Microsoft Defender XDR
Vulnerabilities and exposure

Activate Defender Rbac

In brief

The documentation now provides direct navigation and toggle-based steps for deactivating workloads, including confirmation and the resulting **Not Active** status.

What Defender admins need to know

Administrators have clearer instructions for managing workload activation in the Microsoft Defender portal.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

You can deactivate Microsoft Defender unified RBAC and revert to the individual RBAC models from Microsoft Defender for Endpoint, Microsoft Defender for Identity, Microsoft Sentinel, and Microsoft Defender for Office 365 (which includes the built-in security features for all cloud mailboxes).

To deactivate workloads:

  1. Sign in to the workloads, repeatMicrosoft Defender portal.
  2. In the steps in Activate Microsoft Defender unified RBAC andnavigation pane, select System > Permissions.
  3. Under Microsoft Defender XDR, select Roles.
  4. Select Workload settings at the workloadstop of the page.
  5. Turn off the toggle for each workload you want to deactivate.
  6. Select Activate on the confirmation message.

The status for deactivated workloads is set to Not Active.

If you deactivate a workload, the roles created and edited within Microsoft Defender unified RBAC are no longer in effect, and the previous permissions model is used instead.