# Check inherited full access before narrowing a Cloud Apps administrator locally

> Can a local Defender for Cloud Apps role override an Entra role that already grants full access?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-437-check-inherited-full-access-before-narrowing-a-cloud-apps-administrator-locally/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:24:39+00:00
- Modified: 2026-09-10T02:04:57+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Briefing
- DSE priority: Information
- Topics: Cybersecurity, IT
- Reading time: 2 minutes

## What you need to know

Can a local Defender for Cloud Apps role override an Entra role that already grants full access?

## Potentially affected

Administrators reviewing Microsoft Entra, Microsoft 365 and local Defender for Cloud Apps role assignments.

## DSE recommendation

Inspect the directory role assignments before relying on a narrower local Cloud Apps role as the access boundary.

## Article

## Source facts

Defender for Cloud Apps can override some Microsoft Entra or Microsoft 365 permissions through a manually added local administrator role. It cannot override Entra roles already providing full access: Global administrator, Security administrator and Cloud App Security administrator. Those directory-service roles do not appear on the Cloud Apps Manage admin access page. The built-in local Cloud Apps roles grant access only to that service. [Microsoft Learn](https://learn.microsoft.com/en-us/defender-cloud-apps/manage-admins).

## Applicability

Use this distinction when an administrator is meant to have limited Cloud Apps responsibilities but may also hold a broader directory role. A local assignment review is only part of the access review; it does not establish the complete inherited permission set.

## DSE recommendation

Inspect the directory role assignments before relying on a narrower local Cloud Apps role as the access boundary. Have the identity owner and Cloud Apps owner reconcile the user’s intended duties with both assignment surfaces. If a broader role is required for another task, document that conflict and consider a separate administrative identity under the organization’s access policy. Do not describe the local role as a restriction that the product cannot enforce.

## Verification

With an approved test identity, compare the expected visible data and allowed actions with actual access. Include a directory-role review rather than checking only the Cloud Apps role list. Preserve the assignment evidence and observed restrictions without performing destructive governance actions. Resolve unexpected full access before signing off the narrower role, and repeat the comparison after any approved directory-role change.

## Official references

[Microsoft Learn: Configure Cloud Apps admin access](https://learn.microsoft.com/en-us/defender-cloud-apps/manage-admins). Source reviewed September 9, 2026.

## Primary reference

- Name: Configure admin access - Microsoft Defender for Cloud Apps | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/defender-cloud-apps/manage-admins
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Check inherited full access before narrowing a Cloud Apps administrator locally,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-437-check-inherited-full-access-before-narrowing-a-cloud-apps-administrator-locally/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
