Entra ID

Microsoft Entra Account Discovery Closes App Gaps

3 min read

Summary

Microsoft has introduced Account Discovery in Microsoft Entra ID Governance public preview to help organizations identify existing user accounts and permissions inside connected applications. The feature gives identity teams a clearer view of matched, unassigned, and orphaned accounts so they can bring unmanaged access under policy and reduce identity risk.

Need help with Entra ID?Talk to an Expert

Microsoft Entra Account Discovery closes identity visibility gaps

Introduction

Identity governance only works when administrators can see who already has access. Microsoft is addressing that problem with Account Discovery in Microsoft Entra ID Governance, a new public preview feature designed to surface existing accounts inside connected SaaS and on-premises apps.

This matters because many applications were deployed long before modern governance controls were enabled. As a result, organizations often inherit unmanaged access, orphaned accounts, and direct app assignments that sit outside Conditional Access, access reviews, and lifecycle policies.

What’s new

Account Discovery connects to a target application, retrieves user accounts and properties, and compares them against identities in Microsoft Entra using configurable matching attributes such as:

  • User principal name
  • Email address

It then checks whether matched users are already assigned to the enterprise application in Entra and produces a discovery report with three classifications:

  • Matched and assigned: Users exist in Entra and are already assigned to the app
  • Matched but unassigned: Users exist in Entra, but access was granted directly in the application
  • Orphaned or local accounts: No matching Entra identity exists for the app account

This gives IT teams a fast baseline for understanding which accounts are already governed and which ones need remediation.

Why it matters for administrators

For identity and security teams, the biggest benefit is visibility before enforcing policy. During app onboarding, admins can use Account Discovery to find users who already have access through legacy processes, manual provisioning, or direct sign-up.

Microsoft’s example uses Salesforce, where discovery can reveal:

  • Employees with valid identities but no Entra app assignment
  • Local or orphaned accounts that may need removal or investigation
  • Service and test accounts that require separate review

Once identified, admins can move legitimate users into Entitlement Management access packages and apply approvals, expiration rules, and recurring access reviews. They can also investigate local accounts that may bypass MFA and Conditional Access.

Ongoing governance and next steps

Account Discovery is not just for initial onboarding. Microsoft positions it as an ongoing governance checkpoint to detect drift over time, such as:

  • New local accounts created outside approved workflows
  • Missed offboarding cases
  • Temporary contractor or test accounts that remain active longer than expected

What IT teams should do now

  • Review which enterprise applications have legacy or manually managed access
  • Run Account Discovery during onboarding of newly governed apps
  • Use findings to map users into Entra governance workflows
  • Investigate and remediate orphaned, service, and local accounts
  • Schedule periodic discovery reviews to detect access drift

Availability

Account Discovery is available in public preview for organizations licensed with:

  • Microsoft Entra ID Governance
  • Microsoft Entra Suite
  • Microsoft E7

The feature is accessible through the Microsoft Entra admin center and Microsoft Graph APIs.

Need help with Entra ID?

Our experts can help you implement and optimize your Microsoft solutions.

Talk to an Expert

Stay updated on Microsoft technologies

Microsoft EntraEntra ID Governanceidentity governanceapplication securityaccount discovery

Related Posts

Entra ID

Azure AD B2C Migration Tools Now Available

Microsoft has released generally available migration tools and guidance to help Azure AD B2C customers move to Microsoft Entra External ID. With Azure AD B2C no longer receiving new features, these new options give IT teams a clearer path to modernize customer identity while reducing migration risk.

Entra ID

Microsoft Entra ID Security Updates: Key 2026 Changes

Microsoft is making three important Microsoft Entra ID security changes in 2026: retiring Custom controls in favor of External MFA, enforcing Conditional Access more consistently during credential registration, and requiring explicitly registered authentication methods for SSPR. These updates matter because they close policy enforcement gaps, improve identity security, and require admins to review configurations before enforcement deadlines arrive.

Entra ID

Global Secure Access Operations Guide Now Available

Microsoft has published a new Microsoft Entra Global Secure Access operations guide on Microsoft Learn to help teams manage day 2 operations after deployment. The guide provides prescriptive monitoring, health checks, role assignments, templates, and automation guidance so IT teams can run Global Secure Access more consistently and proactively.

Entra ID

Microsoft Entra Agent ID GA Secures AI Agents

Microsoft Entra Agent ID is now generally available, giving organizations a dedicated identity and access foundation for AI agents in production. Combined with the Microsoft Agent 365 CLI and SDK, it helps IT and security teams onboard, govern, audit, and secure agent instances across Microsoft and non-Microsoft frameworks.

Entra ID

Microsoft Entra June 2026: Passkeys, Linux MFA, B2C

Microsoft Entra’s June 2026 updates bring major identity improvements across passkeys, phishing-resistant MFA for Linux desktops, and Azure AD B2C migration to External ID. The release also adds cross-tenant group sync, app deactivation, redesigned My Account pages, and new governance features that help IT teams strengthen security and simplify administration.

Entra ID

Microsoft Entra Tenant Governance Finds Shadow Tenants

Microsoft Entra Tenant Governance now helps organizations discover shadow tenants connected through B2B collaboration, multitenant apps, and shared billing signals. The new related tenants capability gives IT teams continuous visibility into hidden tenant sprawl so they can assess risk, quarantine unsanctioned tenants, and tighten identity governance.