Microsoft Defender XDR
General

Manage Rbac

In brief

The page replaces Microsoft Defender XDR with Microsoft Defender in its descriptions, licensing notes, role guidance, and workload activation instructions. The page date was also updated.

What Defender admins need to know

Administrators should use the updated Microsoft Defender terminology when following RBAC guidance. No action is stated as required.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

#customer intent: As a security administrator, I want to manage permissions and access to Microsoft Defender portal experiences using unified role-based access control (RBAC).

Microsoft Defender XDR provides integrated threat protection, detection, and response across endpoints, email, identities, applications, and data within a single portal. Controlling a user's permissions around their access to view data or complete tasks is essential for organizations to minimize the risks associated with unauthorized access.

The Microsoft Defender unified role-based access control (RBAC) model provides a single permissions management experience that provides one central location for administrators to control user permissions across different security solutions.

Service name Unified RBAC support
Microsoft Defender XDR Centralized permissions management for Microsoft Defender XDR experiences.
Microsoft Defender for Endpoint Full support for all endpoint data and actions. All roles are compatible with the device group's scope as defined on the device groups page. Limiting permissions to different device groups is accomplished in the Devices Groups page.
Microsoft Defender Vulnerability Management Centralized permissions management for all Defender Vulnerability Management capabilities.
Microsoft Defender for Office 365 Full support for all data and actions.

Note:
  • Initially, the Microsoft Defender XDR RBAC model is available only for organizations with Microsoft Defender for Office 365 Plan 2 licenses (trial licenses aren't supported).
  • Exchange Online PowerShell and Security & Compliance PowerShell continue to use Exchange Online roles and Email & Collaboration roles. Microsoft Defender unified RBAC doesn't affect Exchange Online PowerShell or Security & Compliance PowerShell.
Microsoft Defender for Identity Full support for all identity data and actions. All roles are compatible with Microsoft Defender for Identity scoped access.

Note: Defender for Identity experiences also adhere to permissions granted from Microsoft Defender for Cloud Apps. For more information, see Microsoft Defender for Identity role groups.
Microsoft Defender for Cloud Support access management for all Defender for Cloud data that is available in Microsoft Defender portal.
Microsoft Security Exposure Management Full support for all Exposure Management data and actions, including Microsoft Secure Score data.
Microsoft Defender for Cloud Apps (Preview) Note: Once Unified RBAC is activated, some built-in scoped roles will no longer be supported. For more information, see Map Microsoft Defender for Cloud Apps permissions to the Microsoft Defender unified RBAC permissions.
Microsoft Sentinel Supports unified access management for all Microsoft Sentinel workspaces onboarded to the Defender portal. Sentinel role assignments made in Unified RBAC sync with Azure RBAC and are visible there. However, unified RBAC becomes the source of permissions once enabled.

When activating Sentinel in Unified RBAC, the User Access Administrator role is assigned to the MTP Unified RBAC app within the enabled workspace.

Assigning permissions to a service principal or to a GDAP user group in Microsoft Sentinel isn't supported in unified RBAC. If you need either capability, keep using Azure RBAC for Microsoft Sentinel. For more information, see Activate Microsoft Defender unified RBAC.

Sentinel experiences in the Defender portal continue to respect ARM roles and permissions in addition to URBAC. Therefore, users with more permissions in ARM than in URBAC may see more data in the Sentinel pages in the Defender portal than configured in their URBAC permissions.

Supports permission management for the Microsoft Sentinel data lake default workspace, when Microsoft Sentinel is onboarded to both the Defender portal and the Microsoft Sentinel data lake.

Microsoft Sentinel users with built-in Azure RBAC roles for their workspaces receive parallel permissions in the Microsoft Sentinel data lake experiences, such as the lake explorer and notebooks. For more information, see Roles and permissions for the Microsoft Sentinel data lake.

For row-level access to Sentinel data by using reusable scope tags, see Configure Microsoft Sentinel scoping.

To see which roles are supported, check the unified RBAC roles mapping.
  • Create a custom role that can grant access to security groups or individual users to manage roles and permissions in Microsoft Defender unified RBAC. This removes the need for Microsoft Entra global roles to manage permissions. To do this, you need to assign the Authorization permission in Microsoft Defender unified RBAC. For details on how to assign the Authorization permission, see Create a role to access and manage roles and permissions.

  • The Microsoft Defender XDR security solution continues to respect existing Microsoft Entra global roles when you activate the Microsoft Defender unified RBAC model for some or all of your workloads, that is, Security Administrators retain assigned administrator privileges.

  • To activate a Microsoft Sentinel workspace in unified RBAC, you need:

    • Security Administrator role in Microsoft Entra ID

Activation of the Microsoft Defender unified RBAC model

You must activate the workloads in Microsoft Defender XDR to use the Microsoft Defender unified RBAC model. Until activated, Microsoft Defender XDR continues to respect the existing RBAC models. Microsoft Sentinel must be activated on a per-workspace basis. For more information, see Activate Microsoft Defender unified RBAC.

When you activate some or all of your workloads to use the new permission model, the roles and permissions for these workloads are fully controlled by the Microsoft Defender unified RBAC model in the Microsoft Defender portal.