Skip to content

Commit e93779d

Browse files
Merge branch 'main' into main
2 parents 5e7582e + f0b4f4c commit e93779d

File tree

1 file changed

+1
-32
lines changed

1 file changed

+1
-32
lines changed

CloudAppSecurityDocs/activity-filters-queries.md

Lines changed: 1 addition & 32 deletions
Original file line numberDiff line numberDiff line change
@@ -135,7 +135,7 @@ Defender for Cloud Apps also provides you with **Suggested queries**. Suggested
135135
- Successful log in - Filters all your activities to display only those activities that involve successful sign-ins, including impersonate action, impersonate sign-in, single sign-o sign-ins, and sign-in from a new device.
136136

137137
![query activities.](media/queries-activity.png)
138-
138+
139139
Additionally, you can use the suggested queries as a starting point for a new query. First, select one of the suggested queries. Then, make changes as needed and finally select **Save as** to create a new **Saved query**.
140140

141141
### Query activities six months back
@@ -184,37 +184,6 @@ Reports that include private activities are marked with an Eye icon in the repor
184184

185185
![eye-icon](media/activity-filters-queries/eye-icon-to-indicate-private-report.png)
186186

187-
> [!NOTE]
188-
>Exporting and viewing activity data up to six months back is restricted to specific roles with elevated permissions.
189-
190-
The following roles are supported:
191-
192-
- `INVITED_ADMIN`
193-
194-
- `GLOBAL_ADMINISTRATOR`
195-
196-
- `SECURITY_ADMINISTRATOR`
197-
198-
- `MCAS_ADMINISTRATOR`
199-
200-
- `DISCOVERY_ADMIN`
201-
202-
- `SECURITY_OPERATOR`
203-
204-
- `COMPLIANCE_ADMIN`
205-
206-
- `SECURITY_READER`
207-
208-
- `GLOBAL_READER`
209-
210-
- `URBAC_ROLES_GLOBAL_ADMINISTRATOR`
211-
212-
- `URBAC_ROLES_COMPLIANCE_ADMINISTRATOR`
213-
214-
- `URBAC_ROLES_SECURITY_READER`
215-
216-
- `URBAC_ROLES_SECURITY_OPERATOR`
217-
218187
## Next steps
219188

220189
> [!div class="nextstepaction"]

0 commit comments

Comments
 (0)