Skip to content

Commit e3ca63a

Browse files
authored
Merge pull request #2571 from MicrosoftDocs/diannegali-updateurbacmde
adding MDE note for URBAC - publishing Feb 17, 2025
2 parents 746864c + 16a8721 commit e3ca63a

File tree

5 files changed

+41
-17
lines changed

5 files changed

+41
-17
lines changed

defender-xdr/activate-defender-rbac.md

Lines changed: 13 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -12,7 +12,7 @@ ms.collection:
1212
- tier3
1313
ms.custom:
1414
ms.topic: how-to
15-
ms.date: 11/17/2024
15+
ms.date: 02/16/2025
1616
ms.reviewer:
1717
search.appverid: met150
1818
---
@@ -32,7 +32,12 @@ search.appverid: met150
3232
- [Microsoft Defender for Cloud Apps](/defender-cloud-apps/)
3333
- [Microsoft Security Exposure Management](/security-exposure-management/)
3434

35-
For the Microsoft Defender XDR security portal to start enforcing the permissions and assignments configured in your new [custom roles](create-custom-rbac-roles.md) or [imported roles](import-rbac-roles.md), you must activate the Microsoft Defender XDR Unified RBAC model for some or all of your workloads.
35+
This article lists the steps to activate Defender workloads available in your environment to use the Microsoft Defender XDR Unified role-based access control (RBAC). Activate the Unified RBAC model for some or all of your workloads for the Microsoft Defender portal to start enforcing the permissions and assignments configured in your new [custom roles](create-custom-rbac-roles.md) or [imported roles](import-rbac-roles.md).
36+
37+
> [!IMPORTANT]
38+
> Starting February 16, 2025, the Microsoft Defender XDR Unified RBAC model will be the default permissions model for new Microsoft Defender Endpoint tenants. These new tenants won't have the capability to export roles and permissions from the current model.
39+
>
40+
> Defender for Endpoint tenants with roles and permissions assigned or exported prior to this date will maintain their current roles and permissions configuration.
3641
3742
<a name='activate-microsoft-365-defender-unified-rbac'></a>
3843

@@ -44,7 +49,7 @@ The following steps guide you on how to activate the Microsoft Defender XDR Unif
4449
2. [Activate in Microsoft Defender XDR settings](#activate-in-microsoft-365-defender-settings)
4550

4651
> [!IMPORTANT]
47-
> You must be a Global Administrator or Security Administrator in Microsoft Entra ID to perform this task. For more information on permissions, see [Permission pre-requisites](manage-rbac.md#permissions-prerequisites).
52+
> You must be a Global Administrator or Security Administrator in Microsoft Entra ID to perform this task. For more information on permissions, see [Permission prerequisites](manage-rbac.md#permissions-prerequisites).
4853
> Microsoft recommends that you use roles with the fewest permissions. This helps improve security for your organization. Global Administrator is a highly privileged role that should be limited to emergency scenarios when you can't use an existing role.
4954
5055
### Activate from the Permissions and roles page
@@ -60,12 +65,12 @@ You can activate your workloads in two ways from the Permissions and roles page:
6065
- Select **Activate workloads** on the banner above the list of roles to go directly to the **Activate workloads** screen.
6166
- You must activate each workload one by one. Once you select the individual toggle, you activate (or deactivate) that workload.
6267

63-
:::image type="content" source="/defender/media/defender/defender-activate-workloads.png" alt-text="Screenshot of the choose workloads to activate screen.":::
68+
:::image type="content" source="/defender/media/defender/defender-activate-workloads.png" alt-text="Screenshot of the page where you can choose workloads to activate.":::
6469

6570
> [!NOTE]
66-
> The **Activate workloads** button is only available when there is it at least one workload that's not active for Microsoft Defender XDR Unified RBAC.
71+
> The **Activate workloads** button is only available when there's it at least one workload that's not active for Microsoft Defender XDR Unified RBAC.
6772
> Microsoft Defender for Cloud is active by default with Microsoft Defender XDR Unified RBAC.
68-
> Defender XDR Unified RBAC is automatically active for Exposure Management access. Once a custom role with one of the Exposure Management permissions is created, it has an immediate impact on assigned users. There is no need to activate it.
73+
> Defender XDR Unified RBAC is automatically active for Exposure Management access. Once a custom role with one of the Exposure Management permissions is created, it has an immediate impact on assigned users. There's no need to activate it.
6974
>
7075
> To activate Exchange Online permissions in Microsoft Defender XDR Unified RBAC, Defender for Office 365 permissions must be active.
7176
@@ -98,15 +103,15 @@ Follow these steps to activate your workloads directly in Microsoft Defender XDR
98103
You have now successfully activated (or deactivated) that workload.
99104

