Skip to content

Commit 059c550

Browse files
authored
Document permissions for Advanced Hunting access
Added detailed permissions required for Advanced Hunting, including roles in Microsoft Defender XDR, Email & Collaboration, Exchange Online, and Microsoft Entra. reviewed by our Beta Engineer Mithun
1 parent a77d3f6 commit 059c550

File tree

1 file changed

+44
-0
lines changed

1 file changed

+44
-0
lines changed

defender-xdr/advanced-hunting-overview.md

Lines changed: 44 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -56,6 +56,50 @@ For more information on advanced hunting in Microsoft Defender for Cloud Apps da
5656
## Get access
5757

5858
To use advanced hunting or other [Microsoft Defender XDR](microsoft-365-defender.md) capabilities, you need an appropriate role in Microsoft Entra ID. [Read about required roles and permissions for advanced hunting](custom-roles.md).
59+
## Permissions required for Advanced Hunting
60+
61+
You need to be assigned permissions before you can run Advanced Hunting queries. You have the following options:
62+
63+
### **Microsoft Defender XDR Unified role-based access control (URBAC)**
64+
65+
**Read-only Advanced Hunting access (Email & Collaboration tables):**
66+
Membership assigned with the following Defender URBAC permission:
67+
68+
* **Security operations → Security data → Security data basic (read)**
69+
70+
This permission provides access to:
71+
72+
* **EmailEvents**
73+
* **EmailUrlInfo**
74+
* **EmailAttachmentInfo**
75+
* **UrlClickEvents**
76+
* **Email entity metadata**
77+
78+
### **Email & Collaboration (EOP / Defender for Office 365) permissions**
79+
80+
Membership in one of the following Email & Collaboration role groups provides access to email data tables in Advanced Hunting:
81+
82+
* **Security Administrator**
83+
* **Security Operator**
84+
* **Security Reader**
85+
86+
### **Exchange Online RBAC permissions**
87+
88+
To access EXO-related data surfaced in Advanced Hunting, users must be members of one of the following Exchange Online role groups:
89+
90+
* **View-Only Organization Management**
91+
* **View-Only Configuration**
92+
* **Security Reader**
93+
* **Global Reader**
94+
95+
### **Microsoft Entra permissions**
96+
97+
Membership in one of the following Microsoft Entra roles grants full read access to all Advanced Hunting data:
98+
99+
* **Global Administrator**
100+
* **Security Administrator**
101+
* **Security Reader**
102+
* **Global Reader**
59103

60104
Also, your access to endpoint data is determined by role-based access control (RBAC) settings in Microsoft Defender for Endpoint. [Read about managing access to Microsoft Defender XDR](m365d-permissions.md).
61105

0 commit comments

Comments
 (0)