Skip to content

Commit 1bb9bec

Browse files
committed
Update edit-delete-rbac-roles.md
1 parent 54f80af commit 1bb9bec

File tree

1 file changed

+11
-2
lines changed

1 file changed

+11
-2
lines changed

defender-xdr/edit-delete-rbac-roles.md

Lines changed: 11 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -38,11 +38,16 @@ The following steps guide you on how to edit roles in Microsoft Defender XDR Uni
3838

3939
> [!IMPORTANT]
4040
> You must be a Global Administrator or Security Administrator in Microsoft Entra ID, or have all the **Authorization** permissions assigned in Microsoft Defender XDR Unified RBAC to perform this task. For more information on permissions, see [Permission pre-requisites](manage-rbac.md#permissions-prerequisites).
41+
> Microsoft recommends that you use roles with the fewest permissions. This helps improve security for your organization. Global Administrator is a highly privileged role that should be limited to emergency scenarios when you can't use an existing role.
4142
4243
1. Sign in to the [Microsoft Defender portal](https://security.microsoft.com) as global administrator or security administrator.
44+
4345
2. In the navigation pane, select **Permissions**.
46+
4447
3. Select **Roles** under Microsoft Defender XDR to get to the Permissions and roles page.
48+
4549
4. Select the role you want to edit. You can only edit one role at a time.
50+
4651
5. Once selected, this opens a flyout pane where you can edit the role:
4752

4853
:::image type="content" source="/defender/media/defender/m365-defender-rbac-edit-roles.png" alt-text="Screenshot of the edit roles flyout page" lightbox="/defender/media/defender/m365-defender-rbac-edit-roles.png":::
@@ -76,14 +81,17 @@ The CSV also includes a snapshot of the Unified RBAC activation status for each
7681

7782
The following steps guide you on how to export roles in Microsoft Defender XDR Unified RBAC:
7883

79-
>[!Note]
80-
>To export roles, you must be a Global Administrator or Security Administrator in Microsoft Entra ID, or have the **Authorization (manage)** permission assigned for all data sources in Microsoft Defender XDR Unified RBAC and have at least one workload activated for Unified RBAC.
84+
> [!NOTE]
85+
> To export roles, you must be a Global Administrator or Security Administrator in Microsoft Entra ID, or have the **Authorization (manage)** permission assigned for all data sources in Microsoft Defender XDR Unified RBAC and have at least one workload activated for Unified RBAC.
8186
>
8287
>For more information on permissions, see [Permission pre-requisites](manage-rbac.md#permissions-prerequisites).
8388
8489
1. Sign in to the [Microsoft Defender portal](https://security.microsoft.com) with the required roles or permissions.
90+
8591
2. In the navigation pane, select **Permissions**.
92+
8693
3. Select **Roles** under Microsoft Defender XDR to get to the Permissions and roles page.
94+
8795
4. Select the **Export** button.
8896

8997
:::image type="content" source="/defender/media/defender/m365-defender-rbac-export-roles.png" alt-text="Screenshot of the export roles page" lightbox="/defender/media/defender/m365-defender-rbac-export-roles.png":::
@@ -94,4 +102,5 @@ A CSV file containing all the roles data will be generated and downloaded to the
94102

95103
- [Learn about RBAC permissions](custom-permissions-details.md)
96104
- [Map existing RBAC roles to Microsoft Defender XDR Unified RBAC roles](compare-rbac-roles.md)
105+
97106
[!INCLUDE [Microsoft Defender XDR rebranding](../includes/defender-m3d-techcommunity.md)]

0 commit comments

Comments
 (0)