Microsoft Defender for Identity
Identity protection

Configure scoped access for Microsoft Defender for Identity

In brief

The article now opens with an Overview section, with minor wording updates. Its publication date and custom metadata were also updated.

What Defender admins need to know

Administrators can use the revised overview to understand the article’s scoped-access guidance more quickly. No action is required.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Configure scoped access for Microsoft Defender for Identity

Overview

As your organization grows, you need to control who can access which resources. Microsoft Defender for Identity scoping lets you focus monitoring on specific Active Directory domains or organizational units. ThisScoping reduces noise from data you don't need and helps you focus on critical assets. You can also limit visibility to specific entities so that access matches each person's role. To set up scoped access, create a custom role using Microsoft Defender unified RBAC. When you configure the role, you choose which users or Entra ID groups can access specific Active Directory domains or organizational units.

Prerequisites