Forum Discussion
StuartH .
Jul 24, 2023Brass Contributor
MDI Roles/Permissions - where art thou now ?
It used to be simple. In ATP (now MDI), there used to be 3 groups used for administration/viewing (Azure ATP [workspace] Admin, Azure ATP [workspace] Users and Azure ATP [workspace] Viewers). Having...
eliekarkafy
Jul 24, 2023MVP
StuartH . you can now create a custom role from MD365 permission blade for the admin they need to manage the security alerts for MDI.
Please click Mark as Best Response & Like if my post helped you to solve your issue. This will help others to find the correct solution easily.
StuartH .
Jul 24, 2023Brass Contributor
Hey eliekarkafy
Thanks for the quick response. So, are you saying the previous ATP roles (Admin, User & Viewer) are no longer used ? If they are supposed to be, they seem not to be working !
Can you detail your exact steps to get to Permissions & Roles|Microsoft Defender, as that is not what I see in our security.ms.com (Defender) portal as I see:
- eliekarkafyJul 24, 2023MVP
StuartH . from the new permissions blade in Defender, under M365 Defender click on Roles
then click on custom role to create your MDI custom role
- StuartH .Jul 24, 2023Brass Contributor
eliekarkafy mmm, that might be an issue, as I don't even see Microsoft 365 Defender as an item under Permissions. Is this valid for an Enterprise customer - RBAC not available for Defender for Business and hence why it is not showing ? I have looked in two of our tenants, as a Global Admin, and it is not in either
Asides....can you tell me whether those "old" permissions groups are no longer used ? I just don't see that doc'ed anywhere, and I would have thought that there would have been something doced if there was some expectation on customers to migrate from the old way to the new way. Now we are seemingly in a position whereby our admins can't seem to manage MDI alerts. As a global admin, of course, I can still manage the backend MDI settings/sensors etc.
- eliekarkafyJul 24, 2023MVP
The ATP groups can be found in Azure AD under group