Forum Discussion
Grant access to Security Administrators on Secure Score
- Jun 27, 2017
Hey Gents,
The non-global-admin access has been in place since April 2017. Any users with admin roles are able to access the Secure Score experience, but will not be able to make changes unless that change is in scope for the admin role they are assigned. If you aren't seeing that behavior, please do escalate to Microsoft support so they can help get it resolved.
Thanks!
Brandon Koeller
Eduardo - did you get any further with delegating Secure Score portal access to accounts other than Global Administrators?
One of my colleagues has been working on Secure Score for the past few months as we use it for our security adoption and tracking. Not being able to follow "least privilege" principles in a sceutiy product is quite annoying and it would be good to understand if MS are going to address this
Paul
Hey Gents,
The non-global-admin access has been in place since April 2017. Any users with admin roles are able to access the Secure Score experience, but will not be able to make changes unless that change is in scope for the admin role they are assigned. If you aren't seeing that behavior, please do escalate to Microsoft support so they can help get it resolved.
Thanks!
Brandon Koeller
- Paul BendallJun 28, 2017Iron Contributor
Brandon Koeller thanks for the information. Any plans to allow the "Security Reader" role the ability to view the data in the Secure Score portal? For example in our organisation we would like to be able to provide management a view on the state of compliance but don't want them to have admin rights . They could inadvertently change a setting with admin privileges but more importantly we don't want to contaminent an on-prem user identity with access to email and the web having admin privileges in O365.
The other solution would be if you plan to produce a PowerBI content pack that consumes the data from Secure Score portal
Many thanks
Paul- Brandon KoellerJun 28, 2017Copper ContributorHey Paul,
Thanks for the follow-up. Straight up, I didn't even realize there was a role in AAD called Security Reader. :) I've added a task to our backlog to get this role added to the allow list. Thanks for the feedback!
Brandon Koeller- DeletedSep 18, 2018
+1 on having the Security Reader or Security Administrator role access to securescore without having the ability to modify settings. I lead the InfoSec team and the system admins do not want my team to have modify access. We are also getting the 403 "You are not an administrator for your tenancy. The Secure Score requires some kind of administrative role for access" error. Is there a status? Thanks!