Forum Discussion
Can't find correct RBAC permissions to approve AIR actions
I've been configuring custom RBAC roles, and even though the "Response (manage)" permission in the Security Operations permissions group includes "approve or dismiss pending remediation actions," it doesn't work. I've tried it with pending "soft delete emails" actions in the Action Center, and I get an error. The only way we can approve or reject these actions is with the Entra Security Administrator role checked out.
Does anyone know which RBAC permission is supposed to grant the rights to approve these remediation actions?
- YouriCopper Contributor
Hi RSKadish,
In this example indeed you need the Entra Security Administrator role.
Full Action Center permissions below:
https://learn.microsoft.com/en-us/defender-xdr/m365d-action-center#required-permissions-for-action-center-tasks
I recommend to use PIM so operators only elevate their permissions when needed:
https://learn.microsoft.com/en-us/entra/id-governance/privileged-identity-management/pim-getting-started- RSKadishBrass Contributor
Hi Youri,
Thank you. We already use PIM, but I'm trying to get people away from using Security Administrator for things like releasing emails.
In the article you cited, I'm referring to THIS section:
Microsoft Defender XDR Unified role based access control (RBAC)
- Microsoft Defender for Endpoint remediation: Security operations \ Security data \ Response (manage).
- Microsoft Defender for Office 365 remediation (Office content and email, if Email & collaboration > Defender for Office 365 permissions is
- Read access for email and Teams message headers: Security operations/Raw data (email & collaboration)/Email & collaboration metadata (read).
- Remediate malicious email: Security operations/Security data/Email & collaboration advanced actions (manage).
I already have a custom role configured with these permissions, but that role can't approve/reject pending actions.
Best regards,
- Steve
- YouriCopper ContributorI understand you on this one. Maybe somebody from Microsoft is able to respond on this.