Assigning permissions for non-IT users to Microsoft Defender
Assigning appropriate permissions to non-IT users in Microsoft Defender ensures they can access necessary features without compromising security or gaining unnecessary permissions (following the principle of least privilege). This recipe will help you assign roles and permissions in Microsoft Defender. Specifically, we’ll assign a user the Security Reader role, which will allow them to read reports and logs, but not change configurations.
Getting ready
Ensure you have the Global Administrator or Security Administrator role to complete the steps in this recipe.
How to do it…
- Go to the Microsoft 365 admin center at https://admin.microsoft.com.
- In the left navigation menu, select Users | Active users.
- Choose the user account you want to assign permissions to by selecting the user’s name to open their account details.
- In the account details pane, go to the Roles section and select...