Microsoft Defender for Cloud
Cloud and workloads

Grant and request tenant-wide permissions

In brief

The documentation now identifies Global Administrators as responsible for granting or requesting Azure permissions needed to view organization-wide Defender for Cloud information. It also clarifies the limited-view banner workflow and updates section headings and links.

What Defender admins need to know

Administrators can use the revised guidance to understand permission responsibilities and the process for requesting access. No action is required.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Request tenant-wide permissions when yours are insufficient

When you navigate to Defender for Cloud, you might see a banner that alerts you to the fact that your view is limited. If you see this banner, select itthe banner to send a request to the global administrator for your organization. In the request, you can include the role you'd like to be assigned and the global administrator will decide which role to grant.

It's the global administrator's decision whether to accept or reject these requests.

After the global administrator selects **Review the request** and completes the process, the decision is emailed to the requesting user.

Remove tenant-wide permissions

To remove permissions from the root tenant group, follow these steps:

  1. Review the list of role assignments to identify which one you need to remove.
  2. Select the role assignment you want to remove (Security admin or Security reader) and select Remove. Ensure you have the necessary permissions to make changes to role assignments in the Tenant Root Group.

Next stepsRelated content

Learn more about Defender for Cloud permissions in the following related page: