Skip to content

Commit 85c853a

Browse files
committed
gadi changes
1 parent bb66092 commit 85c853a

File tree

1 file changed

+3
-3
lines changed

1 file changed

+3
-3
lines changed

exposure-management/prerequisites.md

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -20,8 +20,7 @@ Security Exposure Management is currently in public preview.
2020
## Permissions
2121

2222
> [!IMPORTANT]
23-
> Microsoft recommends that you use roles with the fewest permissions. This helps improve security for your organization.
24-
> Global Administrator is a highly privileged role that should be limited to emergency scenarios when you can't use an existing role.
23+
> Microsoft recommends that you use roles with the fewest permissions. This helps improve security for your organization. Global Administrator is a highly privileged role that should be limited to emergency scenarios when you can't use an existing role.
2524
2625
## Manage permissions with Microsoft Defender XDR Unified role-based access control (RBAC)
2726

@@ -53,7 +52,8 @@ Users with restricted access to some of the organization's device groups can:
5352
- Access the Security Exposure Management attack surface map and advanced hunting schemas (ExposureGraphNodes and ExposureGraphEdges) for the device groups they have access to.
5453

5554
> [!NOTE]
56-
> Access with manage permissions to **Critical asset management**, under **System \ Settings \ Microsoft Defender XDR** requires users to have access to all Defender for Endpoint device groups.
55+
> Access with manage permissions to **Critical asset management**, under **System> Settings> Microsoft Defender XDR** requires users to have access to all Defender for Endpoint device groups.
56+
5757
## Access with Microsoft Entra ID roles
5858

5959
An alternative to managing access with Microsoft Defender XDR Unified RBAC permissions, access to Microsoft Security Exposure Management data and actions is also possible with [Microsoft Entra ID Roles](/entra/identity/role-based-access-control/custom-overview). You need a tenant with at least one Global Admin or Security Admin to create a Security Exposure Management workspace.

0 commit comments

Comments
 (0)