Skip to content

Commit 92ccbe4

Browse files
authored
Update manage-security-policies.md
Update for accuracy regarding the permissions needed to manage polices- We are saying security admin, but in reality its- Core security settings (manage) + being exposed to all devices
1 parent a22da2e commit 92ccbe4

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

defender-endpoint/manage-security-policies.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -34,7 +34,7 @@ Use security policies to manage security settings on devices. As a Security Admi
3434
You'll find endpoint security policies under **Endpoints** > **Configuration management** > **Endpoint security policies**.
3535

3636
> [!NOTE]
37-
> The **Endpoint Security Policies** page in the Microsoft Defender portal is available only for [users with the Security Administrator role assigned](assign-portal-access.md). Any other user role, such as Security Reader, cannot access the portal. When a user has the required permissions to view policies in the Microsoft Defender portal, the data is presented based on Intune permissions. If the user is in scope for Intune role-based access control, it applies to the list of policies presented in the Microsoft Defender portal. We recommend granting security administrators with the [Intune built-in role, "Endpoint Security Manager"](/mem/intune/fundamentals/role-based-access-control#built-in-roles) to effectively align the level of permissions between Intune and the Microsoft Defender portal.
37+
> The **Endpoint Security Policies** page in the Microsoft Defender portal is available only for users who have access to all devices and possess "Core security settings (manage)" permissions. Any user role without these permissions, such as Security Reader, cannot access the portal. When a user has the required permissions to view policies in the Microsoft Defender portal, the data is presented based on Intune permissions. If the user is in scope for Intune role-based access control, it applies to the list of policies presented in the Microsoft Defender portal. We recommend granting security administrators with the [Intune built-in role, "Endpoint Security Manager"](/mem/intune/fundamentals/role-based-access-control#built-in-roles) to effectively align the level of permissions between Intune and the Microsoft Defender portal.
3838
3939
:::image type="content" source="./media/endpoint-security-policies.png" alt-text="Managing Endpoint security policies in the Microsoft Defender portal":::
4040

0 commit comments

Comments
 (0)