Implementing RBAC
When MDI is configured in a tenant, the feature will automatically provide you with three role groups in Azure Active Directory (Azure AD). These, outside of the Azure AD roles that have permission to manage MDI settings, can help you govern access to the MDI workspace.
The Azure AD roles that have access as administrators in MDI are as follows:
- Global Administrator
- Security Administrator
The groups that are created once MDI is deployed are defined here:
- Azure ATP <tenant name> Administrators
- Azure ATP <tenant name> Users
- Azure ATP <tenant name> Viewers
Important note
The <tenant name> will be replaced by the display name of your tenant.
The Azure Advanced Threat Protection (ATP) groups have different levels of permissions toward MDI. While the Administrators groups can manage the MDI settings in full, the Users group has more limited access, and the Viewers group has read-only access to the...