Configure the permissions needed for Microsoft Defender for IoT in the Defender portal
In brief
The article now provides an overview of roles and permissions, clarifies Microsoft Entra global roles versus Defender unified RBAC, adds prerequisite guidance, and improves links to feature-specific permission mappings and site security monitoring.
What Defender admins need to know
Administrators have clearer guidance for reviewing and configuring access to Defender for IoT features.
Summaries are generated from the documentation change itself.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
Configure full roles and permissions for Microsoft Defender for IoT
Overview of Defender for IoT roles and permissions
The Microsoft Defender portal allows granular access to features and data based on user roles and the permissions given to each user with Role-Based Access Control (RBAC).
Microsoft Defender for IoT is part of the Defender portal and user access permissions for alerts, incidents, device inventory, device groups and vulnerabilities should already be configured. Nevertheless, with the added features of Defender for IoT you might want to check, adjust or add to the existing roles and permissions of your team in the Defender portal.
This article shows you how to make general changes to RBAC roles and permissions that relate to all areas of Defender for IoT in the Defender portal. Before you begin, make sure you meet the prerequisites. To set up roles and permissions specifically for site security, see set up RBAC permissions for site security.
[!INCLUDE defender-iot-preview]
Prerequisites
Before you begin, make sure you have the following:
- Review the general prerequisites for Microsoft Defender for IoT.
- Details of all users to be assigned updated roles and permissions for the Defender portal.
Access management options
There are two ways toDepending on whether your organization uses Microsoft Entra global roles or Microsoft Defender unified RBAC, you can manage user access to the Defender portal, depending on the typeportal in one of tenent you're using.two ways. Each system has different named permissions that allow access for Defender for IoT. The two systems are:
- Global Microsoft Entra roles.
- Microsoft Defender unified RBAC: Use Microsoft Defender unified role-based access control (RBAC) to manage access to specific data, tasks, and capabilities in the Defender portal.
The following role-assignment procedure and permission mappings in this section apply to Defender unified RBAC.Defender unified RBAC roles for features in Defender for IoT.
RBAC for version 1 or 2 only
Depending on your Microsoft Defender tenant configuration, you might have access to RBAC version 1 or 2 instead of Defender unified RBAC. Assign RBAC permissions and roles, based on the summary of roles and permissions for Defender for IoT features later in this article (covering alerts, incidents, vulnerabilities, inventory, and device groups), to give users access to general Defender for IoT features. However, follow the instructions in Defender for Endpoint deployment guidance for RBAC version 1, or Defender for Endpoint permission options for RBAC version 2.
If you're using the Defender portal for the first time, you need to set up all of your roles and permissions. For more information, see manage portal access using role-based access control.
Summary of roles and permissions for all Defender for IoT features
The following table summarizes the roles and permissions required for each Defender for IoT feature.
| Feature | Write permissions | Read permissions |
|---|---|---|
| Alerts and incidents | Defender Permissions: Alerts (manage) Entra ID roles: Global Administrator, Security Administrator, Security Operator |
Write roles Defender Permissions: Security data basics Entra ID roles: Global Reader, Security Reader |
Next steps
After you configure roles and permissions, learn how to Monitor site security.
