A cloud-based identity and access management service for securing user authentication and resource access
Thank you for your post!
When it comes to setting up (enabling / disabling) Security Defaults, you're correct - a Conditional Access Administrator has the appropriate permissions to do this, along with the Security Admin and Global Admin built-in RBAC roles.
Additional Links:
I hope this helps!
If you have any other questions, please let me know. Thank you for your time and patience throughout this issue.
If the information helped address your question, please Accept the answer. This will help us and also improve searchability for others in the community who might be researching similar information.