You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: CloudAppSecurityDocs/activity-filters-queries.md
+4-1Lines changed: 4 additions & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -20,8 +20,11 @@ Below is a list of the activity filters that can be applied. Most filters suppor
20
20
- Activity objects – Search for the objects the activity was done on. This filter applies to files, folders, users, or app objects.
21
21
- Activity object ID - the ID of the object (file, folder, user, or app ID).
22
22
23
-
- Item - Enables you to search by the name or ID of any activity object (for example, user names, files, parameters, sites). For the **Activity object Item** filter, you can select whether to filter for items that **Contain**, **Equal**, or **Starts with** the specific item.
23
+
- Item - Enables you to search by the name or ID of any activity object (for example, user names, files, parameters, sites). For the **Activity object Item** filter, you can select whether to filter for items that **Contains**, **Equals**, or **Starts with** the specific item.
-[Microsoft Defender for Cloud Apps](/defender-cloud-apps/what-is-defender-for-cloud-apps)
33
34
34
35
In Microsoft Defender XDR Unified role-based access control (RBAC), you can edit and delete custom roles or roles that were imported from Defender for Endpoint, Defender for Identity, or Defender for Office 365.
35
36
@@ -39,7 +40,7 @@ The following steps guide you on how to edit roles in Microsoft Defender XDR Uni
39
40
40
41
> [!IMPORTANT]
41
42
> You must be a Global Administrator or Security Administrator in Microsoft Entra ID, or have all the Authorization permissions assigned in Microsoft Defender XDR Unified RBAC to perform this task. For more information on permissions, see [Permission pre-requisites](manage-rbac.md#permissions-prerequisites).
42
-
> Microsoft recommends that you use roles with the fewest permissions. This helps improve security for your organization. Global Administrator is a highly privileged role that should be limited to emergency scenarios when you can't use an existing role.
43
+
> Microsoft recommends that you use roles with the fewest permissions to help improve security for your organization. Global Administrator is a highly privileged role that should be limited to emergency scenarios when you can't use an existing role.
43
44
44
45
1. Sign in to the [Microsoft Defender portal](https://security.microsoft.com) as global administrator or security administrator.
45
46
@@ -49,7 +50,7 @@ The following steps guide you on how to edit roles in Microsoft Defender XDR Uni
49
50
50
51
4. Select the role you want to edit. You can only edit one role at a time.
51
52
52
-
5. Once selected, this opens a flyout pane where you can edit the role:
53
+
5. Once selected, a flyout pane opens where you can edit the role:
53
54
54
55
:::image type="content" source="/defender/media/defender/m365-defender-rbac-edit-roles.png" alt-text="Screenshot of the edit roles flyout page" lightbox="/defender/media/defender/m365-defender-rbac-edit-roles.png":::
55
56
@@ -60,7 +61,7 @@ The following steps guide you on how to edit roles in Microsoft Defender XDR Uni
60
61
61
62
To delete roles in Microsoft Defender XDR Unified RBAC, select the role or roles you want to delete and select **Delete roles**.
62
63
63
-
If the workload is active, by removing the role all assigned user permission will be deleted.
64
+
If the workload is active, all assigned user permission are deleted by removing the role.
64
65
65
66
> [!NOTE]
66
67
> After deleting an imported role, the role won't be deleted from the individual product RBAC model. If needed, you can re-import it to the Microsoft Defender XDR Unified RBAC list of roles.
@@ -76,7 +77,7 @@ The Export feature enables you to export the following roles data:
76
77
- The assigned data sources
77
78
- The assigned users or user groups
78
79
79
-
When a role has multiple assignments, each assignment will be represented as a separate row in the CSV file.
80
+
When a role has multiple assignments, each assignment is represented as a separate row in the CSV file.
80
81
81
82
The CSV also includes a snapshot of the Defender XDR Unified RBAC activation status for each workload available on the tenant.
82
83
@@ -97,7 +98,7 @@ The following steps guide you on how to export roles in Microsoft Defender XDR U
97
98
98
99
:::image type="content" source="/defender/media/defender/m365-defender-rbac-export-roles.png" alt-text="Screenshot of the export roles page" lightbox="/defender/media/defender/m365-defender-rbac-export-roles.png":::
99
100
100
-
A CSV file containing all the roles data will be generated and downloaded to the local machine.
101
+
A CSV file containing all the roles data is generated and downloaded to the local computer.
## Import roles to Microsoft Defender XDR Unified RBAC from individual RBAC models
36
37
37
38
You can import existing roles that are maintained as part of individual supported products in Microsoft Defender XDR (for example, Microsoft Defender for Endpoint) to the Microsoft Defender XDR Unified RBAC model.
38
39
39
-
Importing roles will migrate and maintain the roles with full parity in relation to their permissions and user assignments in the Microsoft Defender XDR Unified RBAC model.
