Skip to content

Commit 31a16d2

Browse files
authored
Update date and add role limitations
1 parent 0617407 commit 31a16d2

File tree

1 file changed

+16
-2
lines changed

1 file changed

+16
-2
lines changed

defender-office-365/attack-simulation-training-get-started.md

Lines changed: 16 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -19,7 +19,7 @@ ms.custom:
1919
- seo-marvel-apr2020
2020
description: Admins can learn how to use Attack simulation training to run simulated phishing and password attacks in their Microsoft 365 E5 or Microsoft Defender for Office 365 Plan 2 organizations.
2121
ms.service: defender-office-365
22-
ms.date: 12/04/2024
22+
ms.date: 02/04/2025
2323
appliesto:
2424
- ✅ <a href="https://learn.microsoft.com/defender-office-365/mdo-about#defender-for-office-365-plan-1-vs-plan-2-cheat-sheet" target="_blank">Microsoft Defender for Office 365 Plan 2</a>
2525
---
@@ -55,12 +55,26 @@ Watch this short video to learn more about Attack simulation training.
5555
- **Security Administrator**
5656
- **Attack Simulation Administrators**²: Create and manage all aspects of attack simulation campaigns.
5757
- **Attack Payload Author**²: Create attack payloads that an admin can initiate later.
58-
- **Security Operator and Security Reader**: View all aspects of attack simulation campaigns. Cannot create or manage all aspects of attack simulation campaigns (e.g. creating or editing simulations, training campaigns, simulation automation, payload automation, content (e.g. tenant payloads, notifications) or changing global settings).
58+
- **Security Operator and Security Reader**³: View all aspects of attack simulation campaigns.
5959

6060
> [!IMPORTANT]
6161
> ¹ Microsoft recommends that you use roles with the fewest permissions. Using lower permissioned accounts helps improve security for your organization. Global Administrator is a highly privileged role that should be limited to emergency scenarios when you can't use an existing role.
6262
>
6363
> ² Adding users to this role group in [Email & collaboration permissions in the Microsoft Defender portal](mdo-portal-permissions.md) is currently unsupported.
64+
>
65+
> Members of Attack Payload Author have the following limitations in attack simulation training:
66+
>
67+
> - They can't create or edit simulations, training campaigns, simulation automations, or payload automations.
68+
> - They can't change global settings.
69+
> - They can't change content (for example, notifications), but they can change payloads.
70+
> - They can't view tenant simulation reports, aggregate reports, simulation automation records, or payload automation records.
71+
>
72+
> ³ Members of Security Operator and Security Reader have the following limitations in attack simulation training:
73+
>
74+
> - They can't create or edit simulations, training campaigns, simulation automations, or payload automations.
75+
> - They can't change global settings.
76+
> - They can't change content (for example, tenant payloads or notifications).
77+
> - They can access data through read APIs with user scope, but they can't use write APIs.
6478
6579
Currently, [Microsoft Defender XDR Unified role based access control (RBAC)](/defender-xdr/manage-rbac) isn't supported.
6680

0 commit comments

Comments
 (0)