You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: defender-endpoint/threat-analytics.md
+7-5Lines changed: 7 additions & 5 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -59,14 +59,16 @@ Each report provides an analysis of a tracked threat and extensive guidance on h
59
59
60
60
The following table outlines the roles and permissions required to access threat analytics. Roles defined in the following table refer to custom roles in individual portals and aren't connected to global roles in Microsoft Entra ID, even if similarly named.
61
61
62
-
|**One of the following roles are required for Microsoft Defender XDR**|**One of the following roles are required for Defender for Endpoint**|**One of the following roles are required for Defender for Office 365**|**One of the following roles are required for Defender for Cloud Apps**|
63
-
|---------|---------|---------|---------|
64
-
| Threat Analytics | Alerts and incidents data: <ul><li>View data- security operations</li></ul>Defender Vulnerability Management mitigations:<ul><li>View data - Threat and vulnerability management</li></ul> | Alerts and incidents data:<ul> <li>View-only manage alerts</li> <li>Manage alerts</li> <li>Organization configuration</li><li>Audit logs</li> <li>View-only audit logs</li><li>Security reader</li> <li>Security admin</li><li>View-only recipients</li> </ul> Prevented email attempts: <ul><li>Security reader</li> <li>Security admin</li><li>View-only recipients</li> | Not available for Defender for Cloud Apps or MDI users |
62
+
|**One of the following roles are required for Microsoft Defender XDR**|**One of the following roles are required for Microsoft Defender for Endpoint**|**One of the following roles are required for Microsoft Defender for Office 365**|**One of the following roles are required for Microsoft Defender for Cloud Apps**|**One of the following roles are required for Microsoft Defender for Cloud**|
| Threat Analytics | Alerts and incidents data: <ul><li>View data- security operations</li></ul>Defender Vulnerability Management mitigations:<ul><li>View data - Threat and vulnerability management</li></ul> | Alerts and incidents data:<ul> <li>View-only manage alerts</li> <li>Manage alerts</li> <li>Organization configuration</li><li>Audit logs</li> <li>View-only audit logs</li><li>Security reader</li> <li>Security admin</li><li>View-only recipients</li> </ul> Prevented email attempts: <ul><li>Security reader</li> <li>Security admin</li><li>View-only recipients</li> | Not available for Defender for Cloud Apps or Microsoft Defender for Identity users| <ul><li>Global admin</li><li>Security admin</li></ul>|
65
65
66
66
>[!IMPORTANT]
67
67
> You'll have visibility to all threat analytics reports even if you have just one of the products and its corresponding roles described in the previous table. However, you're required to have each product and roles to see that product’s specific incidents, assets, exposure, and recommended actions associated with the threat.
68
68
69
-
[Learn more about custom roles in role-based access control for Microsoft Defender XDR](/defender-xdr/custom-roles)
69
+
Learn more:
70
+
-[Custom roles in role-based access control for Microsoft Defender XDR](/defender-xdr/custom-roles)
71
+
-[Microsoft Defender XDR Unified role-based access control (RBAC)](/defender-xdr/manage-rbac)
70
72
71
73
72
74
## View the threat analytics dashboard
@@ -159,7 +161,7 @@ The **Related incidents** tab provides the list of all incidents related to the
159
161
:::image type="content" source="media/ta-related-incidents.png" alt-text="Screenshot of the related incidents section of a threat analytics report." lightbox="media/ta-related-incidents.png":::
160
162
161
163
> [!NOTE]
162
-
> Incidents and alerts associated with the threat are sourced from Microsoft Defender for Endpoint, Microsoft Defender for Identity, Microsoft Defender for Office 365, Microsoft Defender for Cloud Apps, and Microsoft Defender for Cloud.
164
+
> Incidents and alerts associated with the threat are sourced from Defender for Endpoint, Defender for Identity, Defender for Office 365, Defender for Cloud Apps, and Defender for Cloud.
