HomeNewsletterCommunityMVP FeedToolsArchiveBlogToday's NewsAboutServicesQuick Links★ Pro Subscribe free
← Back to Blog
Entra ID Entra IDMicrosoft Defender for CloudCIEMCloud SecurityAzurePowerShell

Entra Permissions Management Is Retired. Your CIEM Coverage Might Still Have a Hole In It.

IA
Imran Awan
24 September 2026

If you went looking for the Permissions Management blade in the Microsoft Entra admin center any time after November 1, 2025 and found nothing there, you didn't miss a menu — Microsoft deleted it, and the data collection behind it, on schedule. Microsoft Entra Permissions Management (the product born from the 2021 CloudKnox acquisition) is retired. What almost nobody has written about clearly is what that actually leaves an Intune/Entra admin with today, in September 2026, and it is not a simple like-for-like swap.

This post is not "breaking news" — the retirement itself is over ten months old by the time you're reading this. It exists because the coverage question is not old news at all: Microsoft is still actively changing how Cloud Infrastructure Entitlement Management (CIEM) works inside Microsoft Defender for Cloud as recently as August 2026, most admins were never given a CIEM replacement in the first place (Microsoft's own recommended path was a third-party product, not an internal one), and this site — despite covering Entra ID heavily — has never once written about Permissions Management, CIEM, or what replaced either of them. That gap, not the retirement date, is the actual news here.

The short version

Microsoft Entra Permissions Management stopped selling on April 1, 2025 (May 1, 2025 for CSP customers) and was fully retired — with all collected permissions data deleted — on November 1, 2025, after a one-month extension from the original October 1 date. Microsoft's own official migration recommendation is not "just turn on Defender for Cloud" — it's a third-party partner product, Delinea's Privilege Control for Cloud Entitlements. Separately, and this is the part that gets lost, Microsoft Defender for Cloud already had (and still has) its own native CIEM capability, bundled into the paid Defender CSPM plan, that was never the same product and was unaffected by the shutdown. It covers less ground than the old standalone tool did, it lives entirely in the Azure portal (not Entra ID, not Intune), and Microsoft has been quietly trimming it further — deprecating its risk-scoring metric and cutting back AWS/GCP detail — as recently as August 2026. This post gives you the exact steps to turn it on, what it actually gives you versus what you lost, and a read-only PowerShell script to audit which of your subscriptions have it enabled at all.

The problem: the portal blade is gone and the data is already deleted

Here's the exact sequence, in Microsoft's own words and dates, because a lot of the secondary coverage of this got the final date wrong (an earlier, since-superseded plan said October 1, 2025 — that date changed).

Quoted directly from Microsoft's own offboarding guidance on Microsoft Learn: "Effective April 1, 2025, Microsoft Entra Permissions Management will no longer be available for purchase, and on November 1, 2025, we'll retire and discontinue support of this product." The same page states plainly: "On October 01, 2025, Permissions Management will be automatically offboarded and associated data collection will be deleted" — that October date was the original plan; Microsoft's Entra blog subsequently confirmed a one-month extension, with auto-offboarding actually landing on November 1, 2025.

If you had it onboarded and did nothing, here is what happened to you automatically, with no action required on your part:

Watch out — this already happened, and it's not reversible. There is no "restore" for a retired SaaS product's deleted dataset. If nobody on your team exported the Permissions Management custom reports, alert rules, or the list of onboarded AWS/GCP authorization systems before November 1, 2025, that historical visibility is gone permanently. The only thing worth doing now is confirming nothing in your environment still silently depends on it (see "How to verify" below) and closing the resulting gap going forward — not trying to recover what was deleted.

The confusing part for most Intune/Entra admins isn't the retirement itself — it's what to do instead. And here's the detail that gets skipped in almost every summary of this story: Microsoft's own official recommendation for what replaces Permissions Management is not "Microsoft Defender for Cloud." It's a named third-party partner.

