Tenant will be auto-enabled into Microsoft Defender Unified RBAC

🚨 The Signal: Microsoft Defender Unified RBAC will auto-enable, centralising access management for Defender and Sentinel. Existing roles will migrate, offering granular scoping and future-proofing permissions across security workloads.

The Impact

Security teams and administrators are affected, with a low risk of disruption due to automatic migration of existing roles.

  • Security Administrators: Will use a new unified portal for Defender/Sentinel access.
  • Identity Teams: Need to understand how existing roles map to the new URBAC model.
  • Compliance Teams: Can leverage enhanced scoping for better access control attestation.

The Action

  1. Review existing Microsoft Defender and Microsoft Sentinel role assignments and their permissions.
  2. Familiarise with the new Unified RBAC portal experience and its scoping capabilities.
  3. Plan for potential adjustments to custom roles or specific permission sets post-migration.

Domain: Defender · Impact: low · Workload: Microsoft Defender · Essential Eight: Restrict Administrative Privileges · ISM: ISM-0445, ISM-1175, ISM-1380, ISM-1507, ISM-1508, ISM-1509, ISM-1647, ISM-1648, ISM-1650, ISM-1686, ISM-1688, ISM-1689, ISM-1883, ISM-1897, ISM-1898