Forum Discussion
Can't find correct RBAC permissions to approve AIR actions
Hi RSKadish,
In this example indeed you need the Entra Security Administrator role.
Full Action Center permissions below:
https://learn.microsoft.com/en-us/defender-xdr/m365d-action-center#required-permissions-for-action-center-tasks
I recommend to use PIM so operators only elevate their permissions when needed:
https://learn.microsoft.com/en-us/entra/id-governance/privileged-identity-management/pim-getting-started
- RSKadishJul 17, 2024Brass Contributor
Hi Youri,
Thank you. We already use PIM, but I'm trying to get people away from using Security Administrator for things like releasing emails.
In the article you cited, I'm referring to THIS section:
Microsoft Defender XDR Unified role based access control (RBAC)
- Microsoft Defender for Endpoint remediation: Security operations \ Security data \ Response (manage).
- Microsoft Defender for Office 365 remediation (Office content and email, if Email & collaboration > Defender for Office 365 permissions is
- Read access for email and Teams message headers: Security operations/Raw data (email & collaboration)/Email & collaboration metadata (read).
- Remediate malicious email: Security operations/Security data/Email & collaboration advanced actions (manage).
I already have a custom role configured with these permissions, but that role can't approve/reject pending actions.
Best regards,
- Steve
- YouriJul 18, 2024Copper ContributorI understand you on this one. Maybe somebody from Microsoft is able to respond on this.
- MicrosoftIsBuggyAug 08, 2024Copper Contributor
Hi Steve,
I was just looking at this for someone and found it can get quite complex when you move to XDR permissions.
Option 1: XDR Permissions
From what I've seen you have to "hijack" the permissions in XDR from MDO before AIR approvals will work (specifically the soft-delete action). Which is fine, but requires a bit of planning as the built-in roles no longer function as expected.
Enable the MDO workload here: https://security.microsoft.com/securitysettings/defender/mtp_roles
Option 2: Traditional RBAC permissions
Otherwise the least privileged option out-of-the-box appears to be Global Reader + the Data Investigator (MDO) role.MDO Permissions here: https://security.microsoft.com/emailandcollabpermissions
Permissions for AIR capabilities are described by Microsoft here:
https://learn.microsoft.com/en-us/defender-office-365/air-about#required-permissions-to-use-air-capabilities- RSKadishAug 09, 2024Brass Contributor
Hi MicrosoftIsBuggy,
I agree that it takes some planning to transition from the old RBAC scheme to the new, but activating the workloads is well-documented. The problem I was having seemed to be related to an advisory Microsoft has been updating for over a year, Issue ID DZ584153. Sometimes we could approve the actions, sometimes not. The problem is supposedly fixed now, and I look forward to testing it.