SHD / MC Checker

MC1479503 | Microsoft Defender for Cloud Apps: Permission changes for select App Governance Entra roles



MC1479503 | Microsoft Defender for Cloud Apps: Permission changes for select App Governance Entra roles

Classification planForChange
Last Updated 09/25/2026 21:33:20
Start Time 09/25/2026 21:33:11
End Time 12/30/2026 08:00:00
Message Content

[What and Why:]

We are introducing Microsoft Defender XDR Unified role-based access control (Unified RBAC) support for App Governance. As part of this rollout, App Governance permissions associated with select Microsoft Entra roles will change.

This update helps align App Governance access with Defender XDR role management and provides more consistent permission handling for organizations using Microsoft Defender for Cloud Apps.

[Rollout Schedule:]

General Availability (Worldwide): We will begin rolling out in mid-October 2026 and expect to complete by late October 2026.

[Impact on Your Organization:]

Who is affected:

  • Admins who manage App Governance in Microsoft Defender for Cloud Apps.
  • Users assigned Cloud App Security Administrator, Compliance Administrator, Compliance Data Administrator, or custom Microsoft Defender XDR Unified RBAC roles for Microsoft Defender for Cloud Apps.

Platforms/Services:

  • Microsoft Defender XDR.
  • Microsoft Defender for Cloud Apps.
  • App Governance.

What will happen:

  • Cloud App Security Administrator: Users with this Microsoft Entra role will gain permission to view and manage App Governance policies.
  • Compliance Administrator: Users with this Microsoft Entra role will no longer be able to manage App Governance policies or enable and disable App Governance in Settings.
  • Compliance Data Administrator: Users with this Microsoft Entra role will no longer be able to enable and disable App Governance in Settings.
  • Custom Defender XDR Unified RBAC roles: Users assigned a custom role in Defender XDR Unified RBAC for Microsoft Defender for Cloud Apps will also get access to App Governance features.

[Action Required/Recommendations:]

Before the enforcement date, we recommend that admins:

  • Review users who access App Governance through the Compliance Administrator, Compliance Data Administrator, or Cloud App Security Administrator role.
  • Review custom roles in Microsoft Defender XDR Unified RBAC for Microsoft Defender for Cloud Apps.
  • Assign another supported Microsoft Entra role or a custom Defender XDR Unified RBAC role to affected users, following least-privilege principles.
  • Update internal role assignment guidance and administrator documentation as needed.

[Compliance considerations:]

Does the change include an admin control, and can it be controlled through Entra ID group membership? This change affects App Governance permissions for selected Microsoft Entra roles and custom Microsoft Defender XDR Unified RBAC roles. Admins should review affected role assignments and update them as needed.
Does the change alter how admins can monitor, report on, or demonstrate compliance activities? The change affects which admin roles can access and manage App Governance policies and settings.
Machine Translation

[何となぜ:]

App Governance向けにMicrosoft Defender XDR Unified role-based access control(Unified RBAC)サポートを導入します。この展開の一環として、特定のMicrosoft Entra役割に関連するApp Governance権限が変更されます。

このアップデートにより、App GovernanceへのアクセスがDefender XDRロール管理と整合し、Microsoft Defender for Cloud Appsを使用する組織に対してより一貫した権限処理が提供されます。

[展開スケジュール:]

一般公開(世界)は2026年10月中旬から展開を開始し、2026年10月下旬までに完了する予定です。

[組織への影響:]

影響を受ける人物:

  • Microsoft Defender for Cloud Appsでアプリガバナンスを管理する管理者。
  • ユーザーはCloud App Security Administrator、Compliance Administrator、Compliance Data Administrator、またはMicrosoft Defender for Cloud Apps向けにカスタムのMicrosoft Defender XDR Unified RBAC役割を割り当てました。

プラットフォーム/サービス:

  • Microsoft Defender XDR。
  • Microsoft Defender for Cloud Apps。
  • アプリガバナンス。

今後の展開:

  • クラウドアプリセキュリティ管理者: このMicrosoft Entraの役割を持つユーザーは、App Governanceポリシーの閲覧および管理権限を得ます。
  • コンプライアンス管理者: このMicrosoft Entraの役割を持つユーザーは、設定でApp Governanceポリシーの管理や有効・無効の操作ができなくなります。
  • コンプライアンスデータ管理者: このMicrosoft Entraの役割を持つユーザーは、設定でアプリガバナンスの有効化・無効を行えなくなります。
  • カスタムDefender XDR Unified RBACの役割: Microsoft Defender for Cloud AppsのDefender XDR Unified RBACでカスタムロールを割り当てたユーザーは、App Governance機能にもアクセスできます。

[必要な行動/推奨事項:]

施行日前には、管理者の皆様に以下のことを推奨します:

  • コンプライアンス管理者、コンプライアンスデータ管理者、またはクラウドアプリセキュリティ管理者の役割を通じてアプリガバナンスにアクセスするユーザーをレビューしてください。
  • Microsoft Defender XDR Unified RBAC for Microsoft Defender for Cloud Apps のカスタムロールをレビューしてください。
  • 影響を受けたユーザーに、最小権限原則に従い、別のサポートされているMicrosoft EntraロールまたはカスタムDefender XDR Unified RBACロールを割り当ててください。
  • 必要に応じて社内役割割り当てのガイダンスや管理者のドキュメントを更新してください。

[コンプライアンス上の考慮事項:]

変更には管理者権限が含まれていますか?また、Entra IDのグループメンバーシップを通じて管理できますか? この変更は、選択されたMicrosoft EntraロールおよびカスタムMicrosoft Defender XDR Unified RBACロールのApp Governance権限に影響を与えます。管理者は影響を受けたロール割り当てを確認し、必要に応じて更新してください。
この変更は管理者がコンプライアンス活動を監視、報告、または示す方法に変化をもたらしますか? この変更により、どの管理者ロールがアプリガバナンスのポリシーや設定にアクセスし管理できるかが変わります。