ENow | AppGov Blog

Top 5 Entra ID Governance Challenges (and What to Fix First)

Written by Sander Berkouwer | Jul 17, 2026 6:28:09 PM

Earlier this year, I shared a stage at the Microsoft 365 Community Conference. Jay Gundotra, Daniel Glenn, Sean Hurley, and I presented on the top 5 challenges managing Microsoft 365 and Entra ID… and what to fix first.I won’t go into depth on managing Microsoft 365, as Daniel covers that part more extensively than I do; I do want to offer you a quick recap of what I talked about during this session, though, effectively giving you 45 minutes of your time and probably a large portion of your travel budget back if you’re interested in the Entra part of that session.

What Are the Top 5 Entra ID Governance Challenges?

So here are the top 5 challenges when governing Entra:

1. Least Privilege: Over-Permissioned Apps, Service Principals, and AI Agents

One of the biggest risks in Entra ID environments is excessive privilege. Applications, service principals, and AI agents should only receive the minimum permissions necessary to perform their tasks.

As an Entra admin, you should avoid assigning broad permissions wherever possible. As a follow-up, you might want to stay in communication with vendors whose solution needs broad permissions; they may have come up with clever ways to reduce their permission needs, and you may benefit.

As organizations move further into AI and agent-based workflows, assigning least privilege becomes even more important.

2. Credential Hygiene for Non-Human Identities (NHIs)

These days, Microsoft talks about enterprise applications, application registrations, and agents as non-human identities (NHIs). Even though they don’t look or smell like humans, they still act largely the same and require credentials, which need regular changes.

The types of credentials for NHIs in Entra include:

  • Secrets
  • Certificates
  • Managed identities

Organizations need clear operational processes to prevent unexpected credential expiration from causing outages or service disruptions. Credential hygiene sounds operationally boring until an expired secret or certificate takes down a production application at 2 AM.

This is one of the most common operational risks Entra administrators face today.

3. Risky Application Permissions and Privilege Escalation

While you might govern privileges assigned to applications on a per-application basis or on a per-permission basis, some permission combinations introduce privilege escalation risks.

Organizations should regularly audit:

This becomes increasingly important as AI agents and automation platforms continue expanding.

4. Improper Access Controls and Over-Permissive Defaults

By default, many environments are more permissive than administrators realize.

Examples include:

  • All Users assignments
  • Broad app access
  • Open guest access
  • Excessive sharing defaults

These often small configuration choices can create significant downstream security and governance risks. You wouldn’t be the first admin to change a small setting to accommodate a VIP in your organization or solve an organization-wide outage… to find out years later that the identity solution has been vulnerable for years because of that seemingly innocent setting that affected everyone and everything.

5. Weak Tenant-Wide Settings in Entra ID

Tenant-wide defaults matter.

Organizations should regularly review:

  • User consent policies
  • Guest access settings
  • Application registration permissions
  • Agent deployment controls

In my experience, many governance improvements start with reviewing and tightening Entra tenant-wide defaults, e.g., “turn the faucet off, so you aren’t continuously mopping up the same mess.”

Quick answer: What are the top challenges managing Entra ID applications?

 

The five biggest Entra ID governance challenges are excessive privilege, poor credential hygiene for non-human identities, risky application permissions, improper access controls, and weak tenant-wide settings. Fix them in order of blast radius: start with tenant-wide defaults and expiring credentials, since those affect every app and identity at once, or are time sensitive.

 

Entra ID Governance at Enterprise Scale: What Actually Breaks

As I was already providing examples from my experience, I dove deeper in some of the recurring themes we hear from large enterprises.

The hardest part is not identifying governance problems

This may come as a surprise. Even at scale, the hardest path to governance is not identifying the problems or even identifying attack paths. The hardest part is operationalizing governance consistently over time. Only that way are you consistently able to provide value to your organization… whether it be taking advantage of the latest innovations, getting the competitive edge, or maximizing collaboration and productivity gains without having to worry about potential breaches.

We’ve come across enterprises that are dealing with tens of thousands of enterprise applications and service principals. That’s the scale we’re dealing with.

