Microsoft Unified SecOps Platform
General

customer intent: To learn how to create, delete, import, and edit roles in the unified role-based access control in Microsoft Defender multitenant ma…

In brief

The article updates navigation labels, clarifies and renumbers role and assignment steps, adds screenshot descriptions, refreshes metadata, and includes related-content links.

What Defender admins need to know

Administrators can use the revised instructions and links when managing roles and assignments; no action is required.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Manage unified role-based access control in multitenant management

Use the Microsoft Defender multitenant management portal to manage unified role-based access control (URBAC) across multiple tenants. You can view permissions and access for all your tenants in one place. You can also manage these permissions from a central location. This article coversThe following sections explain how to view custom roles, create or edit roles, delete roles, and import roles from tenant workloads.

View custom roles

:::image type="content" source="media/mto-urbac/urbac-main.png" alt-text="Screenshot of main Permissions and roles page":::

From thisthe Permissions & roles page, you can create or edit a custom role. You can also import and delete roles. Use the Search function to find a specific role. To narrow results, filter roles by data source, permissions category, assignee type, or tenant name.

Create or edit a custom role (Preview)

  1. In the Assignments page, select Add assignment or Create assignment to assign users and data sources.

  2. In the Add assignments pane, enter the assignment name. Add the team members you want to assign. Select the data sources they can access and the identity scopes they need. Thenneed, then select Add. Here's

    The following screenshot shows an example.example of the Add assignments pane:

    :::image type="content" source="media/mto-urbac/urbac-create-assignment.png" alt-text="Screenshot of the options in the Add Assignments pane":::

To delete roles, select one or more roles from the list. You can choose roles from different tenants, then select Delete roles.

:::image type="content" source="media/mto-urbac/urbac-delete-multiple.png" alt-text="Screenshot highlighting multiple role selection for deletion":::

To delete a single role, select the three dots next to the role name, then select Delete.

:::image type="content" source="media/mto-urbac/urbac-delete-option.png" alt-text="Screenshot of the Delete option in the Permissions page":::

You can import existing roles from a tenant’s workloads to migrate permissions and assignments. Imported roles become available in the Permissions and roles list.

To import roles, follow these steps:

  1. Navigate to System > Permissions.

    :::image type="content" source="media/mto-urbac/urbac-import-workload.png" alt-text="Screenshot of the Workloads page in the Import role scenario":::

  2. In the Roles page, select all or some of the roles that you want to import from the Eligible roles list. To review the permissions and assignments for a role, select the role name. The following screenshot shows an example of the role review pane.

    :::image type="content" source="media/mto-urbac/urbac-import-review-role.png" alt-text="Screenshot of the role review pane in the Import role scenario":::

  3. Review the details then select Submit to finish importing the roles.

To learn more about unified RBAC, see Microsoft Defender unified role-based access control.

Related content