Cloud-based identity management dashboard showing user controls, analytics, workflow, and security protection.
Microsoft will remove Microsoft Entra Cloud Application Administrator access to App Governance in Microsoft Defender for Cloud Apps when Unified Role-Based Access Control is enabled, with enforcement scheduled for September 26, 2026. Administrators who hold only that role must receive another supported role by September 25 or they will lose access to the App Governance experience the following day.

The change is documented in Microsoft 365 Message Center item MC1462464 and was first reported by Neowin. It applies worldwide to organizations using App Governance in Defender for Cloud Apps and using Defender unified RBAC, known as URBAC. It does not remove the Cloud Application Administrator role from Microsoft Entra, and it does not change that role’s ability to manage app registrations and enterprise applications. The narrow but consequential change is that the role will no longer open the App Governance portion of the Defender portal under URBAC.

For security teams, the immediate risk is a silent operational gap: an administrator can retain what appears to be a highly relevant application-management role while being unable to investigate risky OAuth applications, review App Governance alerts, or take permitted remediation actions after the cutoff.

September 26 is the enforcement date, not the planning deadline​

MC1462464 sets September 25, 2026 as the date to complete the review and September 26 as the date the new access rule takes effect. Microsoft describes rollout as beginning in late September, but the enforcement date is specific enough that organizations should treat September 26 as a hard cutover rather than a gradual feature rollout.

The short notice matters more than the apparent simplicity of assigning a replacement role. In many tenants, Entra administrator roles are governed through Privileged Identity Management, access packages, approval workflows, or group-based assignments. A security team that identifies affected staff on September 25 may still be waiting for role activation, a change request, or a privileged-access review when access disappears.

Microsoft’s notice says the change affects administrators assigned only the Cloud Application Administrator role. That word is important. A person who also holds a supported Entra role should retain App Governance access, subject to that role’s permissions. The required work is therefore an assignment audit, not an assumption that every Cloud Application Administrator must be replaced wholesale.

App Governance is where OAuth app risk becomes actionable​

App Governance is the Defender for Cloud Apps capability for identifying and responding to OAuth-enabled applications connected to Microsoft 365, Google Workspace, and Salesforce. It exposes the applications that have been granted access to organizational data, the permissions they use, the activity associated with them, and policy-driven alerts that can flag anomalous or risky behavior.

That makes access loss more serious than a missing administrative dashboard. The feature can be part of an organization’s response path for an overprivileged third-party application, a suspicious consent grant, or an OAuth app exhibiting unusual data access. A team may still have Entra access to manage the application object while losing its established Defender workflow for detecting and investigating risk.

Microsoft’s own App Governance documentation also draws a line that administrators should understand before making emergency changes: App Governance data and actions are controlled largely through Microsoft Entra roles, while Defender unified RBAC has a limited App Governance role in advanced hunting. In particular, Microsoft says unified RBAC permissions govern access to the OAuthAppInfo table in advanced hunting, but that most App Governance experiences still rely on Entra roles.

In practice, adding a Defender custom role alone may not restore the portal access that an affected Cloud Application Administrator loses. The remediation must use one of the Microsoft Entra roles named in the Message Center notice.


Microsoft has supplied several replacements, but they do not mean the same thing​

The supported alternatives listed in MC1462464 are Security Administrator, Compliance Administrator, Compliance Data Administrator, Security Operator, Security Reader, Application Administrator, and Global Reader. Those names represent materially different levels of authority and different operational purposes. Treating them as interchangeable substitutes would undermine the least-privilege rationale Microsoft cites for the change.

For a read-only App Governance investigator, Security Reader or Global Reader may be more appropriate than an administrative role, depending on the tasks the person actually performs. Microsoft’s Defender for Cloud Apps role documentation says Global Reader receives read-only access across Defender for Cloud Apps, while Security Administrator has full access and can manage policies, settings, governance actions, and administrators.

Security Operator sits between those endpoints for many Defender tasks, while the compliance roles should be assessed against the team’s actual investigation and remediation needs rather than assigned simply because they preserve visibility. A compliance administrator is not a drop-in replacement for a security administrator: Microsoft’s Defender for Cloud Apps documentation limits compliance administrators from tasks including governance actions and policy creation.

The most tempting replacement for a Cloud Application Administrator is Application Administrator. It is also the option that deserves the closest security review. Microsoft Entra documents Application Administrator as a privileged role that can manage enterprise applications, app registrations, and application proxy settings. It can also manage application credentials and grant consent for many delegated and application permissions, with exceptions for Microsoft Graph and Azure AD Graph application permissions.

