Defender Admins Could Lose App Governance Access Unless They Change Roles Fast


microsoft defender role change
Image credit: Microsoft

Microsoft is retiring support for the Cloud Application Administrator role in Microsoft Defender for Cloud Apps’ App Governance when Unified Role-Based Access Control (URBAC) is enabled.

According to Message Center advisory MC1462464, the change takes effect one day after Microsoft Edge 154 launches, giving Microsoft 365 administrators just eight days to review existing permissions and reassign affected users.

Admins who rely only on the Cloud Application Administrator role will lose access to App Governance features once Microsoft makes the change.

The company says the move will align App Governance with the standardized security role hierarchy used across the wider Microsoft Defender suite.

Some existing roles will continue working

The change does not affect every administrator role.

Users assigned one of the following supported roles will retain access to App Governance:

  • Security Administrator
  • Application Administrator
  • Global Reader

Organizations should review current role assignments and move affected administrators to an approved alternative before the deadline.

Microsoft is tightening least-privilege access

Microsoft is moving App Governance permissions away from the broader Cloud Application Administrator role as part of an effort to enforce tighter least-privilege security boundaries.

The company wants App Governance access controls to match the role structure already used across other Microsoft Defender services.

For organizations using URBAC, that means relying on supported Defender roles instead of the Cloud Application Administrator role for App Governance access.

Admins should audit permissions now

Microsoft Defender for Cloud Apps administrators should audit App Governance permissions before the change takes effect.

Any administrator who depends solely on the Cloud Application Administrator role could otherwise lose access once Microsoft removes support for it.

The timing also comes as Microsoft gives organizations only days to move away from Windows Information Protection and Microsoft Defender Application Guard, which will no longer be supported in Edge 154.

In other news, Microsoft Edge Canary appears to be finally disabling Manifest V2 extensions, while Microsoft wants organizations to adopt Windows Autopilot Device Preparation.

Microsoft has also given Exchange Online admins another warning before EWS retirement begins.

Via Neowin

Readers help support Windows Report. We may get a commission if you buy through our links. Tooltip Icon

Read our disclosure page to find out how can you help Windows Report sustain the editorial team. Read more

User forum

0 messages