40
+
Importing roles migrates and maintains the roles with full parity in relation to their permissions and user assignments in the Microsoft Defender XDR Unified RBAC model.
40
41
41
42
> [!NOTE]
42
43
> Once roles are migrated, you can modify the imported roles and change the level of permissions as needed.
@@ -45,7 +46,7 @@ The following steps guide you on how to import roles into Microsoft Defender XDR
45
46
46
47
> [!IMPORTANT]
47
48
> You must be a Global Administrator or Security Administrator in Microsoft Entra ID, or have all the **Authorization** permissions assigned in Microsoft Defender XDR Unified RBAC to perform this task. For more information on permissions, see [Permission pre-requisites](manage-rbac.md#permissions-prerequisites).
48
-
> Microsoft recommends that you use roles with the fewest permissions. This helps improve security for your organization. Global Administrator is a highly privileged role that should be limited to emergency scenarios when you can't use an existing role.
49
+
> Microsoft recommends that you use roles with the fewest permissions to help improve security for your organization. Global Administrator is a highly privileged role that should be limited to emergency scenarios when you can't use an existing role.
49
50
50
51
1. Sign in to the [Microsoft Defender portal](https://security.microsoft.com).
51
52
@@ -72,14 +73,14 @@ The following steps guide you on how to import roles into Microsoft Defender XDR
72
73
73
74
9. Select **Done** on the confirmation page.
74
75
75
-
Now that you have imported your roles you will be able to [View and edit roles](edit-delete-rbac-roles.md) and activate the workloads.
76
+
After importing your roles, you are be able to [View and edit roles](edit-delete-rbac-roles.md) and activate the workloads.
76
77
77
-
For the Microsoft Defender XDR security portal to start enforcing the permissions and assignments configured in your new or imported roles, you'll need to activate the new Defender XDR Unified RBAC model. For more information, see [Activate the workloads](activate-defender-rbac.md).
78
+
You need to activate the new Defender XDR Unified RBAC model to start enforcing the permissions and assignments configured in your new or imported roles within the Microsoft Defender portal. For more information, see [Activate the workloads](activate-defender-rbac.md).
78
79
79
-
Imported roles appear in the **Permissions and roles** list together with any custom roles you might have created. All imported roles will be marked as **Imported** in the description. Once you edit an imported role it will no longer be marked as **Imported**.
80
+
Imported roles appear in the **Permissions and roles** list together with any custom roles you created. All imported roles are marked as **Imported** in the description. Once you edit an imported role, it will no longer be marked as **Imported**.
80
81
81
82
> [!NOTE]
82
-
> You can import roles as frequently as required. After you edit an imported role, the changes will not affect the original role where it was imported from. This means you have the option to delete an imported role and re-import the original role, if required. If you import the same role twice you will create a duplicate role.
83
+
> You can import roles as frequently as required. After you edit an imported role, the changes will not affect the original role where it was imported from. This means you have the option to delete an imported role and re-import the original role, if necessary. If you import the same role twice, you create a duplicate role.
-[Microsoft Defender for Cloud Apps](/defender-cloud-apps/what-is-defender-for-cloud-apps)
33
34
34
35
Microsoft Defender XDR provides integrated threat protection, detection, and response across endpoints, email, identities, applications, and data within a single portal. Controlling a user's permissions around their access to view data or complete tasks is essential for organizations to minimize the risks associated with unauthorized access.
35
36
@@ -50,11 +51,10 @@ Centralized permissions management is supported for the following solutions:
50
51
|Microsoft Defender for Identity|Full support for all identity data and actions. </br></br> **Note:** Defender for Identity experiences also adhere to permissions granted from [Microsoft Defender for Cloud Apps](https://security.microsoft.com/cloudapps/permissions/roles). For more information, see [Microsoft Defender for Identity role groups](https://go.microsoft.com/fwlink/?linkid=2202729).|
51
52
|Microsoft Defender for Cloud|Support access management for all Defender for Cloud data that is available in Microsoft Defender portal.|
52
53
|Microsoft Security Exposure Management|Full support for all Exposure Management data and actions, including Microsoft Secure Score data.|
54
+
|Microsoft Defender for Cloud Apps|Full support for all cloud apps data and actions. </br></br> **Note:** Once Unified RBAC is activated, some built-in scoped roles will no longer be supported. For more information, see [Map Microsoft Defender for Cloud Apps permissions to the Microsoft Defender XDR Unified RBAC permissions](compare-rbac-roles.md#map-microsoft-defender-for-cloud-apps-permissions-to-the-microsoft-defender-xdr-unified-rbac-permissions).|
53
55
54
56
> [!NOTE]
55
57
> Scenarios and experiences controlled by Compliance permissions are still managed in the Microsoft Purview compliance portal.
56
-
>
57
-
> This offering isn't currently available for Microsoft Defender for CloudApps.
0 commit comments