100105
> [!NOTE]
101-
> The Microsoft Defender XDR Unified RBAC model only impacts the Microsoft Defender XDR security portal. It does not impact the [Microsoft Purview Compliance center](https://compliance.microsoft.com) or the [Exchange Admin Center](https://admin.exchange.microsoft.com).
106+
> The Microsoft Defender XDR Unified RBAC model only impacts the Microsoft Defender portal. It doesn't impact the [Microsoft Purview portal](https://purview.microsoft.com) or the [Exchange Admin Center](https://admin.exchange.microsoft.com).
102107
103108
<a name='deactivate-microsoft-365-defender-unified-rbac'></a>
104109

105110
## Deactivate Microsoft Defender XDR Unified RBAC
106111

107112
You can deactivate Microsoft Defender XDR Unified RBAC and revert to the individual RBAC models from Microsoft Defender for Endpoint, Microsoft Defender for Identity, and Microsoft Defender for Office 365 (Exchange Online Protection).
108113

109-
To Deactivate the workloads, repeat the steps above and select the workloads you want to deactivate. The status is set to **Not Active**.
114+
To deactivate the workloads, repeat the steps in the previous section and select the workloads you want to deactivate. The status is set to **Not Active**.
110115

111116
If you deactivate a workload, the roles created and edited within Microsoft Defender XDR Unified RBAC are no longer in effect, and the previous permissions model is used instead.
112117

defender-xdr/compare-rbac-roles.md

Lines changed: 6 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -12,7 +12,7 @@ ms.collection:
1212
- tier3
1313
ms.custom:
1414
ms.topic: reference
15-
ms.date: 11/17/2024
15+
ms.date: 02/16/2025
1616
ms.reviewer:
1717
search.appverid: met150
1818
---
@@ -42,6 +42,11 @@ This article describes how existing roles and permissions in Microsoft Defender
4242

4343
## Map Microsoft Defender XDR Unified RBAC permissions to existing RBAC permissions
4444

45+
> [!IMPORTANT]
46+
> Starting February 16, 2025, the Microsoft Defender XDR Unified RBAC model will be the default permissions model for new Microsoft Defender Endpoint tenants. These new tenants won't have the capability to export roles and permissions from the current model.
47+
>
48+
> Defender for Endpoint tenants with roles and permissions assigned or exported prior to this date will maintain their current roles and permissions configuration.
49+
4550
Use the tables in the following sections to learn more about how your existing individual RBAC role definitions map to your new Microsoft Defender XDR Unified RBAC roles:
4651

4752
1. [Map Defender for Endpoint and Defender Vulnerability Management permissions](#map-defender-for-endpoint-and-defender-vulnerability-management-permissions-to-the-microsoft-365-defender-rbac-permissions)

defender-xdr/edit-delete-rbac-roles.md

Lines changed: 11 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -12,12 +12,12 @@ ms.collection:
1212
- tier3
1313
ms.custom:
1414
ms.topic: how-to
15-
ms.date: 11/17/2024
15+
ms.date: 02/16/2025
1616
ms.reviewer:
1717
search.appverid: met150
1818
---
1919

20-
# Edit, delete and export roles in Microsoft Defender XDR Unified role-based access control (RBAC)
20+
# Edit, delete, and export roles in Microsoft Defender XDR Unified role-based access control (RBAC)
2121

2222
[!INCLUDE [Microsoft Defender XDR rebranding](../includes/microsoft-defender.md)]
2323

@@ -39,7 +39,7 @@ In Microsoft Defender XDR Unified role-based access control (RBAC), you can edit
3939
The following steps guide you on how to edit roles in Microsoft Defender XDR Unified RBAC:
4040

4141
> [!IMPORTANT]
42-
> You must be a Global Administrator or Security Administrator in Microsoft Entra ID, or have all the Authorization permissions assigned in Microsoft Defender XDR Unified RBAC to perform this task. For more information on permissions, see [Permission pre-requisites](manage-rbac.md#permissions-prerequisites).
42+
> You must be a Global Administrator or Security Administrator in Microsoft Entra ID, or have all the Authorization permissions assigned in Microsoft Defender XDR Unified RBAC to perform this task. For more information on permissions, see [Permission prerequisites](manage-rbac.md#permissions-prerequisites).
4343
> Microsoft recommends that you use roles with the fewest permissions to help improve security for your organization. Global Administrator is a highly privileged role that should be limited to emergency scenarios when you can't use an existing role.
4444
4545
1. Sign in to the [Microsoft Defender portal](https://security.microsoft.com) as global administrator or security administrator.
@@ -61,13 +61,18 @@ The following steps guide you on how to edit roles in Microsoft Defender XDR Uni
6161

