Skip to content

Commit dab7cff

Browse files
committed
updated RBAC table
1 parent 6b7e525 commit dab7cff

File tree

2 files changed

+14
-10
lines changed

2 files changed

+14
-10
lines changed

defender-endpoint/threat-analytics.md

Lines changed: 7 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -59,14 +59,16 @@ Each report provides an analysis of a tracked threat and extensive guidance on h
5959

6060
The following table outlines the roles and permissions required to access threat analytics. Roles defined in the following table refer to custom roles in individual portals and aren't connected to global roles in Microsoft Entra ID, even if similarly named.
6161

62-
| **One of the following roles are required for Microsoft Defender XDR** | **One of the following roles are required for Defender for Endpoint** | **One of the following roles are required for Defender for Office 365** | **One of the following roles are required for Defender for Cloud Apps** |
63-
|---------|---------|---------|---------|
64-
| Threat Analytics | Alerts and incidents data: <ul><li>View data- security operations</li></ul>Defender Vulnerability Management mitigations:<ul><li>View data - Threat and vulnerability management</li></ul> | Alerts and incidents data:<ul> <li>View-only manage alerts</li> <li>Manage alerts</li> <li>Organization configuration</li><li>Audit logs</li> <li>View-only audit logs</li><li>Security reader</li> <li>Security admin</li><li>View-only recipients</li> </ul> Prevented email attempts: <ul><li>Security reader</li> <li>Security admin</li><li>View-only recipients</li> | Not available for Defender for Cloud Apps or MDI users |
62+
| **One of the following roles are required for Microsoft Defender XDR** | **One of the following roles are required for Microsoft Defender for Endpoint** | **One of the following roles are required for Microsoft Defender for Office 365** | **One of the following roles are required for Microsoft Defender for Cloud Apps** | **One of the following roles are required for Microsoft Defender for Cloud** |
63+
|---------|---------|---------|---------|---------|
64+
| Threat Analytics | Alerts and incidents data: <ul><li>View data- security operations</li></ul>Defender Vulnerability Management mitigations:<ul><li>View data - Threat and vulnerability management</li></ul> | Alerts and incidents data:<ul> <li>View-only manage alerts</li> <li>Manage alerts</li> <li>Organization configuration</li><li>Audit logs</li> <li>View-only audit logs</li><li>Security reader</li> <li>Security admin</li><li>View-only recipients</li> </ul> Prevented email attempts: <ul><li>Security reader</li> <li>Security admin</li><li>View-only recipients</li> | Not available for Defender for Cloud Apps or Microsoft Defender for Identity users | <ul><li>Global admin</li><li>Security admin</li></ul> |
6565

6666
>[!IMPORTANT]
6767
> You'll have visibility to all threat analytics reports even if you have just one of the products and its corresponding roles described in the previous table. However, you're required to have each product and roles to see that product’s specific incidents, assets, exposure, and recommended actions associated with the threat.
6868
69-
[Learn more about custom roles in role-based access control for Microsoft Defender XDR](/defender-xdr/custom-roles)
69+
Learn more:
70+
- [Custom roles in role-based access control for Microsoft Defender XDR](/defender-xdr/custom-roles)
71+
- [Microsoft Defender XDR Unified role-based access control (RBAC)](/defender-xdr/manage-rbac)
7072

7173

7274
## View the threat analytics dashboard
@@ -159,7 +161,7 @@ The **Related incidents** tab provides the list of all incidents related to the
159161
:::image type="content" source="media/ta-related-incidents.png" alt-text="Screenshot of the related incidents section of a threat analytics report." lightbox="media/ta-related-incidents.png":::
160162

161163
> [!NOTE]
162-
> Incidents and alerts associated with the threat are sourced from Microsoft Defender for Endpoint, Microsoft Defender for Identity, Microsoft Defender for Office 365, Microsoft Defender for Cloud Apps, and Microsoft Defender for Cloud.
164+
> Incidents and alerts associated with the threat are sourced from Defender for Endpoint, Defender for Identity, Defender for Office 365, Defender for Cloud Apps, and Defender for Cloud.
163165
164166
### Impacted assets: Get list of impacted devices, users, mailboxes, apps, and cloud resources
165167

defender-xdr/threat-analytics.md

Lines changed: 7 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -58,14 +58,16 @@ Each report provides an analysis of a tracked threat and extensive guidance on h
5858
## Required roles and permissions
5959
The following table outlines the roles and permissions required to access Threat Analytics. Roles defined in the following table refer to custom roles in individual portals and aren't connected to global roles in Microsoft Entra ID, even if similarly named.
6060

