You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/active-directory/roles/permissions-reference.md
+2-2Lines changed: 2 additions & 2 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -1972,7 +1972,7 @@ Users with this role can manage alerts and have global read-only access on secur
1972
1972
|[Azure AD Identity Protection](../identity-protection/overview-identity-protection.md)| All permissions of the Security Reader role<br>Additionally, the ability to perform all Identity Protection Center operations except for resetting passwords and configuring alert e-mails. |
1973
1973
|[Privileged Identity Management](../privileged-identity-management/pim-configure.md)| All permissions of the Security Reader role |
1974
1974
|[Office 365 Security & Compliance Center](https://support.office.com/article/About-Office-365-admin-roles-da585eea-f576-4f55-a1e0-87090b6aaa9d)| All permissions of the Security Reader role<br>View, investigate, and respond to security alerts |
1975
-
|[Microsoft Defender for Endpoint](/microsoft-365/security/defender-endpoint/prepare-deployment)| All permissions of the Security Reader role<br>View, investigate, and respond to security alerts |
1975
+
|[Microsoft Defender for Endpoint](/microsoft-365/security/defender-endpoint/prepare-deployment)| All permissions of the Security Reader role<br/>View, investigate, and respond to security alerts<br/>When you turn on role-based access control in Microsoft Defender for Endpoint, users with read-only permissions such as the Security Reader role lose access until they are assigned a Microsoft Defender for Endpoint role.|
1976
1976
|[Intune](/intune/role-based-access-control)| All permissions of the Security Reader role |
1977
1977
|[Microsoft Defender for Cloud Apps](/defender-cloud-apps/manage-admins)| All permissions of the Security Reader role<br>View, investigate, and respond to security alerts |
1978
1978
|[Microsoft 365 service health](/microsoft-365/enterprise/view-service-health)| View the health of Microsoft 365 services |
@@ -2004,7 +2004,7 @@ In | Can do
2004
2004
Identity Protection Center | Read all security reports and settings information for security features<br><ul><li>Anti-spam<li>Encryption<li>Data loss prevention<li>Anti-malware<li>Advanced threat protection<li>Anti-phishing<li>Mail flow rules
2005
2005
[Privileged Identity Management](../privileged-identity-management/pim-configure.md) | Has read-only access to all information surfaced in Azure AD Privileged Identity Management: Policies and reports for Azure AD role assignments and security reviews.<br>**Cannot** sign up for Azure AD Privileged Identity Management or make any changes to it. In the Privileged Identity Management portal or via PowerShell, someone in this role can activate additional roles (for example, Global Administrator or Privileged Role Administrator), if the user is eligible for them.
[Microsoft Defender for Endpoint](/microsoft-365/security/defender-endpoint/prepare-deployment) | View and investigate alerts. When you turn on role-based access control in Microsoft Defender for Endpoint, users with read-only permissions such as the Azure AD Security Reader role lose access until they are assigned to a Microsoft Defender for Endpoint role.
2007
+
[Microsoft Defender for Endpoint](/microsoft-365/security/defender-endpoint/prepare-deployment) | View and investigate alerts<br/>When you turn on role-based access control in Microsoft Defender for Endpoint, users with read-only permissions such as the Security Reader role lose access until they are assigned a Microsoft Defender for Endpoint role.
2008
2008
[Intune](/intune/role-based-access-control) | Views user, device, enrollment, configuration, and application information. Cannot make changes to Intune.
2009
2009
[Microsoft Defender for Cloud Apps](/defender-cloud-apps/manage-admins) | Has read permissions.
2010
2010
[Microsoft 365 service health](/office365/enterprise/view-service-health) | View the health of Microsoft 365 services
0 commit comments