163
165
164
166
### Impacted assets: Get list of impacted devices, users, mailboxes, apps, and cloud resources
Copy file name to clipboardExpand all lines: defender-xdr/threat-analytics.md
+7-5Lines changed: 7 additions & 5 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -58,14 +58,16 @@ Each report provides an analysis of a tracked threat and extensive guidance on h
58
58
## Required roles and permissions
59
59
The following table outlines the roles and permissions required to access Threat Analytics. Roles defined in the following table refer to custom roles in individual portals and aren't connected to global roles in Microsoft Entra ID, even if similarly named.
60
60
61
-
|**One of the following roles are required for Microsoft Defender XDR**|**One of the following roles are required for Defender for Endpoint**|**One of the following roles are required for Defender for Office 365**|**One of the following roles are required for Defender for Cloud Apps**|
62
-
|---------|---------|---------|---------|
63
-
| Threat Analytics | Alerts and incidents data: <ul><li>View data- security operations</li></ul>Defender Vulnerability Management mitigations:<ul><li>View data - Threat and vulnerability management</li></ul> | Alerts and incidents data:<ul> <li>View-only manage alerts</li> <li>Manage alerts</li> <li>Organization configuration</li><li>Audit logs</li> <li>View-only audit logs</li><li>Security reader</li> <li>Security admin</li><li>View-only recipients</li> </ul> Prevented email attempts: <ul><li>Security reader</li> <li>Security admin</li><li>View-only recipients</li> | Not available for Defender for Cloud Apps or MDI users |
61
+
|**One of the following roles are required for Microsoft Defender XDR**|**One of the following roles are required for Microsoft Defender for Endpoint**|**One of the following roles are required for Microsoft Defender for Office 365**|**One of the following roles are required for Microsoft Defender for Cloud Apps**|**One of the following roles are required for Microsoft Defender for Cloud**|
| Threat Analytics | Alerts and incidents data: <ul><li>View data- security operations</li></ul>Defender Vulnerability Management mitigations:<ul><li>View data - Threat and vulnerability management</li></ul> | Alerts and incidents data:<ul> <li>View-only manage alerts</li> <li>Manage alerts</li> <li>Organization configuration</li><li>Audit logs</li> <li>View-only audit logs</li><li>Security reader</li> <li>Security admin</li><li>View-only recipients</li> </ul> Prevented email attempts: <ul><li>Security reader</li> <li>Security admin</li><li>View-only recipients</li> | Not available for Defender for Cloud Apps or Microsoft Defender for Identity users| <ul><li>Global admin</li><li>Security admin</li></ul>|
64
64
65
65
>[!IMPORTANT]
66
66
> You'll have visibility to all threat analytics reports even if you have just one of the products and its corresponding roles described in the previous table. However, you're required to have each product and roles to see that product’s specific incidents, assets, exposure, and recommended actions associated with the threat.
67
67
68
-
[Learn more about custom roles in role-based access control for Microsoft Defender XDR](custom-roles.md)
68
+
Learn more:
69
+
-[Custom roles in role-based access control for Microsoft Defender XDR](custom-roles.md)
70
+
-[Microsoft Defender XDR Unified role-based access control (RBAC)](manage-rbac.md)
69
71
70
72
## View the threat analytics dashboard
71
73
@@ -159,7 +161,7 @@ The **Related incidents** tab provides the list of all incidents related to the
159
161
:::image type="content" source="/defender/media/threat-analytics/ta_related_incidents_mtp.png" alt-text="Screenshot of the related incidents section of a threat analytics report." lightbox="/defender/media/threat-analytics/ta_related_incidents_mtp.png":::
160
162
161
163
> [!NOTE]
162
-
> Incidents and alerts associated with the threat are sourced from Microsoft Defender for Endpoint, Microsoft Defender for Identity, Microsoft Defender for Office 365, Microsoft Defender for Cloud Apps, and Microsoft Defender for Cloud.
164
+
> Incidents and alerts associated with the threat are sourced from Defender for Endpoint, Defender for Identity, Defender for Office 365, Defender for Cloud Apps, and Defender for Cloud.
163
165
164
166
### Impacted assets: Get list of impacted devices, users, mailboxes, apps, and cloud resources
0 commit comments