Cloud Application Administrator already has almost all of that app-management authority, except Application Proxy management. Moving a user from Cloud Application Administrator to Application Administrator can preserve an existing application-administration model and restore App Governance access, but it does not meaningfully reduce standing privilege. In fact, it adds Application Proxy administration. Organizations should use that replacement only where the administrator genuinely needs tenant-wide application management and the accompanying risk has been accepted.

Microsoft’s least-privilege recommendation points in the opposite direction for many App Governance operators: assign the narrowest supported security or reader role that allows the job to be completed, rather than using Application Administrator or Global Administrator as a universal repair.

URBAC’s wider rollout makes this more than a legacy-tenant issue​

Defender for Cloud Apps permissions were integrated with Microsoft Defender unified RBAC worldwide in December 2025. In August 2026, Microsoft began enabling unified RBAC automatically for new Defender for Cloud Apps customers. That expansion explains why an access-rule adjustment that might have affected a limited group of early adopters now deserves attention from ordinary Microsoft 365 security operations teams.

There is a practical complication for organizations that manage several Defender workloads together. Microsoft’s unified RBAC model centralizes many Defender permissions, but App Governance retains substantial dependence on Entra’s directory roles. The result is a two-layer authorization model: Defender roles may determine access to much of the Defender portal and advanced hunting, while Entra roles remain decisive for the App Governance experience.

That split is where access reviews can fail. A team might inspect Defender role assignments, find a user with a broad security role in one workload, and assume that App Governance is covered. Conversely, a Cloud Application Administrator may appear properly provisioned in Entra and be working normally today, yet become blocked solely because the tenant has Defender for Cloud Apps URBAC enabled.

Microsoft’s Message Center notice does not identify how many tenants or administrators are affected, nor does it provide a portal report that enumerates people whose only qualifying route is Cloud Application Administrator. It also does not describe whether the Defender portal will show a dedicated warning before enforcement. The safe approach is to assume the tenant must perform that correlation itself.


What administrators should audit before the cutoff​

Start in Microsoft Entra ID by identifying every active and eligible assignment of the Cloud Application Administrator role, including assignments delivered through role-assignable groups and Privileged Identity Management. The role’s template ID is 4ba39ca4-527c-499a-b93d-d9b492c50246, which can help teams that inventory directory roles through Microsoft Graph or PowerShell rather than the Entra portal.

Then determine whether each principal uses App Governance and whether it already holds another supported role. Do not limit the review to permanent user assignments. Emergency accounts, managed service provider guest accounts, automation identities, and PIM-eligible assignments can all create a failure at the moment a responder needs to investigate an OAuth incident.

A focused change plan should include the following:

  • Review Cloud Application Administrator assignments at tenant scope and through role-assignable groups, then identify administrators who have no other supported App Governance role.
  • Match each affected identity to its real App Governance duty: read-only investigation, alert handling, policy administration, or wider Defender administration.
  • Assign the minimum supported Microsoft Entra role needed for that duty, following the organization’s PIM, approval, and separation-of-duties controls.
  • Test access to the App Governance overview, OAuth application inventory, alerts, policies, and any remediation actions the administrator is expected to perform.
  • Document the result in the access-review record, including whether the original Cloud Application Administrator assignment remains necessary for app-registration administration.

Testing is worth emphasizing. A portal landing page that loads successfully does not prove that a user can perform the activities required during an incident. Teams should validate the exact workflow: finding an OAuth application, reading its permissions and activity, opening related alerts, and taking the approved response action. The person approving or changing policies may need a different role from the person who only triages alerts.

The change removes a convenience path, not an application-management role​

Microsoft frames the move as alignment with standard role support across Defender and as groundwork for future role-based access enhancements. The record supports that explanation: App Governance is increasingly being brought into a broader Defender permission structure, while the Cloud Application Administrator role remains fundamentally an Entra application-management role rather than a Defender security role.

But the practical outcome is less elegant than the rationale. Organizations that deliberately assigned Cloud Application Administrator to avoid broader security roles must now decide whether the affected staff are security operators, compliance users, readers, or application administrators with extra access. That decision cannot safely be made with a bulk replacement.

On September 26, an administrator who has only Cloud Application Administrator and tries to enter App Governance in a URBAC-enabled Defender for Cloud Apps tenant should expect to be denied. The work to prevent that denial is small for a well-documented tenant, but the deadline leaves little room for discovering that App Governance access was tied to a role nobody considered part of the security operations model.