Microsoft Unified SecOps Platform
General

Microsoft Defender portal implementation guide for MSSPs

In brief

The page now explains that available email and collaboration capabilities depend on using Microsoft Entra B2B or GDAP. It adds notes on B2B Exchange RBAC limitations and GDAP workload and role requirements, and updates the email-management examples.

What Defender admins need to know

MSSP administrators can use the revised guidance to assess customer-tenant access and management capabilities.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Microsoft Defender portal implementation guide for MSSPs

Azure B2B invited guests aren't supported by experiences that were previously under Microsoft Exchange Online RBAC. Since Defender for Office 365 unified RBAC leans on Exchange Online Admin APIs, actions performed in Defender for Office 365 have limitations. B2B guest admins might get errors when attempting to perform certain actions, such as:

  • Managing spam and phishing policies
  • Managing TABL
  • Can't release emailsReleasing email messages from quarantine
  • Missing Threat Explorer in navigation panequarantine.

Manage entitlement

Email and collaboration tools

When managingyou manage email and collaboration toolsworkloads in customer tenants, available capabilities depend on whether you use Microsoft Entra B2B or granular delegated admin privileges (GDAP).

Identities