You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: defender-xdr/activate-defender-rbac.md
+4-4Lines changed: 4 additions & 4 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -2,17 +2,17 @@
2
2
title: Activate Microsoft Defender XDR Unified role-based access control (RBAC)
3
3
description: Activate Microsoft Defender XDR Security unified role-based access control(RBAC)
4
4
ms.service: defender-xdr
5
-
ms.author: siosulli
5
+
ms.author: diannegali
6
6
author: siosulli
7
7
ms.localizationpriority: medium
8
-
manager: dansimp
8
+
manager: deniseb
9
9
audience: ITPro
10
10
ms.collection:
11
11
- m365-security
12
12
- tier3
13
13
ms.custom:
14
14
ms.topic: how-to
15
-
ms.date: 08/03/2023
15
+
ms.date: 06/13/2024
16
16
ms.reviewer:
17
17
search.appverid: met150
18
18
---
@@ -42,7 +42,7 @@ The following steps guide you on how to activate the Microsoft Defender XDR Unif
42
42
2.[Activate in Microsoft Defender XDR settings](#activate-in-microsoft-365-defender-settings)
43
43
44
44
> [!IMPORTANT]
45
-
> You must be a Global Administrator or Security Administrator in Microsoft Entra ID to perform this task. For more information on permissions, see [Permission pre-requisites](manage-rbac.md#permissions-pre-requisites).
45
+
> You must be a Global Administrator or Security Administrator in Microsoft Entra ID to perform this task. For more information on permissions, see [Permission pre-requisites](manage-rbac.md#permissions-prerequisites).
Copy file name to clipboardExpand all lines: defender-xdr/create-custom-rbac-roles.md
+4-4Lines changed: 4 additions & 4 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -2,17 +2,17 @@
2
2
title: Create custom roles with Microsoft Defender XDR Unified role-based access control (RBAC)
3
3
description: Create custom roles in Microsoft Defender XDR Security portal role-based access control (RBAC)
4
4
ms.service: defender-xdr
5
-
ms.author: siosulli
5
+
ms.author: diannegali
6
6
author: siosulli
7
7
ms.localizationpriority: medium
8
-
manager: dansimp
8
+
manager: deniseb
9
9
audience: ITPro
10
10
ms.collection:
11
11
- m365-security
12
12
- tier3
13
13
ms.custom:
14
14
ms.topic: how-to
15
-
ms.date: 08/03/2023
15
+
ms.date: 06/13/2024
16
16
ms.reviewer:
17
17
search.appverid: met150
18
18
---
@@ -35,7 +35,7 @@ search.appverid: met150
35
35
The following steps guide you on how to create custom roles in Microsoft Defender XDR Unified RBAC.
36
36
37
37
> [!IMPORTANT]
38
-
> You must be a Global Administrator or Security Administrator in Microsoft Entra ID, or have all the **Authorization** permissions assigned in Microsoft Defender XDR Unified RBAC to perform this task. For more information on permissions, see [Permission pre-requisites](manage-rbac.md#permissions-pre-requisites).
38
+
> You must be a Global Administrator or Security Administrator in Microsoft Entra ID, or have all the **Authorization** permissions assigned in Microsoft Defender XDR Unified RBAC to perform this task. For more information on permissions, see [Permission pre-requisites](manage-rbac.md#permissions-prerequisites).
39
39
40
40
1. Sign in to the [Microsoft Defender portal](https://security.microsoft.com).
41
41
2. In the navigation pane, select **Permissions**.
Copy file name to clipboardExpand all lines: defender-xdr/edit-delete-rbac-roles.md
+5-5Lines changed: 5 additions & 5 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -2,17 +2,17 @@
2
2
title: Edit or delete roles Microsoft Defender XDR Unified role-based access control (RBAC)
3
3
description: Edit or delete roles in Microsoft Defender XDR Security portal experiences using role-based access control (RBAC)
4
4
ms.service: defender-xdr
5
-
ms.author: siosulli
5
+
ms.author: diannegali
6
6
author: siosulli
7
7
ms.localizationpriority: medium
8
-
manager: dansimp
8
+
manager: deniseb
9
9
audience: ITPro
10
10
ms.collection:
11
11
- m365-security
12
12
- tier3
13
13
ms.custom:
14
14
ms.topic: how-to
15
-
ms.date: 08/03/2023
15
+
ms.date: 06/13/2024
16
16
ms.reviewer:
17
17
search.appverid: met150
18
18
---
@@ -37,7 +37,7 @@ In Microsoft Defender XDR Unified role-based access control (RBAC), you can edit
37
37
The following steps guide you on how to edit roles in Microsoft Defender XDR Unified RBAC:
38
38
39
39
> [!IMPORTANT]
40
-
> You must be a Global Administrator or Security Administrator in Microsoft Entra ID, or have all the **Authorization** permissions assigned in Microsoft Defender XDR Unified RBAC to perform this task. For more information on permissions, see [Permission pre-requisites](manage-rbac.md#permissions-pre-requisites).
40
+
> You must be a Global Administrator or Security Administrator in Microsoft Entra ID, or have all the **Authorization** permissions assigned in Microsoft Defender XDR Unified RBAC to perform this task. For more information on permissions, see [Permission pre-requisites](manage-rbac.md#permissions-prerequisites).
41
41
42
42
1. Sign in to the [Microsoft Defender portal](https://security.microsoft.com) as global administrator or security administrator.
