Account Discovery: find the accounts your SaaS apps forgot to tell you about
Account Discovery reports the accounts that exist inside connected applications, including orphaned ones that nobody in Entra was ever assigned. It's now generally available.
Provisioning and SSO tell you who should have access to an app. They don't always tell you who does. Apps collect accounts over the years: created locally by an app admin, left behind after a migration, or belonging to people who left long ago.
Assigned in Entra
Should have access
- Users and groups assigned to the app
- Provisioned by Entra
- Handled by joiner and leaver processes
Discovered in the app
Actually has an account
- Every account the app reports
- Includes local and legacy accounts
- Matched to Entra users where possible
Orphaned
The gap
- In the app, but no Entra assignment
- Leavers, local admins, old migrations
- Invisible to access reviews until now
Account Discovery reports the accounts that exist in your connected applications, and flags orphaned accounts: accounts in the app that don't correspond to an assignment in Entra. It's generally available and requires Entra ID Governance or Entra Suite licensing.
Using it well
- Start with high-risk apps: finance, HR, anything holding client data, and any app with its own admin accounts.
- Review the orphaned accounts with the app owner. Some will be service or break-glass accounts that are meant to be there; document those.
- Disable the rest in the app, and fix the process that created them.
- Bring legitimate users under Entra assignment so future joiners and leavers are handled automatically.
Making it stick
- Agree an owner for each in-scope app before you start
- Bring the app's discovered accounts into your regular access reviews
- Turn on provisioning where the app supports it, so new accounts start in Entra
- Remove local account creation rights from app admins where you can
- Re-run discovery after each clean-up to show the trend
Which apps does it work with?
Apps connected to Entra for provisioning and governance. Check the documentation for the current list of supported connectors.
Will it change anything in the app?
Discovery reports. Changes are yours to make, either in the app or through provisioning.