Why it happens: one retired product, one surviving feature, and they are not the same thing

To make sense of this, you need to separate two things that get talked about as if they're interchangeable, because Microsoft itself used the same acronym — CIEM — for both.

Thing one: the standalone product that just died

Microsoft Entra Permissions Management was a full standalone SaaS product, reachable from the Microsoft Entra admin center, with its own portal, its own onboarding wizard (OIDC app registrations into your AWS and GCP accounts), custom reports, configurable alerts, and a scoring metric called the Permissions Creep Index (PCI). Microsoft's own retirement notice explains the business reasoning plainly:

Quoted directly from Microsoft's offboarding guidance: "The decision to phase out Microsoft Entra Permissions Management from the Microsoft Security portfolio was made after deep consideration of our innovation portfolio and how we can focus on delivering the best innovations aligned to our differentiating areas and partner with the ecosystem on adjacencies." In plainer language: Microsoft decided full-featured CIEM was an "adjacency," not a core Entra investment, and handed that ground to a partner instead of building it out further themselves.

That partner is Delinea, specifically their product Privilege Control for Cloud Entitlements (PCCE). Microsoft's guidance is explicit that this — not Defender for Cloud — is the recommended migration target for anyone who actually relied on the full feature set: continuous entitlement discovery, granular usage-based recommendations, and dashboards comparable to what Permissions Management provided.

Thing two: the feature inside Defender for Cloud that never went anywhere

Separately, Microsoft Defender for Cloud has its own native CIEM capability, bundled as part of the Defender Cloud Security Posture Management (CSPM) plan. This is not a new product Microsoft spun up to replace Permissions Management — it already existed as an integration point, and Microsoft's current documentation is careful to say the shutdown doesn't touch it:

Quoted directly from Microsoft Learn's CIEM overview page (defender-for-cloud/permissions-management): "The deprecation of Microsoft Entra Permissions Management doesn't affect any existing CIEM capabilities in Microsoft Defender for Cloud."

So: one product retired and had its data deleted. A separate, narrower capability with a similar name and acronym kept running the whole time, inside a completely different portal, under a completely different license (a paid Defender for Cloud plan, not an Entra add-on), and it was never a one-for-one replacement for the thing that got shut down.

Gotcha. Don't assume that because you already have Microsoft Defender for Cloud deployed, you automatically have CIEM coverage. Defender CSPM has to be the Standard pricing tier (not Free), and even then, native CIEM is a separate toggle inside that plan's settings — Permissions Management (CIEM) — that has to be switched on explicitly per subscription, per AWS account, and per GCP project. Plenty of tenants have Defender CSPM enabled for its other capabilities (Attack Path Analysis, Cloud Security Explorer for resource-level queries) with this specific toggle left off, and never notice.

What you actually lose going from the old product to the new feature

Even fully onboarded, native CIEM in Defender for Cloud is a smaller feature set than the retired standalone product. As of this post, Microsoft's own documentation lists these two coverage gaps explicitly under "Limitations" on the CIEM enablement page:

Both of those changes landed within the last two months of this post being written — this is not a static, settled feature. If you built a migration plan around native CIEM a year ago, it's worth re-reading it against what's actually there today.

Microsoft Entra admin center Identity Permissions Management — no longer listed

That's the breadcrumb you will not find anymore. There is no "Permissions Management" node under Identity in the Entra admin center as of this post. If a runbook, an onboarding doc, or a piece of internal training material still tells a new hire to go find it there, that documentation needs updating before it wastes someone's afternoon.

Watch out — a real console distinction most Intune/Entra admins will trip over. Everything about the surviving CIEM feature lives in the Azure portal, under Microsoft Defender for Cloud — not the Microsoft Entra admin center, and not Intune. If your role is primarily Intune/Entra-scoped and you don't normally sign in to Azure's Defender for Cloud blade at all, this is genuinely a different console with a different RBAC model (Azure roles, not just Entra roles) than the one you're used to. Budget time to get access before you try to follow the steps below.

