Skip to content

Commit 79e01b5

Browse files
Merge pull request #281199 from dcurwin/wi-271973-remove-permissions-july18-2024
Removing permissions
2 parents b229e3e + d3ab074 commit 79e01b5

File tree

1 file changed

+12
-0
lines changed

1 file changed

+12
-0
lines changed

articles/defender-for-cloud/tenant-wide-permissions-management.md

Lines changed: 12 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -74,6 +74,18 @@ To request elevated permissions from your global administrator:
7474

7575
After the global administrator selects **Review the request** and completes the process, the decision is emailed to the requesting user.
7676

77+
## Removing permissions
78+
79+
To remove permissions from the root tenant group, follow these steps:
80+
81+
1. Go to the Azure portal.
82+
1. In the Azure portal, search for **Management Groups** in the search bar at the top.
83+
1. In the **Management Groups** pane, find and select the **Tenant Root Group** from the list of management groups.
84+
1. Once inside the **Tenant Root Group**, select **Access Control (IAM)** in the left-hand menu.
85+
1. In the **Access Control (IAM)** pane, select the **Role assignments** tab. This shows a list of all role assignments for the **Tenant Root Group**.
86+
1. Review the list of role assignments to identify which one you need to remove.
87+
1. Select the role assignment you want to remove (**Security admin** or **Security reader**) and select **Remove**. Ensure you have the necessary permissions to make changes to role assignments in the **Tenant Root Group**.
88+
7789
## Next steps
7890

7991
Learn more about Defender for Cloud permissions in the following related page:

0 commit comments

Comments
 (0)