Assign Azure role on Tenant Roots Management Group

Mohammed Altamash Khan 2,086 Reputation points
2022-09-27T09:45:52.573+00:00

Hello Folks

For an Environment mentioned below

Tenant Roots management group -----> Management group ------> 3 Subscription Subscription 1 ,2 , 3

I have Log Analytics ( with Sentinel ) in subscription 1
I have Azure policies on tenant root Management group
I have defender for cloud which cover all subscription with p2 License.

I believe the best scenario to give view for all security controls , security settings on resource , compliance etc is to give security reader on Tenant root level for whole security visibility .

can someone give me step wise way solution to give access on root tenant group so my security member can have entire visibility of security of azure.
I don't want custom role.

Regards

Azure Role-based access control
Azure Role-based access control
An Azure service that provides fine-grained access management for Azure resources, enabling you to grant users only the rights they need to perform their jobs.
800 questions
Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,358 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Sandeep G-MSFT 18,851 Reputation points Microsoft Employee
    2022-09-30T03:47:24.71+00:00

    @Mohammed Altamash Khan

    You can look into below article and check if this answers your question.
    https://learn.microsoft.com/en-us/azure/role-based-access-control/role-assignments-portal

    From Defender for cloud, user need to generate the request and request will be forwarded to Global admin and he will approve.

    Please "Accept the answer" if the information helped you. This will help us and others in the community as well.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.