How to verify: check what you still have and what you never turned on

Before deciding what to do, find out where you actually stand. There are two separate things to check: leftover artifacts from the retired product, and whether the surviving feature is even switched on.

Step 1 — Check for leftover Permissions Management artifacts in Entra ID

Even though the product itself is gone, its supporting app registrations and role assignments can linger in your tenant if nobody ran the offboarding steps. Check both of these:

  1. Sign in to the Microsoft Entra admin center.
  2. Go to Identity › Applications › Enterprise applications › All applications.
  3. Search for Cloud Infrastructure Entitlement Management. If this app is still present and still enabled for user sign-in, it's a dead credential surface left over from the old AWS/GCP OIDC connections — worth disabling even though the product behind it is retired.
  4. Separately, go to Identity › Roles & administrators and search for the Permissions Management Administrator role. Check its assignments — anyone still holding that role has a standing privileged role assignment for a product that no longer exists.
PowerShell (Microsoft Graph, read-only)
Connect-MgGraph -Scopes "Application.Read.All","RoleManagement.Read.Directory" Get-MgServicePrincipal -Filter "displayName eq 'Cloud Infrastructure Entitlement Management'" | Select-Object DisplayName, AppId, AccountEnabled

If AccountEnabled comes back True, that service principal can still accept sign-ins even though the product it belonged to has been shut down and its data deleted for almost a year. There's no upside to leaving it enabled.

Step 2 — Check whether native CIEM in Defender for Cloud is actually on

This is the check most tenants skip, because it's easy to assume "we have Defender for Cloud" means "we have CIEM." Confirm it directly, per subscription, with PowerShell rather than clicking through every subscription's settings blade by hand.

PowerShell (Az.Security, read-only)
Connect-AzAccount Set-AzContext -SubscriptionId "<your-subscription-id>" $cspm = Get-AzSecurityPricing -Name "CloudPosture" $cspm.PricingTier $cspm.Extensions | Where-Object { $_.Name -eq "EntraPermissionsManagement" }

Two things have to both be true for CIEM to actually be running on that subscription: PricingTier has to read Standard (Defender CSPM's paid tier — the Free tier doesn't carry CIEM at all), and the extension named EntraPermissionsManagement has to appear in the Extensions collection with IsEnabled set to True. That exact extension name — confusingly, still carrying the old product's name even though it now lives inside Defender for Cloud — is documented in Microsoft's own Azure Resource Manager schema reference for Microsoft.Security/pricings.

Tip. Don't try to guess this from the Azure portal's UI toggle wording alone — the portal calls it "Permissions Management (CIEM)" in the Defender CSPM settings pane, while the underlying API and PowerShell object call the exact same thing EntraPermissionsManagement. Both names refer to the identical setting; if you're grepping infrastructure-as-code or writing your own audit query, search for both strings.

The fix: onboarding native CIEM in Defender for Cloud, click by click

If, after the checks above, you've decided native CIEM in Defender for Cloud is enough for your environment (rather than migrating to Delinea PCCE or another third-party CIEM tool for full feature parity), here is the complete, exact walkthrough — every click, for Azure, AWS, and GCP — straight from Microsoft's current enablement documentation.

Note — this is a licensing and portal toggle, not a CSP or Group Policy setting. Unlike most of what this site covers, CIEM in Defender for Cloud has no Intune OMA-URI/Settings Catalog path and no Group Policy equivalent — it is purely an Azure Resource Manager-level plan configuration (Microsoft.Security/pricings), set through the Azure portal, PowerShell, CLI, or an ARM/Bicep/Terraform deployment. If you were expecting this post's usual "CSP path vs. GPO path" table, this is the reason it isn't here.

