Microsoft Defender for Identity
Identity protection

Role Groups

In brief

The role-groups documentation was updated for permissions to perform Defender for Identity response actions, including the custom Response (manage) role and listed Microsoft Entra roles.

What Defender admins need to know

Administrators should use the updated role requirements when reviewing access for response actions.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

|Manage Defender for Identity security alerts and activities | One of the following Microsoft Entra roles:
- Security Operator
Or
The following Unified RBAC permissions:
- Security operations/Security data/Alerts (Manage)
- Security operations/Security data /Security data basics (Read) | | View Defender for Identity security assessments
(now part of Microsoft Secure Score) | Permissions to access Microsoft Secure Score
And
The following Unified RBAC permissions: Security operations/Security data /Security data basics (Read)| |View the Assets / Identities page|Permissions to access Defender for Cloud Apps
Or
One of the Microsoft Entra roles required by Microsoft Defender | |Perform Defender for Identity response actions |A custom role defined with permissions for Response (manage)
Or
One of the following Microsoft Entra roles:
- Security Operator
- SOC Identity Responder |

Defender for Identity security groups