Skip to content

Commit 15933f6

Browse files
committed
fixed example table and removed personas
1 parent 05a8ffe commit 15933f6

File tree

1 file changed

+6
-14
lines changed

1 file changed

+6
-14
lines changed

defender-endpoint/prepare-deployment.md

Lines changed: 6 additions & 14 deletions
Original file line numberDiff line numberDiff line change
@@ -16,7 +16,7 @@ ms.collection:
1616
ms.topic: conceptual
1717
ms.subservice: onboard
1818
search.appverid: met150
19-
ms.date: 06/26/2024
19+
ms.date: 09/09/2024
2020
---
2121

2222
# Assign roles and permissions for Microsoft Defender for Endpoint deployment
@@ -38,15 +38,7 @@ The next step when deploying Defender for Endpoint is to assign roles and permis
3838
3939
## Role-based access control
4040

41-
Microsoft recommends using the concept of least privileges. Defender for Endpoint leverages built-in roles within Microsoft Entra ID. Microsoft recommends [review the different roles that are available](/azure/active-directory/roles/permissions-reference) and choose the right one to solve your needs for each persona for this application. Some roles may need to be applied temporarily and removed after the deployment has been completed.
42-
43-
|Personas|Roles|Microsoft Entra role (if necessary)|Assign to|
44-
|---|---|---|---|
45-
|Security Administrator||||
46-
|Security Analyst||||
47-
|Endpoint Administrator||||
48-
|Infrastructure Administrator||||
49-
|Business Owner/Stakeholder||||
41+
Microsoft recommends using the concept of least privileges. Defender for Endpoint leverages built-in roles within Microsoft Entra ID. [Review the different roles available](/azure/active-directory/roles/permissions-reference) and choose the right one to solve your needs for each persona for this application. Some roles may need to be applied temporarily and removed after the deployment has been completed.
5042

5143
Microsoft recommends using [Privileged Identity Management](/azure/active-directory/active-directory-privileged-identity-management-configure) to manage your roles to provide additional auditing, control, and access review for users with directory permissions.
5244

@@ -62,11 +54,11 @@ You can find details on permission guidelines here: [Create roles and assign the
6254

6355
The following example table serves to identify the Cyber Defense Operations Center structure in your environment that will help you determine the RBAC structure required for your environment.
6456

65-
|Tier|Description|Permission Required|
57+
|Tier|Description|Permissions required|
6658
|---|---|---|
67-
|Tier 1|**Local security operations team / IT team** <br/><br/> This team usually triages and investigates alerts contained within their geolocation and escalates to Tier 2 in cases where an active remediation is required.||
68-
|Tier 2|**Regional security operations team** <br/><br/> This team can see all the devices for their region and perform remediation actions.|View data|
69-
|Tier 3|**Global security operations team** <br/><br/> This team consists of security experts and is authorized to see and perform all actions from the portal.|View data <br/><br/> Alerts investigation Active remediation actions <br/><br/> Alerts investigation Active remediation actions <br/><br/> Manage portal system settings <br/><br/> Manage security settings|
59+
|Tier 1|**Local security operations team / IT team** <br/><br/> This team usually triages and investigates alerts contained within their geolocation and escalates to Tier 2 in cases where an active remediation is required.|View data|
60+
|Tier 2|**Regional security operations team** <br/><br/> This team can see all the devices for their region and perform remediation actions.|View data <br/><br/> Alerts investigation <br/><br/> Active remediation actions <br/><br/>|
61+
|Tier 3|**Global security operations team** <br/><br/> This team consists of security experts and is authorized to see and perform all actions from the portal.|View data <br/><br/> Alerts investigation <br/><br/> Active remediation actions <br/><br/> Manage portal system settings <br/><br/> Manage security settings|
7062

7163
## Next step
7264

0 commit comments

Comments
 (0)