Prerequisites — read this before you start clicking

  1. You need the Security Admin Azure RBAC role — at subscription level for Azure, at account/organization level for AWS and GCP connectors.
  2. For AWS or GCP resources, the cloud account/project must already be connected to Defender for Cloud (via the AWS or GCP connector) before you can turn on CIEM for it.
  3. Defender CSPM must already be enabled (Standard tier) on the subscription, AWS account, or GCP project — CIEM is a sub-toggle inside that plan, not a standalone purchase.

Enable CIEM for an Azure subscription

Microsoft Defender for Cloud Environment settings Defender CSPM Permissions Management (CIEM) — On
  1. Sign in to the Azure portal.
  2. In the top search bar, search for and select Microsoft Defender for Cloud.
  3. In the left navigation, select Environment settings.
  4. Select the relevant subscription from the tree on the left.
  5. Find the Defender CSPM plan row and select Settings next to it.
  6. Toggle Permissions Management (CIEM) to On.
  7. Select Continue.
  8. Select Save.

The applicable recommendations — "Azure overprovisioned identities should have only the necessary permissions" and "Permissions of inactive identities in your Azure subscription should be revoked" — appear within a few hours. There's no separate connector or credential step for Azure; the toggle alone is sufficient because Defender for Cloud already has read access to the subscription it's protecting.

Enable CIEM for an AWS account

  1. Sign in to the Azure portal and open Microsoft Defender for Cloud › Environment settings.
  2. Select the connected AWS account.
  3. Find the Defender CSPM plan row and select Settings.
  4. Toggle Permissions Management (CIEM) to On.
  5. (Recommended, not required) Set up AWS CloudTrail log ingestion for more accurate CIEM insights.
  6. Select Configure access.
  7. Select a deployment method (CloudFormation is the default onscreen option).
  8. Run the generated CloudFormation deployment script against your AWS environment, following the onscreen instructions.
  9. Check the CloudFormation template has been updated on AWS environment (Stack) box once the stack deployment completes.
  10. Select Review and generate.
  11. Select Update.

Unlike the Azure path, AWS requires this extra CloudFormation deployment because Defender for Cloud needs an IAM role granted inside your AWS account before it can read entitlement data there. Recommendations appear within a few hours of the stack finishing.

Gotcha — a real limitation as of August 6, 2026. The "AWS overprovisioned identities should have only the necessary permissions" recommendation still fires, but Defender for Cloud no longer calculates or displays the detailed list of specific unused AWS permission actions behind it, for performance and scalability reasons on Microsoft's side. If you need that level of detail, Microsoft's own guidance is to go into the AWS IAM console directly — select the identity or policy, open its Last Accessed tab, and review from there.

Enable CIEM for a GCP project

  1. Sign in to the Azure portal and open Microsoft Defender for Cloud › Environment settings.
  2. Select the connected GCP project.
  3. Find the Defender CSPM plan row and select Settings.
  4. Toggle Permissions Management (CIEM) to On.
  5. Select Save.
  6. Select Next: Configure access.
  7. Select the relevant permissions type for the deployment.
  8. Select a deployment method (Cloud Shell or Terraform).
  9. Run the generated deployment script against your GCP environment using the onscreen instructions.
  10. Check the I ran the deployment template for the changes to take effect box.
  11. Select Review and generate.
  12. Select Update.

Same story as AWS on the detail-level limitation: since August 6, 2026, drill-down on exactly which GCP permissions are unused has moved to Google Cloud's own Policy Intelligence and IAM role recommendations rather than staying inside Defender for Cloud.

Defender for Cloud — Environment settings, Defender CSPM plan (illustrative)
sub-prod-01 CSPM: Standard · CIEM: On
sub-dev-03 CSPM: Standard · CIEM: Off
sub-legacy-07 CSPM: Free · CIEM: Unavailable
Illustrative — this is exactly the shape of coverage gap the companion script below is built to find across every subscription in a tenant at once, instead of clicking through Environment settings one subscription at a time.