6262
To delete roles in Microsoft Defender XDR Unified RBAC, select the role or roles you want to delete and select **Delete roles**.
6363

64-
If the workload is active, all assigned user permission are deleted by removing the role.
64+
If the workload is active, all assigned user permissions are deleted by removing the role.
6565

6666
> [!NOTE]
67-
> After deleting an imported role, the role won't be deleted from the individual product RBAC model. If needed, you can re-import it to the Microsoft Defender XDR Unified RBAC list of roles.
67+
> When an an imported role is deleted, the role isn't deleted from the individual product RBAC model. If needed, you can reimport it to the Microsoft Defender XDR Unified RBAC list of roles.
6868
6969
## Export roles
7070

71+
> [!IMPORTANT]
72+
> Starting February 16, 2025, the Microsoft Defender XDR Unified RBAC model will be the default permissions model for new Microsoft Defender Endpoint tenants. These new tenants won't have the capability to export roles and permissions from the current model.
73+
>
74+
> Defender for Endpoint tenants with roles and permissions assigned or exported before this date will maintain their current roles and permissions configuration.
75+
7176
The Export feature enables you to export the following roles data:
7277

7378
- Role name
@@ -86,7 +91,7 @@ The following steps guide you on how to export roles in Microsoft Defender XDR U
8691
> [!NOTE]
8792
> To export roles, you must be a Global Administrator or Security Administrator in Microsoft Entra ID, or have the **Authorization (manage)** permission assigned for all data sources in Microsoft Defender XDR Unified RBAC and have at least one workload activated for Defender XDR Unified RBAC.
8893
>
89-
>For more information on permissions, see [Permission pre-requisites](manage-rbac.md#permissions-prerequisites).
94+
>For more information on permissions, see [Permission prerequisites](manage-rbac.md#permissions-prerequisites).
9095
9196
1. Sign in to the [Microsoft Defender portal](https://security.microsoft.com) with the required roles or permissions.
9297

defender-xdr/manage-rbac.md

Lines changed: 6 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -12,7 +12,7 @@ ms.collection:
1212
- tier3
1313
ms.custom:
1414
ms.topic: overview
15-
ms.date: 11/17/2024
15+
ms.date: 02/16/2025
1616
ms.reviewer:
1717
search.appverid: met150
1818
---
@@ -36,6 +36,11 @@ Microsoft Defender XDR provides integrated threat protection, detection, and res
3636

3737
The Microsoft Defender XDR Unified role-based access control (RBAC) model provides a single permissions management experience that provides one central location for administrators to control user permissions across different security solutions.
3838

39+
> [!IMPORTANT]
40+
> Starting February 16, 2025, the Microsoft Defender XDR Unified RBAC model will be the default permissions model for new Microsoft Defender Endpoint tenants. These new tenants won't have the capability to export roles and permissions from the current model.
41+
>
42+
> Defender for Endpoint tenants with roles and permissions assigned or exported prior to this date will maintain their current roles and permissions configuration.
43+
3944
<a name='whats-supported-by-the-microsoft-365-defender-unified-rbac-model'></a>
4045

4146
## What's supported by the Microsoft Defender XDR Unified RBAC model

defender-xdr/whats-new-in-microsoft-defender-urbac.md

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -12,13 +12,17 @@ ms.collection:
1212
- m365-security-compliance
1313
- tier2
1414
ms.topic: conceptual
15-
ms.date: 11/17/2024
15+
ms.date: 02/16/2025
1616
---
1717

1818
# What's new in Microsoft Defender XDR Unified role-based access control (RBAC)
1919

2020
This article provides information about new features and important product updates for the latest release of Microsoft Defender XDR Unified role-based access control (RBAC).
2121

22+
## February 2025
23+
24+
Starting February 16, 2025, the Microsoft Defender XDR Unified RBAC model is the default permissions model for new Microsoft Defender Endpoint tenants. These new tenants won't have the capability to export roles and permissions from the current model. Defender for Endpoint tenants with roles and permissions assigned or exported prior to this date will maintain their current roles and permissions configuration.
25+
2226
## November 2024
2327

2428
### Microsoft Defender for Cloud Apps permissions are now integrated with Microsoft Defender XDR Unified role-based access control (RBAC)

0 commit comments

Comments
 (0)