azureblog.co.uk
← cd ~/posts

Account Discovery: find the accounts your SaaS apps forgot to tell you about

Account Discovery reports the accounts that exist inside connected applications, including orphaned ones that nobody in Entra was ever assigned. It's now generally available.

2 min read✓ checked 17 Jun 2026Entra ID · Governance · What's new

Provisioning and tell you who should have access to an app. They don't always tell you who does. Apps collect accounts over the years: created locally by an app admin, left behind after a migration, or belonging to people who left long ago.

Assigned in Entra

Should have access

  • Users and groups assigned to the app
  • Provisioned by Entra
  • Handled by joiner and leaver processes

Discovered in the app

Actually has an account

  • Every account the app reports
  • Includes local and legacy accounts
  • Matched to Entra users where possible

Orphaned

The gap

  • In the app, but no Entra assignment
  • Leavers, local admins, old migrations
  • Invisible to access reviews until now
What Entra knows versus what the app holds.

Account Discovery reports the accounts that exist in your connected applications, and flags orphaned accounts: accounts in the app that don't correspond to an assignment in Entra. It's generally available and requires Entra ID Governance or Entra Suite licensing.

Using it well

  1. Start with high-risk apps: finance, HR, anything holding client data, and any app with its own admin accounts.
  2. Review the orphaned accounts with the app owner. Some will be service or that are meant to be there; document those.
  3. Disable the rest in the app, and fix the process that created them.
  4. Bring legitimate users under Entra assignment so future joiners and leavers are handled automatically.
Good for audits: "show me every account in this system and who owns it" is a common audit request. This answers it from one place.
Who does this account belong to?
A current userAssign them in Entra so the account is governed
A service or break-glass accountDocument an owner and the reason, then review it yearly
A leaver or nobodyDisable in the app, then delete after a grace period
Working through an orphaned account.

Making it stick

  • Agree an owner for each in-scope app before you start
  • Bring the app's discovered accounts into your regular
  • Turn on provisioning where the app supports it, so new accounts start in Entra
  • Remove local account creation rights from app admins where you can
  • Re-run discovery after each clean-up to show the trend
Which apps does it work with?

Apps connected to Entra for provisioning and governance. Check the documentation for the current list of supported connectors.

Will it change anything in the app?

Discovery reports. Changes are yours to make, either in the app or through provisioning.