This article covers how to decommission Defend from your Microsoft 365 tenant when your deployment only used app registrations, with no transport rules, connectors, or an accepted domain configured.
For a summary of these changes, see the Defend Quickstart Guide.
Prerequisites
To complete the Defend decommissioning process, the Global Administrator role in Microsoft Entra is required.
Step 1: Delete the App Registrations
Up to five app registrations are created for Defend. Two are legacy and may not exist on newer deployments.
| App Registration | Status |
|---|---|
| Defend User Analysis | Legacy (may not be present) |
| Defend Admin Features | Legacy (may not be present) |
| Egress Software Technologies | Current |
| KnowBe4 Onboard | Current |
| KnowBe4 Deploy | Current |
| KnowBe4 Collaboration Security | Current (only present if Microsoft Teams integration was enabled) |
| KnowBe4 Inbound Email Security | Current |
You can follow the steps below to delete the app registrations:
- Navigate to the Microsoft Entra Admin Center > Enterprise applications > All applications > locate and delete each app listed above.
You will need to confirm that no other KnowBe4 Defend or Egress app registrations or enterprise apps remain.
Step 2: KnowBe4 Decommissions the Defend Tenant
Your KnowBe4 account team handles this final step. We'll remove the Defend tenant configuration from our infrastructure to fully close out the account. This step isn't something you can do from your side.
;