Microsoft Defender for Cloud Apps
Cloud and workloads

Configure admin access | Microsoft Defender for Cloud Apps

In brief

The guide now presents prerequisites for accessing and editing Manage admin access, clarifies steps for adding admins and MSSPs, and states that Microsoft Entra roles already granting Full access cannot be overridden.

What Defender admins need to know

Admins should verify their role before managing access and account for the Full access override limitation when assigning permissions.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.


title: Configure admin access | Microsoft Defender for Cloud Apps description: Set up role-based administrator access in Defender for Cloud Apps and understand how Microsoft Entra ID and Microsoft 365 roles affect permissions. ms.date: 06/16/07/03/2026 ms.topic: how-to ms.reviewer: Naama-Goldbart ms.custom:

  • msecd-doc-authoring-10141016
  • sfi-ga-blocked
  • sfi-image-nochange ai-usage: ai-assisted |Security reader|Has read-only permissions and can create API access tokens. These admins are restricted from doing the following actions:
      Create policies or edit and change existing ones
    • Performing any governance actions
    • Uploading discovery logs
    • Banning or approving non-Microsoft apps
    • Accessing and viewing the IP address range settings page
    • Accessing and viewing any system settings pages
    • Accessing and viewing the Discovery settings
    • Accessing and viewing the App connectors page
    • Accessing and viewing the Governance log
    • Accessing and viewing the Manage snapshot reports page
    | |Global reader|Has full read-only access to all aspects of Defender for Cloud Apps. Can't change any settings or take any actions.|

* Microsoft recommends that you use roles with the fewest permissions. This strategyUsing least-privilege roles helps improve security for your organization. Global Administrator is a highly privileged role that should be limited to emergency scenarios when you can't use an existing role.

|Cloud Discovery report admin|

  • Settings: System settings - View only; Cloud discovery settings - View all (anonymization permissions depend on whether it was allowed during role assignment)
  • Cloud discovery activity - read permissions only
  • Alerts – view only alerts related to the relevant cloud discovery report
  • Policies - Can view all policies and can create only cloud discovery policies, without the possibility to govern application (tagging, sanction and unsanctioned)
  • Activities page - No permissions
  • Accounts page - No permissions
  • App permissions – No permissions
  • Files page – No permissions
  • Conditional access app control - No permissions
  • Security extensions - Creating and deleting their own API tokens
  • Governance actions – view only actions related to the relevant cloud discovery report
  • Security recommendations for cloud platforms - No permissions
  • IP ranges - No permissions|

    Override admin permissions

    You can override a user's permissions from Microsoft Entra ID or Microsoft 365. To do so, manually add the user to Defender for Cloud Apps and assign new permissions.

    For example, Stephanie is a Security reader in Microsoft Entra ID. To give her Full access in Defender for Cloud Apps, add her manually and assign Full access. The new role overrides her existing permissions.

    You can't override Microsoft Entra roles that already grant Full access (Global administrator, Security administrator, and Cloud App Security administrator).

    Add additional admins

    You can add additional admins to Defender for Cloud Apps without adding users to Microsoft Entra administrative roles.

    Prerequisites

    • To access the Manage admin access page, you must be a member of one of the following groups: Global Administrators, Security Administrators, Compliance Administrators, Compliance Data Administrators, Security Operators, Security Readers, or Global Readers.
    • To edit the Manage admin access page and grant other users access to Defender for Cloud Apps, you must have at least a Security Administrator role.

    To add additional admins, perform the following steps:

    1. In the Microsoft Defender Portal, in the left-hand menu, select Permissions.

    2. Select +Add user to add the admins who should have access to Defender for Cloud Apps. Provide an email address of a user from inside your organization.

    ![Screenshot showing the add user dialog to add additional admins in Defender for Cloud Apps.](media/add-admin.png)
    

    Invite external admins

    Defender for Cloud Apps enables you to invite external admins (MSSPs) as administrators of your organization's (MSSP customer) Defender for Cloud Apps service. To add MSSPs, make sure Defender for Cloud Apps is enabled on the MSSPs tenant, and then add themthe MSSPs as Microsoft Entra B2B collaboration users in the MSSPs customersMSSP customer's Azure portal. Once added, MSSPs can be configured as administrators and assigned any of the roles available in Defender for Cloud Apps.

    To add MSSPs to the MSSP customer Defender for Cloud Apps service

    To add MSSPs to the MSSP customer Defender for Cloud Apps service, complete the following steps:

    1. Add MSSPs as people outside the organization in the MSSP customer directory using the steps under Add people outside the organization to the directory.
    2. Add MSSPs and assign an administrator role in the MSSP customer Defender for Cloud Apps using the steps under Add additional admins. Provide the same external email address used when adding them as guests in the MSSP customer directory.