You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Added detailed permissions required for Advanced Hunting, including roles in Microsoft Defender XDR, Email & Collaboration, Exchange Online, and Microsoft Entra.
reviewed by our Beta Engineer Mithun
Copy file name to clipboardExpand all lines: defender-xdr/advanced-hunting-overview.md
+44Lines changed: 44 additions & 0 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -56,6 +56,50 @@ For more information on advanced hunting in Microsoft Defender for Cloud Apps da
56
56
## Get access
57
57
58
58
To use advanced hunting or other [Microsoft Defender XDR](microsoft-365-defender.md) capabilities, you need an appropriate role in Microsoft Entra ID. [Read about required roles and permissions for advanced hunting](custom-roles.md).
59
+
## Permissions required for Advanced Hunting
60
+
61
+
You need to be assigned permissions before you can run Advanced Hunting queries. You have the following options:
62
+
63
+
### **Microsoft Defender XDR Unified role-based access control (URBAC)**
Membership in one of the following Email & Collaboration role groups provides access to email data tables in Advanced Hunting:
81
+
82
+
***Security Administrator**
83
+
***Security Operator**
84
+
***Security Reader**
85
+
86
+
### **Exchange Online RBAC permissions**
87
+
88
+
To access EXO-related data surfaced in Advanced Hunting, users must be members of one of the following Exchange Online role groups:
89
+
90
+
***View-Only Organization Management**
91
+
***View-Only Configuration**
92
+
***Security Reader**
93
+
***Global Reader**
94
+
95
+
### **Microsoft Entra permissions**
96
+
97
+
Membership in one of the following Microsoft Entra roles grants full read access to all Advanced Hunting data:
98
+
99
+
***Global Administrator**
100
+
***Security Administrator**
101
+
***Security Reader**
102
+
***Global Reader**
59
103
60
104
Also, your access to endpoint data is determined by role-based access control (RBAC) settings in Microsoft Defender for Endpoint. [Read about managing access to Microsoft Defender XDR](m365d-permissions.md).
0 commit comments