Microsoft Defender XDR
General

Edit Delete Rbac Roles

In brief

The article now provides clearer steps and prerequisites for editing, deleting, and exporting roles. It also highlights that deleting an active workload role removes its assigned user permissions and clarifies export behavior for newer tenants.

What Defender admins need to know

Administrators can use the revised instructions and deletion warning when managing roles; no action is required.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

ms.collection:

  • m365-security
  • tier3 ms.custom: msecd-doc-authoring-10141016 ms.topic: how-to ms.date: 06/15/07/02/2026 ms.reviewer: appliesto:
  • Microsoft Defender for Endpoint Plan 2

[!INCLUDE Microsoft Defender XDR rebranding]

InThis article walks you through how to edit, delete, and export roles in Microsoft Defender unified role-based access control (RBAC), you can edit and delete. These tasks apply to custom roles oryou created in unified RBAC and roles that were imported from Defender for Endpoint, Defender for Identity, or Defender for Office 365. Each section lists the required permissions before the steps.

Edit roles

The following steps guide you on how toTo edit roles in Microsoft Defender unified RBAC:RBAC, follow these steps:

  1. Sign in to the Microsoft Defender portal as security administrator or higher.

Delete roles

To delete roles in Microsoft Defender unified RBAC, selectRBAC:

  1. Select the role or roles you want to delete and selectdelete.

  2. Select Delete roles.

    If the workload is active, all assigned user permissions are deleted by removing the role.

Export roles

The Export feature lets you export the following role data:

  • Role name
  • Role description
  • Permissions in the role
  • Assignment name
  • Assigned data sources
  • Assigned users or user groups

When a role has multiple assignments, each assignment appears as a separate row in the CSV file.

The CSV also includes the Defender unified RBAC activation status for each workload on the tenant.

To export roles in Microsoft Defender unified RBAC, follow these steps:

  1. Sign in to the Microsoft Defender portal with the required roles or permissions.