
Microsoft Retires Entra Permissions Management – Why Delinea Is the Right Move for Cloud Entitlement Security
Author: Ewan Brown
Release Date: 16/05/2025
On 1st October 2025, Microsoft will officially retire and end support for Microsoft Entra Permissions Management (MEPM). This change marks a significant shift in how organisations will need to manage and secure permissions in their cloud environments. As part of the transition, Microsoft has announced that new purchases of MEPM will no longer be available after 1st April 2025.
To support customers through this change, Microsoft is recommending Delinea’s Privilege Control for Cloud Entitlements as the preferred alternative. This announcement has far-reaching implications for security teams relying on MEPM, particularly in enterprises that manage complex multi-cloud and Saas ecosystems.
What Does This Mean for Existing MEPM Customers?
For existing customers, Microsoft will continue to honour support contracts until the final retirement date of 1st October 2025. However, without ongoing development or new feature releases, MEPM will increasingly become outdated and less effective in keeping pace with rapidly evolving cloud security threats.
From April 2025, no new MEPM licences or renewals will be available, leaving organisations just six months to evaluate alternatives, migrate their workloads, and ensure continuity in cloud permission management.
Failure to act promptly may result in:
• Increased risk of privilege sprawl and over-permissioning.
• Gaps in visibility across hybrid and multi-cloud environments.
• Compliance challenges arise from a lack of continuous monitoring and reporting capabilities.
Why Delinea’s Privilege Control for Cloud Entitlements Is the Recommended Successor
Delinea’s Privilege Control for Cloud Entitlements is purpose-built to secure identities and entitlements across cloud infrastructure and SaaS applications. Unlike static tools, Delinea offers a dynamic, risk-aware approach that aligns with the principles of least privilege and zero trust.
Key benefits of moving to Delinea include:
1. Comprehensive Coverage Across Multi-Cloud Environments
Privilege Control integrates natively with AWS, Azure, and Google Cloud, offering real-time visibility and policy enforcement. It also supports leading SaaS platforms, providing organisations with a unified view of entitlements across their entire digital estate.
2. Continuous Discovery and Rightsizing
With Delinea, entitlements are continuously scanned and assessed for risk, enabling automated recommendations for rightsizing permissions. This drastically reduces the attack surface and helps enforce least privilege access at scale.
3. Context-Aware Access Control
Through integration with identity providers, threat intelligence, and compliance frameworks, Delinea applies contextual risk scoring to every user and role. This means organisations can detect anomalous privilege escalations or misconfigured roles before they become a security incident.
4. Accelerated Compliance
Delinea streamlines audits with detailed access reporting, entitlement reviews, and policy enforcement capabilities aligned with frameworks like ISO 27001, NIST, DORA, and CIS. This makes it easier to demonstrate regulatory compliance and manage cloud risk proactively.
Why This Matters More Than Ever
As cloud adoption accelerates, organisations are increasingly exposed to entitlement sprawl, a silent yet potent threat vector. A single misconfigured role or excessive privilege can be enough to breach a cloud environment.
The retirement of MEPM highlights the need to adopt modern, intelligent entitlement management tools. With the rise of identity-based attacks and cloud misconfigurations accounting for the majority of breaches, relying on outdated or unsupported solutions is no longer a viable option.
Next Steps for MEPM Customers
If you’re currently using MEPM, now is the time to:
1. Review your existing entitlements and usage patterns in Microsoft Entra.
2. Evaluate alternative solutions with a strong track record in cloud identity security.
3. Begin planning your transition to Delinea’s Privilege Control for Cloud Entitlements with support from Somerford Associates' expert onboarding teams.
The good news? Working with Somerford Associates and Delinea offers a proven migration path for former MEPM customers, along with trial environments and tailored onboarding to ensure a smooth transition without compromising security posture.
Final Thoughts
Microsoft’s decision to retire Entra Permissions Management is a clear signal that cloud security needs to evolve. Delinea’s Privilege Control for Cloud Entitlements is not just a replacement; it’s a next-generation solution that helps organisations take control of who has access to what, when, and why.
To learn more about transitioning from MEPM to Delinea, visit the our Delinea partner page, request a demo or speak with one of our cloud security specialists today!