Microsoft Defender for Identity offers role-based security to safeguard data according to your organization's specific security and compliance needs. We recommend that you use role groups to manage access to Defender for Identity, segregating responsibilities across your security team and granting only the amount of access that users need to do their jobs.
Unified role-based access control (RBAC)
Users that are already Global Administrators or Security Administrators on your tenant's Microsoft Entra ID are also automatically Defender for Identity administrator. Microsoft Entra Global and Security Administrators don't need extra permissions to access Defender for Identity.
For other users, enable and use Microsoft 365 role-based access control (RBAC) to create custom roles and to support more Entra ID roles such as Security operator or Security Reader by default to manage access to Defender for Identity.
When creating your custom roles, make sure that you apply the permissions listed in the following table:
Defender for Identity access level
Minimum required Microsoft 365 unified RBAC permissions
Administrators
- Authorization and settings/Security settings/Read - Authorization and settings/Security settings/All permissions - Authorization and settings/System settings/Read - Authorization and settings/System settings/All permissions - Security operations/Security data/Alerts (manage) -Security operations/Security data /Security data basics (Read) - Authorization and settings/Authorization/All permissions - Authorization and settings/Authorization/Read
Users
- Security operations/Security data /Security data basics (Read) - Authorization and settings/System settings/Read - Authorization and settings/Security settings/Read - Security operations/Security data/Alerts (manage) - microsoft.xdr/configuration/security/manage
Viewers
- Security operations/Security data /Security data basics (Read) - Authorization and settings / System settings (Read and manage) - Authorization and settings / Security setting (All permissions)
Information included from the Defender for Cloud Apps activity log may still contain Defender for Identity data. This content adheres to existing Defender for Cloud Apps permissions.
Exception: If you have configured Scoped deployment for Microsoft Defender for Identity alerts in Microsoft Defender for Cloud Apps, these permissions do not carry over and you will have to explicitly grant the Security operations \ Security data \ Security data basics (read) permissions for the relevant portal users.
Required permissions Defender for Identity in Microsoft Defender XDR
The following table details the specific permissions required for Defender for Identity activities in Microsoft Defender XDR.
Oluline
Microsoft recommends that you use roles with the fewest permissions. This helps improve security for your organization. Global Administrator is a highly privileged role that should be limited to emergency scenarios when you can't use an existing role.
One of the following Microsoft Entra roles: - Security Administrator - Security Operator Or The following Unified RBAC permissions: - Authorization and settings/Security settings/Read - Authorization and settings/Security settings/All permissions - Authorization and settings/System settings/Read - Authorization and settings/System settings/All permissions
View Defender for Identity settings
One of the following Microsoft Entra roles: - Global Reader - Security Reader Or The following Unified RBAC permissions: - Authorization and settings/Security settings/Read - Authorization and settings/System settings/Read
Manage Defender for Identity security alerts and activities
One of the following Microsoft Entra roles: - Security Operator Or The following Unified RBAC permissions: - Security operations/Security data/Alerts (Manage) - Security operations/Security data /Security data basics (Read)
View Defender for Identity security assessments (now part of Microsoft Secure Score)
Permissions to access Microsoft Secure Score And The following Unified RBAC permissions: Security operations/Security data /Security data basics (Read)