Microsoft Defender for IoT
General

Configure the permissions needed for Microsoft Defender for IoT in the Defender portal

In brief

The article now provides an overview of roles and permissions, clarifies Microsoft Entra global roles versus Defender unified RBAC, adds prerequisite guidance, and improves links to feature-specific permission mappings and site security monitoring.

What Defender admins need to know

Administrators have clearer guidance for reviewing and configuring access to Defender for IoT features.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Configure full roles and permissions for Microsoft Defender for IoT

Overview of Defender for IoT roles and permissions

The Microsoft Defender portal allows granular access to features and data based on user roles and the permissions given to each user with Role-Based Access Control (RBAC).

Microsoft Defender for IoT is part of the Defender portal and user access permissions for alerts, incidents, device inventory, device groups and vulnerabilities should already be configured. Nevertheless, with the added features of Defender for IoT you might want to check, adjust or add to the existing roles and permissions of your team in the Defender portal.

This article shows you how to make general changes to RBAC roles and permissions that relate to all areas of Defender for IoT in the Defender portal. Before you begin, make sure you meet the prerequisites. To set up roles and permissions specifically for site security, see set up RBAC permissions for site security.

[!INCLUDE defender-iot-preview]

Prerequisites

Before you begin, make sure you have the following:

Access management options

There are two ways toDepending on whether your organization uses Microsoft Entra global roles or Microsoft Defender unified RBAC, you can manage user access to the Defender portal, depending on the typeportal in one of tenent you're using.two ways. Each system has different named permissions that allow access for Defender for IoT. The two systems are:

The following role-assignment procedure and permission mappings in this section apply to Defender unified RBAC.Defender unified RBAC roles for features in Defender for IoT.

RBAC for version 1 or 2 only

Depending on your Microsoft Defender tenant configuration, you might have access to RBAC version 1 or 2 instead of Defender unified RBAC. Assign RBAC permissions and roles, based on the summary of roles and permissions for Defender for IoT features later in this article (covering alerts, incidents, vulnerabilities, inventory, and device groups), to give users access to general Defender for IoT features. However, follow the instructions in Defender for Endpoint deployment guidance for RBAC version 1, or Defender for Endpoint permission options for RBAC version 2.

If you're using the Defender portal for the first time, you need to set up all of your roles and permissions. For more information, see manage portal access using role-based access control.

Summary of roles and permissions for all Defender for IoT features

The following table summarizes the roles and permissions required for each Defender for IoT feature.

Feature Write permissions Read permissions
Alerts and incidents Defender Permissions: Alerts (manage)
Entra ID roles: Global Administrator, Security Administrator, Security Operator
Write roles
Defender Permissions: Security data basics
Entra ID roles: Global Reader, Security Reader

Next steps

After you configure roles and permissions, learn how to Monitor site security.