Skip to content
TrustList
News

Defender for Cloud Apps moves App Governance to unified roles; Compliance Administrators lose policy control from mid-October

Editorial

By TrustList Editorial

From mid-October 2026, App Governance in Microsoft Defender for Cloud Apps follows Defender XDR unified roles. Compliance Administrators can no longer manage its policies; Cloud App Security Administrators gain that right.

About Defender for Cloud Apps moves App Governance to unified roles; Compliance Administrators lose policy control from mid-October

Defender for Cloud Apps moves App Governance to unified roles; Compliance Administrators lose policy control from mid-October

25 September 2026 — Microsoft told administrators on 25 September 2026, in Message Center post MC1479503, that App Governance in Microsoft Defender for Cloud Apps is moving to Microsoft Defender XDR Unified role-based access control (Unified RBAC). As part of the change, the permissions that some Microsoft Entra roles carry in App Governance will change. Rollout is due to start in mid-October 2026 and finish by late October.

App Governance is the part of Defender for Cloud Apps that watches OAuth-enabled apps connected to Microsoft 365, such as third-party apps granted access to mail, files or Teams, and lets administrators set policies that flag or disable risky ones.

Who gains and who loses

According to Microsoft:

  • Cloud App Security Administrator: gains permission to view and manage App Governance policies.
  • Compliance Administrator: will no longer be able to manage App Governance policies, or turn App Governance on and off in Settings.
  • Compliance Data Administrator: will no longer be able to turn App Governance on and off in Settings.
  • Custom Defender XDR Unified RBAC roles for Defender for Cloud Apps will also get access to App Governance features.

Microsoft's stated reason is to align App Governance access with Defender XDR role management and make permission handling more consistent.

Why it matters

In many organisations, app-consent policies are run by compliance or data-protection staff rather than the security operations team. If those people hold only the Compliance Administrator role, they will lose the ability to change App Governance policies when the rollout reaches their tenant. At the same time, anyone holding Cloud App Security Administrator, or a custom role scoped to Defender for Cloud Apps, will gain App Governance rights they may not have had, which can widen access beyond what was intended.

Who is affected

Microsoft 365 organisations that use App Governance, their security and compliance teams, and managed security providers that administer Defender for customers.

What to do

  • Before mid-October, list everyone who manages App Governance through the Compliance Administrator, Compliance Data Administrator or Cloud App Security Administrator roles.
  • Give people who must keep managing policies another supported Entra role or a custom Unified RBAC role, on a least-privilege basis.
  • Review custom Defender XDR roles for Defender for Cloud Apps, since they will now reach App Governance too.
  • Update runbooks and access-review records so audits reflect who can change app policies after the change.

Not yet independently verified. This rests only on Microsoft’s own Message Center post, read through a public archive because the admin centre requires sign-in; no Microsoft Learn page or independent report describing the change was found. We will update this when it can be confirmed, and remove this note.

Sources