Role access to Defender vulnerabilities menu

Paul Creedy 21 Reputation points
2023-02-24T09:31:19.2766667+00:00

I'm trying to grant a user access to vulnerabilities on security.microsoft.com as read only and I've used the documented Azure AD role of "Security Reader"

https://learn.microsoft.com/en-us/azure/defender-for-cloud/permissions

The user now has access to the dashboard but the Vulnerabilities section below the assets item on the menu is missing. That is the very area that I need to grant them access to.

Could someone tell me where I've gone wrong and which Azure AD role I need to grant them to give them access to the vulnerabilities menu/dashboards?

Thank you

User's image

User's image

Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
Microsoft Security | Microsoft Entra | Microsoft Entra ID
0 comments No comments
{count} votes

Accepted answer
  1. Carlos Solís Salazar 18,196 Reputation points MVP Volunteer Moderator
    2023-02-24T19:24:09.1366667+00:00

    Thank you for asking this question on the Microsoft Q&A Platform.

    Please review the Microsoft 365 Defender role-based access control (RBAC) documentation

    The Microsoft 365 Defender role-based access control (RBAC) model provides a single permissions management experience that provides one central location for administrators to control user permissions across different security solutions.

    MS 365 defender has several roles defined (for example Security posture – Posture management) but you can define your own roles

    Also:

    Permissions and roles can also be managed in the Microsoft 365 Defender portal:

    1. Sign in to the Microsoft 365 Defender portal at security.microsoft.com.
    2. In the navigation pane, select Permissions & roles.
    3. Under the Permissions header, select Roles.

    Source: https://learn.microsoft.com/en-us/microsoft-365/security/defender/custom-roles?view=o365-worldwide#manage-permissions-and-roles-in-the-microsoft-365-defender-portal

    Hope this helps!


    Accept Answer and Upvote, if any of the above helped, this thread can help others in the community looking for remediation for similar issues.

    NOTE: To answer you as quickly as possible, please mention me in your reply.

    0 comments No comments

1 additional answer

Sort by: Most helpful
  1. Paul Creedy 21 Reputation points
    2023-02-28T12:28:30.9866667+00:00

    Hi Carlos

    This pointed me in the right direction thank you.

    I had to activate and enable the correct roles inside of security.microsoft.com and set up the new Defender RBAC instead of using Azure RBAC.

    Paul

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.