Skip to content

Commit e17cbf0

Browse files
committed
fixing links
1 parent afcbcc5 commit e17cbf0

File tree

3 files changed

+3
-4
lines changed

3 files changed

+3
-4
lines changed

defender-xdr/custom-roles.md

Lines changed: 3 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -47,9 +47,9 @@ Each Microsoft Defender service has its own custom role management settings, wit
4747
1. In the navigation pane, select **Permissions**.
4848
1. Select the **Roles** link for the service where you want to create a custom role. For example, for Defender for Endpoint:
4949

50-
:::image type="content" source="media/custom-roles/custom-roles-endpoint.jpeg" alt-text="Screenshot of a Roles link for Defender for Endpoint.":::
50+
:::image type="content" source="./media/custom-roles/custom-roles-endpoint.png" alt-text="Screenshot of a Roles link for Defender for Endpoint.":::
5151

52-
## Reference to service-specific content
52+
## Required roles for Defender XDR services
5353

5454
Custom role names aren't connected to global roles in Microsoft Entra ID, even if similarly named. For example, a custom role named *Security Admin* in Microsoft Defender for Endpoint isn't connected to the global *Security Admin* role in Microsoft Entra ID.
5555

@@ -62,8 +62,7 @@ For Defender for Endpoint and Defender for Office, use custom roles as follows:
6262
|**Manage alerts and incidents** | Alert investigation |One of the following: <ul><li>Manage alerts<li>Security admin|
6363
|**Action center remediation** | Active remediation actions – security operations | Search and purge |
6464
|**Set custom detections** | Manage security settings | One of the following: <ul><li>Manage alerts<li>Security admin|
65-
|**Threat analytics** | For alert and incidents data: View data- security operations <br><br>For vulnerability management mitigations: View data - Threat and vulnerability management | For alerts and incidents data, one of the following: <ul><li>View-only Manage alerts<li>Manage alerts<li>Organization configuration<li>Audit logs<li>View-only audit logs<li>Security reader<li>Security admin<li>View-only recipients
66-
<br>For prevented email attempts, one of the following:<ul><li>Security reader<li>Security admin<li>View-only recipients |
65+
|**Threat analytics** | For alert and incidents data: View data- security operations <br><br>For vulnerability management mitigations: View data - Threat and vulnerability management | For alerts and incidents data, one of the following: <ul><li>View-only Manage alerts<li>Manage alerts<li>Organization configuration<li>Audit logs<li>View-only audit logs<li>Security reader<li>Security admin<li>View-only recipients<br>For prevented email attempts, one of the following:<ul><li>Security reader<li>Security admin<li>View-only recipients |
6766

6867
For other service information, see:
6968

-142 KB
Binary file not shown.
371 KB
Loading

0 commit comments

Comments
 (0)