Defender Action Center Approve/Reject greyed out

DrDefender 35 Reputation points
2024-08-14T17:33:11.4333333+00:00

Up until last week we were able to check out the Security Administrator role in order to take action on a reported email in the defender action center. Now it is greyed out after we check out the role and we are unable to approve or reject actions. For example there is an action to soft delete the emails. Normally i'd go in and approve them with the Security administrator role, but now it is greyed out. We have cleared sessions and restarted browsers etc. We can confirm we have the role, just the permissions are not working the same.

User's image

Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud Apps
{count} votes

2 answers

Sort by: Most helpful
  1. DrDefender 35 Reputation points
    2024-08-23T18:11:10.04+00:00

  2. David Bourriez 0 Reputation points
    2025-04-29T14:22:53.1766667+00:00

    I'm not happy with how Microsoft handled this specific rights assignment and how the explanation found in the link below is written, but this is how we fixed it:

    Explanation: https://learn.microsoft.com/en-us/defender-xdr/m365d-action-center

    In the Entra ID portal:

    • Create a Security group and allow rights to be assigned to it.
    • Add the members you want to assign the rights to.
    • Assign the role 'Security Administrator' to that group.

    In the Security Cental portal:

    • Go to 'Settings' and select 'Email & collaboration'
      • Assign the role 'Security Administrator' to the group you created
      • Assign the role 'Data Investigator' to the group you created
    • Go to 'Settings' and select 'Endpoints'
      • Assign the role 'Microsoft Defender for Endpoint administrator (default)' to the group you created

    Remarq: According to this information: https://learn.microsoft.com/en-us/defender-office-365/mdo-portal-permissions
    If you activate Defender XDR RBAC for Email & collaboration, the permissions page at https://security.microsoft.com/emailandcollabpermissions is no longer available in the Defender portal, so you need to ensure that you configure or import your roles before you activate Defender XDR Unified RBAC.

    (or just disable RBAC by turning of the workflows (slider button to 'off')

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.