You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
For the Microsoft Defender XDR security portal to start enforcing the permissions and assignments configured in your new [custom roles](create-custom-rbac-roles.md) or [imported roles](import-rbac-roles.md), you must activate the Microsoft Defender XDR Unified RBAC model for some or all of your workloads.
35
+
This article lists the steps to activate Defender workloads available in your environment to use the Microsoft Defender XDR Unified role-based access control (RBAC). Activate the Unified RBAC model for some or all of your workloads for the Microsoft Defender portal to start enforcing the permissions and assignments configured in your new [custom roles](create-custom-rbac-roles.md) or [imported roles](import-rbac-roles.md).
36
36
37
37
> [!IMPORTANT]
38
-
> From February 16, 2025, the Microsoft Defender XDR Unified RBAC model will be the default permissions model for new Microsoft Defender Endpoint tenants that have not created roles and permissions. The activation of the Microsoft Defender XDR Unified RBAC model won't be available for these new tenants. In addition, these new tenants won't have the ability to export roles and permissions from the current model.
38
+
> From February 16, 2025, the Microsoft Defender XDR Unified RBAC model will be the default permissions model for new Microsoft Defender Endpoint tenants where there are no roles or permissions created yet. As a result, activating the Unified RBAC model won't be available for these new tenants. In addition, these new tenants won't have the ability to export roles and permissions from the current model.
39
39
>
40
-
> All Defender for Endpoint tenants who assigned roles and permissions before this date can continue to use their current roles and permissions.
40
+
> All Defender for Endpoint tenants with previously assigned/exported roles and permissions before this date can continue to use their current roles and permissions.
@@ -49,7 +49,7 @@ The following steps guide you on how to activate the Microsoft Defender XDR Unif
49
49
2.[Activate in Microsoft Defender XDR settings](#activate-in-microsoft-365-defender-settings)
50
50
51
51
> [!IMPORTANT]
52
-
> You must be a Global Administrator or Security Administrator in Microsoft Entra ID to perform this task. For more information on permissions, see [Permission pre-requisites](manage-rbac.md#permissions-prerequisites).
52
+
> You must be a Global Administrator or Security Administrator in Microsoft Entra ID to perform this task. For more information on permissions, see [Permission prerequisites](manage-rbac.md#permissions-prerequisites).
53
53
> Microsoft recommends that you use roles with the fewest permissions. This helps improve security for your organization. Global Administrator is a highly privileged role that should be limited to emergency scenarios when you can't use an existing role.
54
54
55
55
### Activate from the Permissions and roles page
@@ -65,12 +65,12 @@ You can activate your workloads in two ways from the Permissions and roles page:
65
65
- Select **Activate workloads** on the banner above the list of roles to go directly to the **Activate workloads** screen.
66
66
- You must activate each workload one by one. Once you select the individual toggle, you activate (or deactivate) that workload.
67
67
68
-
:::image type="content" source="/defender/media/defender/defender-activate-workloads.png" alt-text="Screenshot of the choose workloads to activate screen.":::
68
+
:::image type="content" source="/defender/media/defender/defender-activate-workloads.png" alt-text="Screenshot of the page where you can choose workloads to activate.":::
69
69
70
70
> [!NOTE]
71
-
> The **Activate workloads** button is only available when there is it at least one workload that's not active for Microsoft Defender XDR Unified RBAC.
71
+
> The **Activate workloads** button is only available when there's it at least one workload that's not active for Microsoft Defender XDR Unified RBAC.
72
72
> Microsoft Defender for Cloud is active by default with Microsoft Defender XDR Unified RBAC.
73
-
> Defender XDR Unified RBAC is automatically active for Exposure Management access. Once a custom role with one of the Exposure Management permissions is created, it has an immediate impact on assigned users. There is no need to activate it.
73
+
> Defender XDR Unified RBAC is automatically active for Exposure Management access. Once a custom role with one of the Exposure Management permissions is created, it has an immediate impact on assigned users. There's no need to activate it.
74
74
>
75
75
> To activate Exchange Online permissions in Microsoft Defender XDR Unified RBAC, Defender for Office 365 permissions must be active.
76
76
@@ -103,15 +103,15 @@ Follow these steps to activate your workloads directly in Microsoft Defender XDR
103
103
You have now successfully activated (or deactivated) that workload.
104
104
105
105
> [!NOTE]
106
-
> The Microsoft Defender XDR Unified RBAC model only impacts the Microsoft Defender XDR security portal. It does not impact the [Microsoft Purview Compliance center](https://compliance.microsoft.com) or the [Exchange Admin Center](https://admin.exchange.microsoft.com).
106
+
> The Microsoft Defender XDR Unified RBAC model only impacts the Microsoft Defender portal. It doesn't impact the [Microsoft Purview portal](https://purview.microsoft.com) or the [Exchange Admin Center](https://admin.exchange.microsoft.com).
You can deactivate Microsoft Defender XDR Unified RBAC and revert to the individual RBAC models from Microsoft Defender for Endpoint, Microsoft Defender for Identity, and Microsoft Defender for Office 365 (Exchange Online Protection).
113
113
114
-
To Deactivate the workloads, repeat the steps above and select the workloads you want to deactivate. The status is set to **Not Active**.
114
+
To deactivate the workloads, repeat the steps in the previous section and select the workloads you want to deactivate. The status is set to **Not Active**.
115
115
116
116
If you deactivate a workload, the roles created and edited within Microsoft Defender XDR Unified RBAC are no longer in effect, and the previous permissions model is used instead.
0 commit comments