SHD / MC Checker

MC1462464 | Microsoft Defender for Cloud Apps: App Governance support for the Cloud Application Administrator role is being retired



MC1462464 | Microsoft Defender for Cloud Apps: App Governance support for the Cloud Application Administrator role is being retired

Classification planForChange
Last Updated 08/26/2026 22:31:45
Start Time 08/26/2026 22:31:24
End Time 11/02/2026 08:00:00
Action Required By Date 2026-09-25T07:00:00Z
Message Content

[What and why]

Microsoft Defender for Cloud Apps is updating the Microsoft Entra roles that grant access to App Governance when Unified Role-Based Access Control (URBAC) is enabled. As part of this change, support for the Cloud Application Administrator role will be retired for App Governance access.

This change aligns App Governance access with the standard supported role set used across Microsoft Defender services and supports future role-based access enhancements.

[Rollout schedule]

  • Retirement (Worldwide): Beginning in late September 2026
  • Enforcement date: September 26, 2026

[Impact on your organization]

Who is affected

  • Organizations that use App Governance in Microsoft Defender for Cloud Apps and have administrators who access App Governance using only the Cloud Application Administrator Microsoft Entra role

Platforms and services

  • Microsoft Defender for Cloud Apps
  • App Governance
  • Microsoft Entra ID

What will happen

After September 26, 2026:

  • Administrators assigned only the Cloud Application Administrator role will no longer be able to access App Governance when URBAC is enabled for Defender for Cloud Apps.
  • Administrators assigned one of the supported roles will continue to have access based on their permissions.
  • No user experience changes are expected.

[Action required and recommendations]

Review administrator assignments by September 25, 2026.

Assign an appropriate supported role to any administrator who requires App Governance access. Supported roles include:

  • Security Administrator
  • Compliance Administrator
  • Compliance Data Administrator
  • Security Operator
  • Security Reader
  • Application Administrator
  • Global Reader

We recommend assigning the role with the minimum permissions required for each administrator’s responsibilities.

[Compliance considerations]

Question Answer
Does this change modify administrative access to a Microsoft 365 service? Yes. This change removes App Governance access for administrators who are assigned only the Cloud Application Administrator Microsoft Entra role when URBAC is enabled for Microsoft Defender for Cloud Apps.
Does this change require organizations to review or update role assignments? Yes. Organizations should review current administrator role assignments and assign a supported role to administrators who require App Governance access before September 26, 2026.
Does this change affect how administrators control or access the service? Yes. Access to App Governance will be governed by a revised set of supported Microsoft Entra roles, changing how some administrators obtain access to the service.
Does this change involve an administrative control or permissions change? Yes. The change retires support for one administrative role and requires use of one of the supported roles to maintain App Governance access.

Machine Translation

[何となぜ]

Microsoft Defender for Cloud Appsは、統合ロールベースアクセス制御(URBAC)が有効化された際にApp Governanceへのアクセスを付与するMicrosoft Entraロールを更新しています。この変更の一環として、Cloud Application Administratorの役割のサポートはApp Governanceへのアクセスに関して終了します。

この変更により、App GovernanceのアクセスはMicrosoft Defenderサービスで標準的にサポートされているロールセットと整合し、将来のロールベースアクセスの強化もサポートします。

[展開スケジュール]

  • 退職(世界規模): 2026年9月下旬から開始
  • 施行日:2026年9月26日

[組織への影響]

影響を受ける人物

  • Microsoft Defender for Cloud Apps で App Governance を使用し、管理者が Cloud Application Administrator Microsoft Entra 役割のみで App Governance にアクセスする組織

ホームとサービス

  • Microsoft Defender for Cloud Apps
  • アプリガバナンス
  • Microsoft Entra ID

何が起こるのか

2026年9月26日以降:

  • Cloud Application Administratorの役割のみに割り当てられた管理者は、Defender for Cloud AppsでURBACを有効にするとApp Governanceにアクセスできなくなります。
  • サポートされている役割のいずれかに割り当てられた管理者は、その権限に基づいて引き続きアクセス権を持ちます。
  • ユーザー体験の変更は期待されていません。

[行動が必要と提言]

管理者の割り当ては2026年9月25日までに 確認してください。

アプリガバナンスアクセスが必要な管理者には、適切なサポートロールを割り当てます。サポートされるロールには以下が含まれます:

  • セキュリティ管理者
  • コンプライアンス管理者
  • コンプライアンスデータ管理者
  • セキュリティオペレーター
  • セキュリティリーダー
  • アプリケーション管理者
  • グローバル・リーダー

各管理者の責任に必要な最低限の権限を持つ役割を割り当てることを推奨します。

[コンプライアンスの考慮事項]

質問 回答
この変更はMicrosoft 365サービスの管理アクセスを変更するのでしょうか? はい。この変更により、Microsoft Defender for Cloud AppsでURBACが有効化された際にCloud Application Administrator Microsoft Entraの役割のみが割り当てられている管理者のApp Governanceアクセスが削除されます。
この変更により、組織は役割割り当てを見直したり更新したりする必要はありますか? はい。組織は現在の管理者の役割割り当てを確認し、2026年9月26日までにApp Governanceアクセスが必要な管理者にサポートロールを割り当てるべきです。
この変更は管理者がサービスの管理やアクセスに影響しますか? はい。App Governanceへのアクセスは、Microsoft Entraの対応ロールの改訂セットによって管理され、一部の管理者がサービスへのアクセス方法を変更します。
この変更は管理上の管理管理や権限の変更を含んでいますか? はい。この変更により、1つの管理ロールのサポートが終了し、アプリガバナンスアクセスを維持するためにサポートされているロールのいずれかを使う必要があります。