43
43
2. In the navigation pane, select **Permissions**.
@@ -79,7 +79,7 @@ The following steps guide you on how to export roles in Microsoft Defender XDR U
79
79
>[!Note]
80
80
>To export roles, you must be a Global Administrator or Security Administrator in Microsoft Entra ID, or have the **Authorization (manage)** permission assigned for all data sources in Microsoft Defender XDR Unified RBAC and have at least one workload activated for Unified RBAC.
81
81
>
82
-
>For more information on permissions, see [Permission pre-requisites](manage-rbac.md#permissions-pre-requisites).
82
+
>For more information on permissions, see [Permission pre-requisites](manage-rbac.md#permissions-prerequisites).
83
83
84
84
1. Sign in to the [Microsoft Defender portal](https://security.microsoft.com) with the required roles or permissions.
85
85
2. In the navigation pane, select **Permissions**.
Copy file name to clipboardExpand all lines: defender-xdr/import-rbac-roles.md
+4-4Lines changed: 4 additions & 4 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -2,17 +2,17 @@
2
2
title: Import roles to Microsoft Defender XDR Unified role-based access control (RBAC)
3
3
description: Create custom Microsoft Defender XDR Security portal role-based access control (RBAC)
4
4
ms.service: defender-xdr
5
-
ms.author: siosulli
5
+
ms.author: diannegali
6
6
author: siosulli
7
7
ms.localizationpriority: medium
8
-
manager: dansimp
8
+
manager: deniseb
9
9
audience: ITPro
10
10
ms.collection:
11
11
- m365-security
12
12
- tier3
13
13
ms.custom:
14
14
ms.topic: how-to
15
-
ms.date: 08/03/2023
15
+
ms.date: 06/13/2024
16
16
ms.reviewer:
17
17
search.appverid: met150
18
18
---
@@ -44,7 +44,7 @@ Importing roles will migrate and maintain the roles with full parity in relation
44
44
The following steps guide you on how to import roles into Microsoft Defender XDR Unified RBAC:
45
45
46
46
> [!IMPORTANT]
47
-
> You must be a Global Administrator or Security Administrator in Microsoft Entra ID, or have all the **Authorization** permissions assigned in Microsoft Defender XDR Unified RBAC to perform this task. For more information on permissions, see [Permission pre-requisites](manage-rbac.md#permissions-pre-requisites).
47
+
> You must be a Global Administrator or Security Administrator in Microsoft Entra ID, or have all the **Authorization** permissions assigned in Microsoft Defender XDR Unified RBAC to perform this task. For more information on permissions, see [Permission pre-requisites](manage-rbac.md#permissions-prerequisites).
48
48
49
49
1. Sign in to the [Microsoft Defender portal](https://security.microsoft.com).
50
50
2. In the navigation pane, select **Permissions**.
Copy file name to clipboardExpand all lines: defender-xdr/manage-rbac.md
+7-4Lines changed: 7 additions & 4 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -3,7 +3,7 @@ title: Microsoft Defender XDR Unified role-based access control (RBAC)
3
3
description: Manage permissions and access to Microsoft Defender XDR Security portal experiences using unified role-based access control (RBAC).
4
4
ms.service: defender-xdr
5
5
ms.author: diannegali
6
-
author: diannegali
6
+
author: siosulli
7
7
ms.localizationpriority: medium
8
8
manager: deniseb
9
9
audience: ITPro
@@ -12,7 +12,7 @@ ms.collection:
12
12
- tier3
13
13
ms.custom:
14
14
ms.topic: overview
15
-
ms.date: 03/28/2024
15
+
ms.date: 06/13/2024
16
16
ms.reviewer:
17
17
search.appverid: met150
18
18
---
@@ -59,7 +59,7 @@ Centralized permissions management is supported for the following solutions:
59
59
60
60
This section provides useful information on what you need to know before you start using Microsoft Defender XDR Unified RBAC.
61
61
62
-
### Permissions pre-requisites
62
+
### Permissions prerequisites
63
63
64
64
- You must be a Global Administrator or Security Administrator in Microsoft Entra ID to:
65
65
- Gain initial access to [Permissions and roles](https://security.microsoft.com/mtp_roles) in the Microsoft Defender portal.
@@ -68,7 +68,10 @@ This section provides useful information on what you need to know before you sta
68
68
69
69
- Create a custom role that can grant access to security groups or individual users to manage roles and permissions in Microsoft Defender XDR unified RBAC. This removes the need for Microsoft Entra global roles to manage permissions. To do this, you need to assign the **Authorization** permission in Microsoft Defender XDR Unified RBAC. For details on how to assign the Authorization permission, see [Create a role to access and manage roles and permissions](create-custom-rbac-roles.md#create-a-role-to-access-and-manage-roles-and-permissions).
70
70
71
-
- The Microsoft Defender XDR security solution continues to respect existing Microsoft Entra global roles when you activate the Microsoft Defender XDR Unified RBAC model for some or all of your workloads, that is, Global Admins retain assigned admin privileges.
71
+
- The Microsoft Defender XDR security solution continues to respect existing Microsoft Entra global roles when you activate the Microsoft Defender XDR Unified RBAC model for some or all of your workloads, that is, Global Administrators retain assigned administrator privileges.
72
+
73
+
> [!IMPORTANT]
74
+
> Global Administrator is a highly privileged role that should be limited to scenarios when you can't use an existing role.
0 commit comments