61-
| **One of the following roles are required for Microsoft Defender XDR** | **One of the following roles are required for Defender for Endpoint** | **One of the following roles are required for Defender for Office 365** | **One of the following roles are required for Defender for Cloud Apps** |
62-
|---------|---------|---------|---------|
63-
| Threat Analytics | Alerts and incidents data: <ul><li>View data- security operations</li></ul>Defender Vulnerability Management mitigations:<ul><li>View data - Threat and vulnerability management</li></ul> | Alerts and incidents data:<ul> <li>View-only manage alerts</li> <li>Manage alerts</li> <li>Organization configuration</li><li>Audit logs</li> <li>View-only audit logs</li><li>Security reader</li> <li>Security admin</li><li>View-only recipients</li> </ul> Prevented email attempts: <ul><li>Security reader</li> <li>Security admin</li><li>View-only recipients</li> | Not available for Defender for Cloud Apps or MDI users |
61+
| **One of the following roles are required for Microsoft Defender XDR** | **One of the following roles are required for Microsoft Defender for Endpoint** | **One of the following roles are required for Microsoft Defender for Office 365** | **One of the following roles are required for Microsoft Defender for Cloud Apps** | **One of the following roles are required for Microsoft Defender for Cloud** |
62+
|---------|---------|---------|---------|---------|
63+
| Threat Analytics | Alerts and incidents data: <ul><li>View data- security operations</li></ul>Defender Vulnerability Management mitigations:<ul><li>View data - Threat and vulnerability management</li></ul> | Alerts and incidents data:<ul> <li>View-only manage alerts</li> <li>Manage alerts</li> <li>Organization configuration</li><li>Audit logs</li> <li>View-only audit logs</li><li>Security reader</li> <li>Security admin</li><li>View-only recipients</li> </ul> Prevented email attempts: <ul><li>Security reader</li> <li>Security admin</li><li>View-only recipients</li> | Not available for Defender for Cloud Apps or Microsoft Defender for Identity users | <ul><li>Global admin</li><li>Security admin</li></ul> |
6464

6565
>[!IMPORTANT]
6666
> You'll have visibility to all threat analytics reports even if you have just one of the products and its corresponding roles described in the previous table. However, you're required to have each product and roles to see that product’s specific incidents, assets, exposure, and recommended actions associated with the threat.
6767
68-
[Learn more about custom roles in role-based access control for Microsoft Defender XDR](custom-roles.md)
68+
Learn more:
69+
- [Custom roles in role-based access control for Microsoft Defender XDR](custom-roles.md)
70+
- [Microsoft Defender XDR Unified role-based access control (RBAC)](manage-rbac.md)
6971

7072
## View the threat analytics dashboard
7173

@@ -159,7 +161,7 @@ The **Related incidents** tab provides the list of all incidents related to the
159161
:::image type="content" source="/defender/media/threat-analytics/ta_related_incidents_mtp.png" alt-text="Screenshot of the related incidents section of a threat analytics report." lightbox="/defender/media/threat-analytics/ta_related_incidents_mtp.png":::
160162

161163
> [!NOTE]
162-
> Incidents and alerts associated with the threat are sourced from Microsoft Defender for Endpoint, Microsoft Defender for Identity, Microsoft Defender for Office 365, Microsoft Defender for Cloud Apps, and Microsoft Defender for Cloud.
164+
> Incidents and alerts associated with the threat are sourced from Defender for Endpoint, Defender for Identity, Defender for Office 365, Defender for Cloud Apps, and Defender for Cloud.
163165
164166
### Impacted assets: Get list of impacted devices, users, mailboxes, apps, and cloud resources
165167

0 commit comments

Comments
 (0)