Using merely the Azure Portal or the Entra admin center, governance becomes impossible. Automation and repeatable operational processes are required at this scale.

One large organization had over 18,000 enterprise applications to evaluate and manage. Sean Hurley shared his experience and drove home the talking point that managing NHIs at this scale is not something you solve manually.

We’ve also seen organizations introduce so much friction into governance workflows that people in the organization begin bypassing governance entirely. We’re talking months to process the onboarding review of a newly requested application that had already been paid for.

The result was predictable: people started finding workarounds.

Governance needs to create operational control without becoming organizational paralysis.

Why Application Governance Has Real-World Business Consequences

Governance decisions can also have very real-world consequences.

Organizations have all types of applications. A few high-stakes apps we’ve heard about:

  • Animal care systems – have you heard the giraffe story!?
  • Apps that keep GPS satellites orbiting and operational
  • Apps controlling critical manufacturing systems and processes

The business operations run by applications at many organizations highlight something important: governance changes, lack of visibility, and lifecycle management can have a massive downstream impact far beyond IT itself.

As organizations become increasingly dependent on automation, integrations, and AI agents, governance mistakes can directly affect business operations.

What to Fix First in Entra ID Governance

The good news is you do not need to fix everything at once… You don’t even have to attend our packed session at the Microsoft 365 Community Conference.

Good governance starts with visibility.

Focus first on identifying:

  • Apps with risky permissions
  • Tenant-wide settings
  • Apps with improper access controls
  • Expiring credentials

Even addressing a small number of these issues can significantly improve governance maturity.

What Does Good Entra ID Governance Look Like?

Good governance is not about perfection. It is about building operational control incrementally. The goal is to move from reactive administration to predictable operational routines.

Good governance is not:

  • Zero exceptions
  • Bureaucracy
  • Saying “no” to everything

Good governance is:

  • Clear ownership
  • Predictable provisioning
  • Intentional access
  • Managed lifecycle decisions
  • Credential discipline
  • Controlled AI rollout
  • Visibility before problems become expensive

Key Takeaways: Scaling Entra ID Governance Safely

As organizations move deeper into AI, Copilot, and agent-based workflows, governance becomes even more important.

However, right now it is important to keep your eye on the goal. The goal is not to slow innovation down forever. The goal is to make sure your organization can scale innovation safely and sustainably.

Start small.

Focus on visibility.

Build repeatable governance routines.

… and most importantly, do not try to tackle everything at once.

If you’re ready to start, I recommend starting by getting your free AppGov Score, a quick Entra ID governance assessment.

 

Frequently Asked Questions About Entra ID Governance

What is Entra ID governance?

Entra ID governance is the practice of controlling who and what can access your Microsoft cloud environment, including users, applications, service principals, and AI agents. It covers permissions, credentials, access controls, and tenant settings so identities stay least-privileged and auditable over time.

What are the biggest challenges in managing Entra ID?

The five most common challenges are excessive privilege, poor credential hygiene for non-human identities, risky application permissions, improper access controls, and weak tenant-wide settings. Most incidents trace back to one of these five rather than a novel attack.

What are non-human identities (NHIs) in Entra ID?

Non-human identities are enterprise applications, app registrations, service principals, managed identities, and AI agents that authenticate without a person behind them. They hold credentials such as secrets and certificates, so they need the same rotation and lifecycle discipline you apply to user accounts.

How often should you rotate credentials for Entra ID applications?

Rotate secrets and certificates on a defined schedule and track credential expiration centrally in a tool like ENow App Governance Accelerator, so nothing lapses silently. The bigger risk is not the interval itself but the lack of a process: an expired secret can take down a production app at 2 AM with no warning.

What is least privilege in Entra ID, and why does it matter for AI agents?

Least privilege means every application, service principal, and agent gets only the permissions it needs to do its job. It matters more with AI agents because they act autonomously and at scale, so an over-permissioned agent can reach far more data and systems than intended.

What should you fix first to improve Entra ID application governance?

Start with visibility, then fix the items with the widest blast radius: weak tenant-wide defaults and expiring credentials, followed by apps with risky permissions and improper access controls. You do not need to fix everything at once; closing a few high-impact gaps meaningfully raises governance maturity.