Entra ID

Microsoft Entra Account Discovery Closes App Gaps

3 min read

Summary

Microsoft has introduced Account Discovery in Microsoft Entra ID Governance public preview to help organizations identify existing user accounts and permissions inside connected applications. The feature gives identity teams a clearer view of matched, unassigned, and orphaned accounts so they can bring unmanaged access under policy and reduce identity risk.

Need help with Entra ID?Talk to an Expert

Microsoft Entra Account Discovery closes identity visibility gaps

Introduction

Identity governance only works when administrators can see who already has access. Microsoft is addressing that problem with Account Discovery in Microsoft Entra ID Governance, a new public preview feature designed to surface existing accounts inside connected SaaS and on-premises apps.

This matters because many applications were deployed long before modern governance controls were enabled. As a result, organizations often inherit unmanaged access, orphaned accounts, and direct app assignments that sit outside Conditional Access, access reviews, and lifecycle policies.

What’s new

Account Discovery connects to a target application, retrieves user accounts and properties, and compares them against identities in Microsoft Entra using configurable matching attributes such as:

  • User principal name
  • Email address

It then checks whether matched users are already assigned to the enterprise application in Entra and produces a discovery report with three classifications:

  • Matched and assigned: Users exist in Entra and are already assigned to the app
  • Matched but unassigned: Users exist in Entra, but access was granted directly in the application
  • Orphaned or local accounts: No matching Entra identity exists for the app account

This gives IT teams a fast baseline for understanding which accounts are already governed and which ones need remediation.

Why it matters for administrators

For identity and security teams, the biggest benefit is visibility before enforcing policy. During app onboarding, admins can use Account Discovery to find users who already have access through legacy processes, manual provisioning, or direct sign-up.

Microsoft’s example uses Salesforce, where discovery can reveal:

  • Employees with valid identities but no Entra app assignment
  • Local or orphaned accounts that may need removal or investigation
  • Service and test accounts that require separate review

Once identified, admins can move legitimate users into Entitlement Management access packages and apply approvals, expiration rules, and recurring access reviews. They can also investigate local accounts that may bypass MFA and Conditional Access.

Ongoing governance and next steps

Account Discovery is not just for initial onboarding. Microsoft positions it as an ongoing governance checkpoint to detect drift over time, such as:

  • New local accounts created outside approved workflows
  • Missed offboarding cases
  • Temporary contractor or test accounts that remain active longer than expected

What IT teams should do now

  • Review which enterprise applications have legacy or manually managed access
  • Run Account Discovery during onboarding of newly governed apps
  • Use findings to map users into Entra governance workflows
  • Investigate and remediate orphaned, service, and local accounts
  • Schedule periodic discovery reviews to detect access drift

Availability

Account Discovery is available in public preview for organizations licensed with:

  • Microsoft Entra ID Governance
  • Microsoft Entra Suite
  • Microsoft E7

The feature is accessible through the Microsoft Entra admin center and Microsoft Graph APIs.

Need help with Entra ID?

Our experts can help you implement and optimize your Microsoft solutions.

Talk to an Expert

Stay updated on Microsoft technologies

Microsoft EntraEntra ID Governanceidentity governanceapplication securityaccount discovery

Related Posts

Entra ID

Microsoft Entra July 2026: Backup, BYOD, AI Security

Microsoft Entra's July 2026 updates introduce several identity and access improvements, led by the general availability of Entra Backup and Recovery and new BYOD support for Global Secure Access. Microsoft also previewed stronger Conditional Access controls for AI agents and announced security enhancements in Microsoft Authenticator, giving IT teams more resilience, flexibility, and governance options.

Entra ID

Microsoft Entra SAP Identity Management Updates

Microsoft has expanded Microsoft Entra integrations with SAP to help organizations modernize identity management as they move away from SAP IDM and other on-premises tools. New capabilities for provisioning, account discovery, OAuth 2.0 authentication, and SAP role governance can help IT teams unify lifecycle management and access governance across SAP and non-SAP apps.

Entra ID

Microsoft Entra ID Branded Sign-In CSS Changes 2026

Microsoft Entra ID is tightening the security of branded sign-in pages by retiring support for custom CSS positioning properties starting October 26, 2026. Organizations that use these properties in company branding should review and remove them now to avoid layout changes and maintain a trusted sign-in experience.

Entra ID

Microsoft Entra Zero Trust Updates for AI and Apps

Microsoft has announced new Microsoft Entra Internet Access and Private Access capabilities to secure AI, web, and private app traffic with Zero Trust controls. The update adds public preview features for network DLP, AI agent controls, and agentic scenarios, while generally available features expand secure access for BYOD, kiosk devices, and MCP traffic visibility.

Entra ID

Azure AD B2C Migration Policy Analyzer Now GA

Microsoft has made the Migration Policy Analyzer generally available to help organizations assess Azure AD B2C custom policies before moving to Microsoft Entra External ID. The tool generates a structured migration assessment, helping IT teams understand current implementations, identify gaps, and prioritize migration work faster.

Entra ID

Microsoft Entra Agent ID: Secure AI Agent Access

Microsoft is urging organizations to treat AI agent governance as an immediate identity and access problem, not a future concern. Based on feedback from identity professionals at Identiverse 2026, the company highlights unmanaged agent sprawl, orphaned agents, and weak agent-to-agent controls, while positioning Microsoft Entra Agent ID and Agent 365 as the foundation for inventory, ownership, and policy enforcement.