Entra ID

Microsoft Entra Account Discovery Closes App Gaps

3 min read

Summary

Microsoft has introduced Account Discovery in Microsoft Entra ID Governance public preview to help organizations identify existing user accounts and permissions inside connected applications. The feature gives identity teams a clearer view of matched, unassigned, and orphaned accounts so they can bring unmanaged access under policy and reduce identity risk.

Need help with Entra ID?Talk to an Expert

Microsoft Entra Account Discovery closes identity visibility gaps

Introduction

Identity governance only works when administrators can see who already has access. Microsoft is addressing that problem with Account Discovery in Microsoft Entra ID Governance, a new public preview feature designed to surface existing accounts inside connected SaaS and on-premises apps.

This matters because many applications were deployed long before modern governance controls were enabled. As a result, organizations often inherit unmanaged access, orphaned accounts, and direct app assignments that sit outside Conditional Access, access reviews, and lifecycle policies.

What’s new

Account Discovery connects to a target application, retrieves user accounts and properties, and compares them against identities in Microsoft Entra using configurable matching attributes such as:

  • User principal name
  • Email address

It then checks whether matched users are already assigned to the enterprise application in Entra and produces a discovery report with three classifications:

  • Matched and assigned: Users exist in Entra and are already assigned to the app
  • Matched but unassigned: Users exist in Entra, but access was granted directly in the application
  • Orphaned or local accounts: No matching Entra identity exists for the app account

This gives IT teams a fast baseline for understanding which accounts are already governed and which ones need remediation.

Why it matters for administrators

For identity and security teams, the biggest benefit is visibility before enforcing policy. During app onboarding, admins can use Account Discovery to find users who already have access through legacy processes, manual provisioning, or direct sign-up.

Microsoft’s example uses Salesforce, where discovery can reveal:

  • Employees with valid identities but no Entra app assignment
  • Local or orphaned accounts that may need removal or investigation
  • Service and test accounts that require separate review

Once identified, admins can move legitimate users into Entitlement Management access packages and apply approvals, expiration rules, and recurring access reviews. They can also investigate local accounts that may bypass MFA and Conditional Access.

Ongoing governance and next steps

Account Discovery is not just for initial onboarding. Microsoft positions it as an ongoing governance checkpoint to detect drift over time, such as:

  • New local accounts created outside approved workflows
  • Missed offboarding cases
  • Temporary contractor or test accounts that remain active longer than expected

What IT teams should do now

  • Review which enterprise applications have legacy or manually managed access
  • Run Account Discovery during onboarding of newly governed apps
  • Use findings to map users into Entra governance workflows
  • Investigate and remediate orphaned, service, and local accounts
  • Schedule periodic discovery reviews to detect access drift

Availability

Account Discovery is available in public preview for organizations licensed with:

  • Microsoft Entra ID Governance
  • Microsoft Entra Suite
  • Microsoft E7

The feature is accessible through the Microsoft Entra admin center and Microsoft Graph APIs.

Need help with Entra ID?

Our experts can help you implement and optimize your Microsoft solutions.

Talk to an Expert

Stay updated on Microsoft technologies

Microsoft EntraEntra ID Governanceidentity governanceapplication securityaccount discovery

Related Posts

Entra ID

Microsoft Entra Passkeys for External IdP App Sign-Ins

Microsoft has made browser-based authentication for external identity providers generally available for supported Microsoft app sign-ins on Android, iOS, and managed macOS. This lets federated Microsoft 365 users use passkeys, FIDO2 security keys, and eligible SSO sessions in apps like Outlook, Teams, and OneDrive, reducing password fallback and embedded web view limitations.

Entra ID

Microsoft Entra Tenant Governance Webinars 2026

Microsoft is promoting upcoming webinars focused on securing multi-tenant environments with Microsoft Entra Tenant Governance, now generally available. The sessions highlight how organizations can detect shadow tenants, apply consistent governance, and build a stronger identity foundation for AI readiness.

Entra ID

Microsoft Entra App Gallery Self-Service Onboarding Preview

Microsoft has launched a public preview of self-service onboarding for new Microsoft Entra App Gallery applications. The new workflow lets publishers validate OIDC, SAML, and provisioning integrations before submission, then create, submit, and track app listings in the Entra admin center, reducing delays and rework.

Entra ID

Microsoft Entra Private Access Replaces VPNs

Microsoft is positioning Entra Private Access as a practical replacement for traditional VPNs, using identity-driven, per-app access instead of broad network tunnels. The guidance outlines a phased migration approach that helps IT teams reduce attack surface, strengthen Zero Trust controls, and simplify remote access operations.

Entra ID

HiBob Microsoft Entra Integration Now Generally Available

Microsoft has announced general availability of HiBob’s native integration with Microsoft Entra, enabling HR-driven identity lifecycle automation for joiners, movers, and leavers. The integration helps IT teams govern provisioning and access changes across hybrid and cloud environments while reducing manual processes and security risk.

Entra ID

Microsoft Entra September 2026: Key Identity Updates

Microsoft Entra's September 2026 updates introduce new tenant governance, user-centric access reviews, lifecycle workflow cloning, and passwordless resource accounts for Teams devices. The release also adds cloud-to-AD provisioning, AI-focused MCP Firewall protections, and important deadlines for MemberOf-based configurations and permission scope changes.