Microsoft Defender for Office 365
Email and collaboration

Mdo Sec Ops Guide

In brief

The guide now bolds the product area for three roles and adds links to the Microsoft Defender for Office 365 overview and getting-started guide.

What Defender admins need to know

Administrators can use the new links to find overview and deployment guidance more easily.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

  • Exchange Online and Email & collaboration: Roles and role groups that grant permission specific to Microsoft Defender for Office 365. The following roles aren't available in Microsoft Entra ID, but can be important for security teams:

    • Preview role (Email(Email & collaboration)collaboration): Assign this role to team members who need to preview or download email messages as part of investigation activities. Allows users to preview and download email messages from cloud mailboxes using Threat Explorer (Explorer) or Real-time detections and the Email entity page.

      By default, the Preview role is assigned only to the following role groups:

      You can add users to those role groups, or you can create a new role group with the Preview role assigned, and add the users to the custom role group.

    • Search and Purge role (Email(Email & collaboration)collaboration): Approve the deletion of malicious messages as recommended by AIR or take manual action on messages in hunting experiences like Threat Explorer.

      By default, the Search and Purge role is assigned only to the following role groups:

      You can add users to those role groups, or you can create a new role group with the Search and Purge role assigned, and add the users to the custom role group.

    • Tenant AllowBlockList Manager (Exchange Online)(Exchange Online): Manage allow and block entries in the Tenant Allow/Block List. Blocking URLs, files (using file hash) or senders is a useful response action to take when investigating malicious email that was delivered.

      By default, this role is assigned only to the Security Operator role group in Exchange Online, not in Microsoft Entra ID. Membership in the Security Operator role in Microsoft Entra ID doesn't allow you to manage entries the Tenant Allow/Block List.

  • Microsoft Defender for Identity

If a relationship is discovered, the system creates an incident that gives visibility for the entire attack.

Related content