The companion script: auditing CIEM coverage across every subscription

Clicking through Environment settings one subscription at a time doesn't scale past a handful of subscriptions. Get-CiemCoverageReport.ps1 loops every subscription the signed-in account can see, checks the Defender CSPM plan's pricing tier and its EntraPermissionsManagement extension state using the exact Get-AzSecurityPricing call shown above, and reports which subscriptions have full CIEM coverage, which have Defender CSPM but not the CIEM extension, and which don't have Defender CSPM (Standard) at all.

It is entirely read-only. It never calls Set-AzSecurityPricing or any other state-changing cmdlet — it only reads pricing configuration and reports on it. Running it does not turn CIEM on or off anywhere.

Watch out. This script only checks the Azure side. It does not audit AWS accounts or GCP projects connected to Defender for Cloud — extending it to iterate those requires the AWS/GCP connector resource IDs, which are tenant-specific and not something this post is going to guess at. Treat this as your Azure subscription coverage check, and check AWS/GCP coverage directly in the Azure portal's Environment settings for now.
PowerShell Scripts — CIEM Coverage Audit

These scripts are ready for local testing. Please run them in your own tenant and confirm they work before they are pushed to GitHub and this box is updated with a live link.

Get-CiemCoverageReport.ps1 — Read-only audit of Defender CSPM tier and EntraPermissionsManagement extension state across every visible subscription

Proof it worked: reading the coverage report correctly

Run the script against a real tenant and you get one row per subscription, plus a summary count at the end. Here is an illustrative example — subscription names and IDs below are fictional, shaped the same way real ones would be, since this section can't publish a real tenant's subscription list.

PowerShell — illustrative run
.\Get-CiemCoverageReport.ps1 Checking CIEM coverage across 3 visible subscription(s)... SubscriptionName CspmTier CiemEnabled Status ----------------- -------- ----------- ------ Prod-Workloads Standard True OK - full CIEM coverage Dev-Sandbox Standard False GAP - Defender CSPM on, CIEM extension off Legacy-Finance Free n/a GAP - Defender CSPM not enabled (Free tier) SUMMARY: 1 of 3 subscription(s) have full CIEM coverage. 2 subscription(s) have a coverage gap - see Status column above. # Exit code 1 - gaps found

Three things confirm the audit ran correctly rather than silently failing:

Tip. Run this once now as a baseline, then again after Microsoft's next Defender for Cloud release notes update — CIEM in Defender for Cloud has changed twice in the last two months (the PCI deprecation and the August 6, 2026 AWS/GCP detail cutback) that this post is aware of. A quarterly re-run is a reasonable cadence for a feature that's still this actively being reshaped.

If your organization actually used Permissions Management's fuller feature set — custom reports, alerting, granular usage analytics — treat a clean "full CIEM coverage" result from this script as a floor, not a ceiling. It confirms the baseline Azure-native recommendations are running. It does not mean you have parity with what was retired; for that, Microsoft's own guidance still points to Delinea PCCE or another dedicated third-party CIEM product.

References

Microsoft MVP community deep-dives

AuthorPostWhat it adds
Anoop C Nair (Microsoft MVP)Phase Out Of Microsoft Entra Permissions ManagementNames Delinea as Microsoft's specific recommended CIEM partner and links its dedicated migration guide, and states plainly that Defender for Cloud keeps the permissions-discovery and PCI-style capabilities that existed before the retirement — useful independent confirmation of the same distinction this post makes between the two products.
Was this post helpful?
React below — no account needed
Share this post
LinkedIn X / Twitter Reddit Bluesky

More from EndpointWeekly

Entra ID
Your Conditional Access "Compliant Device" Check Is Trusting a…
Require device to be marked as compliant reads a stored flag, not a live device check -…
Entra ID
Zero Reviewers Responded, So Entra Auto-Approved a Departed Admin
An Entra access review whose deadline passes with no responses can auto-apply a default…
Entra ID
Group-Based Licensing Fails Silently for Some Users — Here's How…
Assign Microsoft 365 licences to a security group and for some members the assignment…