate dedicated role — such as Security Administrator — and remove reliance on the inherited admin-role access.

Test the new assignments in a small group first if you can, so you can confirm that the personnel in question retain the access they need before rolling it out more broadly. Completing this ahead of the deadline gives you a buffer to catch any gaps.

Bottom line: treat this as a routine least-privilege cleanup that happens to have a hard stop. Audit now, transition the accounts that need it, and you’ll keep App Governance working without a scramble when Microsoft flips the switch.

Source: Neowin

Over to you: Has your team already audited App Governance permissions, or are you planning to wait until the deadline is looming?

Advertisement
Share:
Editorial
Written by
Editorial

Windows & Microsoft news editor at 9to5Windows. Covering everything from Windows 11 builds to enterprise updates.

Advertisement