Skip to content

Commit aeee334

Browse files
authored
Update advanced hunting overview and permissions details
Updated the date for the advanced hunting overview and revised permissions sections for clarity and accuracy.
1 parent 059c550 commit aeee334

File tree

1 file changed

+27
-47
lines changed

1 file changed

+27
-47
lines changed

defender-xdr/advanced-hunting-overview.md

Lines changed: 27 additions & 47 deletions
Original file line numberDiff line numberDiff line change
@@ -22,7 +22,7 @@ appliesto:
2222
- Microsoft Defender XDR
2323
- Microsoft Sentinel in the Microsoft Defender portal
2424
search.appverid: met150
25-
ms.date: 09/09/2025
25+
ms.date: 11/19/2025
2626

2727
---
2828

@@ -55,54 +55,34 @@ For more information on advanced hunting in Microsoft Defender for Cloud Apps da
5555

5656
## Get access
5757

58-
To use advanced hunting or other [Microsoft Defender XDR](microsoft-365-defender.md) capabilities, you need an appropriate role in Microsoft Entra ID. [Read about required roles and permissions for advanced hunting](custom-roles.md).
59-
## Permissions required for Advanced Hunting
60-
6158
You need to be assigned permissions before you can run Advanced Hunting queries. You have the following options:
6259

63-
### **Microsoft Defender XDR Unified role-based access control (URBAC)**
64-
65-
**Read-only Advanced Hunting access (Email & Collaboration tables):**
66-
Membership assigned with the following Defender URBAC permission:
67-
68-
* **Security operations → Security data → Security data basic (read)**
69-
70-
This permission provides access to:
71-
72-
* **EmailEvents**
73-
* **EmailUrlInfo**
74-
* **EmailAttachmentInfo**
75-
* **UrlClickEvents**
76-
* **Email entity metadata**
77-
78-
### **Email & Collaboration (EOP / Defender for Office 365) permissions**
79-
80-
Membership in one of the following Email & Collaboration role groups provides access to email data tables in Advanced Hunting:
81-
82-
* **Security Administrator**
83-
* **Security Operator**
84-
* **Security Reader**
85-
86-
### **Exchange Online RBAC permissions**
87-
88-
To access EXO-related data surfaced in Advanced Hunting, users must be members of one of the following Exchange Online role groups:
89-
90-
* **View-Only Organization Management**
91-
* **View-Only Configuration**
92-
* **Security Reader**
93-
* **Global Reader**
94-
95-
### **Microsoft Entra permissions**
96-
97-
Membership in one of the following Microsoft Entra roles grants full read access to all Advanced Hunting data:
98-
99-
* **Global Administrator**
100-
* **Security Administrator**
101-
* **Security Reader**
102-
* **Global Reader**
103-
104-
Also, your access to endpoint data is determined by role-based access control (RBAC) settings in Microsoft Defender for Endpoint. [Read about managing access to Microsoft Defender XDR](m365d-permissions.md).
105-
60+
- [Microsoft Defender XDR Unified role based access control (URBAC)](manage-rbac.md):
61+
- **Read-only Advanced Hunting access (Email & Collaboration tables)**: Membership assigned with the **Security operations** \> **Security data** \> **Security data basic (read)** URBAC permission. This permission provides access to:
62+
- **EmailEvents**
63+
- **EmailUrlInfo**
64+
- **EmailAttachmentInfo**
65+
- **UrlClickEvents**
66+
- **Email entity metadata**
67+
68+
- [Email & collaboration permissions in the Microsoft Defender portal](/defender-office-365/mdo-portal-permissions): Membership in one of the following Email & Collaboration role groups provides access to email data tables in Advanced Hunting:
69+
- **Security Administrator**
70+
- **Security Operator**
71+
- **Security Reader**
72+
73+
- [Exchange Online permissions](/exchange/permissions-exo/permissions-exo): To access Exchange Online data surfaced in Advanced Hunting, users must be members of one of the following Exchange Online role groups:
74+
- **View-Only Organization Management**
75+
- **View-Only Configuration**
76+
- **Security Reader**
77+
- **Global Reader**
78+
79+
- [Microsoft Entra permissions](/entra/identity/role-based-access-control/manage-roles-portal): Membership in one of the following Microsoft Entra roles grants full read access to all Advanced Hunting data:
80+
- **Global Administrator**
81+
- **Security Administrator**
82+
- **Security Reader**
83+
- **Global Reader**
84+
85+
Also, your access to endpoint data is determined by role-based access control (RBAC) settings in Microsoft Defender for Endpoint. For more information, see [Manage access to Microsoft Defender XDR with Microsoft Entra global roles](m365d-permissions.md).
10686

10787
## Data freshness and update frequency
10888

0 commit comments

Comments
 (0)