Skip to content

Commit e4956b8

Browse files
authored
Merge branch 'main' into bms
2 parents e476618 + 8fb5007 commit e4956b8

File tree

2 files changed

+14
-5
lines changed

2 files changed

+14
-5
lines changed

exposure-management/prerequisites.md

Lines changed: 7 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -6,7 +6,7 @@ author: dlanger
66
manager: rayne-wiselman
77
ms.topic: overview
88
ms.service: exposure-management
9-
ms.date: 06/24/2024
9+
ms.date: 09/16/2024
1010
---
1111

1212
# Prerequisites and support
@@ -19,12 +19,14 @@ Security Exposure Management is currently in public preview.
1919

2020
## Permissions
2121

22-
Permissions are based on [Microsoft Entra ID RBAC](/entra/identity/role-based-access-control/custom-overview). You need a tenant with at least one Global Admin or Security Admin to create a Security Exposure Management workspace.
22+
Permissions are based on [Microsoft Entra ID Roles](/entra/identity/role-based-access-control/custom-overview). You need a tenant with at least one Global Admin or Security Admin to create a Security Exposure Management workspace.
2323

2424
- For full Security Exposure Management access, user roles need access to all Defender for Endpoint [device groups](/microsoft-365/security//defender-endpoint/machine-groups).
25-
- Users who have access restricted to specific device groups can:
26-
- Access global exposure insights data. They can't access specific device information and attack paths
27-
- Access the Security Exposure Management attack surface map and advanced hunting schemas (ExposureGraphNodes and ExposureGraphEdges) for the device groups to which they have access.
25+
- Users who have access restricted to some of the organization's device groups (and not to all), can:
26+
- Access global exposure insights data.
27+
- View affected assets under metrics, recommendations, events, and initiatives history only within users' scope
28+
- View devices in attack paths that are within the users' scope
29+
- Access the Security Exposure Management attack surface map and advanced hunting schemas (ExposureGraphNodes and ExposureGraphEdges) for the device groups to which they have access
2830

2931
### Permissions for Security Exposure Management tasks
3032

exposure-management/whats-new.md

Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -27,6 +27,13 @@ Security Exposure Management is currently in public preview.
2727
2828
## September 2024
2929

30+
### Enhanced visibility for scoped users
31+
32+
This change now allows users who have been granted access to only some of the organization's devices to see the list of affected assets in metrics, recommendations, events, and initiative history within their specific scope.
33+
34+
For more information, see [Prerequisites and support](prerequisites.md).
35+
36+
3037
### Proactively manage your security posture
3138

3239
Read how the *ExposureGraphEdges* and *ExposureGraphNodes* tables in Advanced Hunting helps your organizations proactively manage and understand your security posture by analyzing asset relationships and potential vulnerabilities.

0 commit comments

Comments
 (0)