@@ -1,43 +1,47 @@ --- title: Configure the permissions needed for Microsoft Defender for IoT in the Defender portal-description: This article describes how to configure the permissions required for Microsoft Defender for IoT in the Microsoft Defender portal.+description: Configure RBAC roles and permissions for Microsoft Defender for IoT in the Defender portal, including how to review, adjust, and extend access for IoT alerts, incidents, device inventory, and vulnerabilities. ms.service: defender-for-iot author: limwainstein ms.author: lwainstein ms.localizationpriority: medium-ms.date: 06/11/2026+ms.date: 07/02/2026 ms.topic: how-to-ms.custom: sfi-ga-nochange, msecd-doc-authoring-1013+ms.custom: sfi-ga-nochange, msecd-doc-authoring-1016 ai-usage: ai-assisted --- -# Configure full roles and permissions+# Configure full roles and permissions for Microsoft Defender for IoT++## Overview of Defender for IoT roles and permissions The Microsoft Defender portal allows granular access to features and data based on user roles and the permissions given to each user with Role-Based Access Control (RBAC). Microsoft Defender for IoT is part of the Defender portal and user access permissions for alerts, incidents, device inventory, device groups and vulnerabilities should already be configured. Nevertheless, with the added features of Defender for IoT you might want to check, adjust or add to the existing roles and permissions of your team in the Defender portal. -This article shows you how to make general changes to RBAC roles and permissions that relate to all areas of Defender for IoT in the Defender portal. To set up roles and permissions specifically for site security, see [set up RBAC permissions for site security](set-up-rbac.md). +This article shows you how to make general changes to RBAC roles and permissions that relate to all areas of Defender for IoT in the Defender portal. Before you begin, make sure you meet the [prerequisites](#prerequisites). To set up roles and permissions specifically for site security, see [set up RBAC permissions for site security](set-up-rbac.md). [!INCLUDE [defender-iot-preview](../includes//defender-for-iot-defender-public-preview.md)] ## Prerequisites +Before you begin, make sure you have the following:+ - Review [the general prerequisites for Microsoft Defender for IoT](prerequisites.md). - Details of all users to be assigned updated roles and permissions for the Defender portal. ## Access management options -There are two ways to manage user access to the Defender portal, depending on the type of tenent you're using. Each system has different named permissions that allow access for Defender for IoT. The two systems are:+Depending on whether your organization uses Microsoft Entra global roles or Microsoft Defender unified RBAC, you can manage user access to the Defender portal in one of two ways. Each system has different named permissions that allow access for Defender for IoT. The two systems are: - [Global Microsoft Entra roles](/entra/identity/role-based-access-control/permissions-reference). - [Microsoft Defender unified RBAC](/defender-xdr/custom-roles): Use Microsoft Defender unified role-based access control (RBAC) to manage access to specific data, tasks, and capabilities in the Defender portal. -The role-assignment procedure and permission mappings in this section apply to Defender unified RBAC.+The following role-assignment procedure and permission mappings apply to [Defender unified RBAC roles for features in Defender for IoT](#defender-unified-rbac-roles-for-features-in-defender-for-iot). ### RBAC for version 1 or 2 only -Depending on your Microsoft Defender tenant configuration, you might have access to RBAC version 1 or 2 instead of Defender unified RBAC. Assign RBAC permissions and roles, based on the [summary table](#summary-of-roles-and-permissions-for-all-defender-for-iot-features), to give users access to general Defender for IoT features. However, follow the instructions in [Defender for Endpoint deployment guidance for RBAC version 1](/defender-endpoint/prepare-deployment), or [Defender for Endpoint permission options for RBAC version 2](/defender-endpoint/user-roles#permission-options).+Depending on your Microsoft Defender tenant configuration, you might have access to RBAC version 1 or 2 instead of Defender unified RBAC. Assign RBAC permissions and roles, based on the [summary of roles and permissions for Defender for IoT features](#summary-of-roles-and-permissions-for-all-defender-for-iot-features) later in this article (covering alerts, incidents, vulnerabilities, inventory, and device groups), to give users access to general Defender for IoT features. However, follow the instructions in [Defender for Endpoint deployment guidance for RBAC version 1](/defender-endpoint/prepare-deployment), or [Defender for Endpoint permission options for RBAC version 2](/defender-endpoint/user-roles#permission-options). If you're using the Defender portal for the first time, you need to set up all of your roles and permissions. For more information, see [manage portal access using role-based access control](/defender-xdr/manage-rbac). @@ -74,6 +78,8 @@ Use Defender unified role-based access control (RBAC) to assign permissions and ### Summary of roles and permissions for all Defender for IoT features +The following table summarizes the roles and permissions required for each Defender for IoT feature.+ | Feature | Write permissions | Read permissions | |---|----|---| |Alerts and incidents| **Defender Permissions**: Alerts (manage) <br> **Entra ID roles**: Global Administrator, Security Administrator, Security Operator| Write roles<br> **Defender Permissions**: Security data basics<br>**Entra ID roles**: Global Reader, Security Reader |@@ -87,4 +93,4 @@ For more information, see [map Defender unified RBAC permissions](/defender-xdr/ ## Next steps -[Monitor site security](monitor-site-security.md)+After you configure roles and permissions, learn how to [Monitor site security](monitor-site-security.md). 