ENow | AppGov Blog

New in ENow App Governance Accelerator 3.1 - End Entra ID Chaos with Unified App View

Written by ENow Software | Oct 20, 2025 1:00:00 PM

The modern identity evolution is putting IT and security teams under pressure to govern cloud applications at scale while minimizing security gaps. Bad actors have turned their attention to these Entra ID application governance and security gaps, as this is still a blind spot for most organizations. Breaches over the past few years underscore this reality: from Midnight Blizzard’s use of a legacy OAuth app to access Microsoft’s senior leadership mail, to the Commvault Metallic zero-day that exposed stored client secrets, to multi-tenant consent abuse and Entra ID flaws that enabled tenant hijacking 

The common thread? Entra ID application governance gaps, such as misconfigurations, over-permissioned application registrations, legacy OAuth components, and weak consent governance, create pathways for attackers to gain persistent, high-privilege access that often evades detection. 

With the release of ENow App Governance Accelerator 3.1, ENow is delivering a major leap forward in simplifying Entra ID application governance, increasing visibility, and providing administrators with stronger control of workflows and application ownership. 

This release builds on our commitment to provide the industry’s most effective application governance solution for Entra ID, combining actionable insights with automation to drive faster remediation and stronger identity security. 

Unified App View Reports (Pro & Enterprise) 

Microsoft Entra administrators have long struggled with fragmented visibility. Today, viewing App Registrations and related Enterprise Applications or Service Principals requires toggling between multiple tabs in the Microsoft Entra Admin portal. This results in wasted time, management headaches, and, most critically, security blind spots. 

App Governance Accelerator 3.1 addresses this issue with the introduction of a Unified App View, now available in Pro and Enterprise editions. 

Benefits of the Unified App View for Entra ID: 

  • Visibility: See App Registrations and Enterprise Applications side-by-side in a single pane of glass. 
  • Security: Detect mismatching permissions and identify orphaned applications or service principals left behind after App Registration cleanup. 
  • Efficiency: Save time and reduce errors by consolidating what previously required multiple admin blades. 
  • Peace of Mind: Gain holistic oversight of your tenant, addressing one of Microsoft’s top unfulfilled customer requests. 

With Unified App View, administrators can finally achieve the observability required to govern their Entra ID applications with confidence. 

Enhanced Ownership with Alternate Owner Functionality (Enterprise) 

Assigning the “Owner” field in Entra ID gives a user far-reaching privileges, including the ability to configure SSO, provisioning, and user assignments. For many organizations, this level of access is too risky, leading them to avoid assigning owners altogether. 

The result? The cleanup effort becomes a wild goose chase. Admins waste time determining who should be making decisions around a particular application, and ownerless applications are kept out of fear of accidentally removing an application that might be critical.  

Version 3.1 introduces Alternate Owner functionality (Enterprise), enabling organizations to record ownership inside App Governance Accelerator without assigning elevated permissions in Entra ID. 

Benefits: 

  • Reduce Risk: Keep sensitive privileges out of end users’ hands. 
  • Maintain Governance: Store and display ownership in AppGov workflows, ensuring accountability without exposing the environment. 
  • Improve Scoring: Mark applications as “owned” to avoid negative AppGov Score impacts, even when Entra ID’s native owner field is unused. 

This feature bridges the gap between strong governance practices and strict security postures. 

SSO SAML Certificate Report (Pro & Enterprise) 

SSO outages and token compromise are among the most disruptive risks in modern IT environments. Applications with a SAML signing certificate assigned are used to sign and secure authentication assertions between an Identity Provider and a Service Provider. Version 3.1 introduces a new SSO SAML Certificate Report, available in Pro and Enterprise editions. 

What the SSO SAML Certificate report does: 

This report identifies all applications assigned a SAML signing certificate, allowing administrators to monitor certificate status across the tenant. 

Why this matters: 

  • Prevent Outages: Expired certificates break SSO, blocking user access to critical applications. 
  • Strengthen Security: Compromised certificates could allow attackers to forge tokens and impersonate users. 

How to act on the report: 

  • Enable expiry notifications with App Governance Accelerator workflows. 
  • Implement certificate rollover with secondary certificates. 
  • Notify application owners and business stakeholders before cutover. 
  • Test new certificates in a staging environment before making them primary.

If the cert has already expired, you will need to update the application immediately with new certificate details. You should expect downtime until the update process is complete if the application does not allow login without a valid cert. Once complete you should test SSO and monitor the sign-in logs for errors and confirm successful token issuance.  

By providing proactive visibility into certificate health, this report ensures teams can take preventive action before issues escalate into outages or breaches. 

Customizable AppGov Score (Enterprise) 

Every organization’s governance strategy is unique. In 3.1, Enterprise subscription customers gain the ability to exclude specific tests from their AppGov Score. 

This customization enables administrators to tailor the scoring model to their policies, maturity level, and risk tolerance, ensuring the score reflects what matters most to their business. 

Enhanced & Centralized Admin Role Controls 

Application governance requires consistent rules, permissions, and notifications. To simplify this, version 3.1 introduces a centralized admin control interface (Admin role only) to govern the behavior, availability, and access of key actions and fields in the AppGov Automated Workflow(s).  

Capabilities include: 

  • Defining exclusions for owners and application names. 
  • Controlling workflow actions and automation options. 
  • Standardizing communication with non-editable email templates. 

With these controls, administrators can enforce governance consistency across teams, while still enabling Identity Engineers to execute delegated tasks. 

Updated User Interface 

Governance should be powerful, yet easy. In 3.1, ENow has overhauled the AppGov UI for a cleaner, more intuitive experience. 

Improvements include: 

  • Streamlined layout: Simplified navigation and improved report card views. 
  • Progress tracking: Quickly see governance progress across reports. 
  • Expand/Collapse: One-click expansion or collapse of reports and properties, reducing time spent scrolling. 
  • Enhanced Report Descriptions: Updated “how to use” sections make it easier for admins to take informed actions. 

These changes make AppGov more approachable for new users, while speeding up workflows for experienced administrators. 

Additional Enhancements 

Alongside the headline features, version 3.1 delivers a range of quality-of-life improvements: 

  • Enhanced outputs for Certificates Expired and Client Secrets Expired reports. 
  • Improved Freemium Hunting Analysis report descriptions. 
  • Ability to revert to the AppGov Score ‘Freemium’ scorecard and analysis from higher-level subscriptions. 
  • Updated charts with grid lines and legends for easier scoring insights. 
  • Numerous bug fixes and workflow stability improvements.

Why ENow App Governance Accelerator 3.1 Matters 

In today’s world, application governance is no longer optional; it is mission critical. Every new application onboarded to Entra ID carries potential risks, including misconfigurations, expired certificates, and unmonitored permissions. 

With ENow App Governance Accelerator 3.1, organizations can: 

  • Achieve full visibility across App Registrations and Enterprise Applications. 
  • Strengthen ownership accountability without sacrificing security. 
  • Proactively prevent SSO outages and mitigate identity risks. 
  • Customize governance to reflect organizational priorities. 
  • Streamline workflows with centralized controls and an improved UI. 

ENow continues to innovate where Microsoft leaves gaps, ensuring enterprises have the tools they need to secure their identity landscape and govern applications at scale. 

Take the first step toward stronger application governance. 

Start by running your free AppGov Score to establish your baseline and reveal the scope of risk across your Entra ID applications. With clear insights into where you stand today, you’ll be empowered to reduce blind spots, prioritize remediation, and build a governance strategy that scales. From there, App Governance Accelerator makes it simple to turn those insights into action. 

👉 [Get Your Free AppGov Score Today]