Forum Discussion
Can't find correct RBAC permissions to approve AIR actions
Hi RSKadish,
In this example indeed you need the Entra Security Administrator role.
Full Action Center permissions below:
https://learn.microsoft.com/en-us/defender-xdr/m365d-action-center#required-permissions-for-action-center-tasks
I recommend to use PIM so operators only elevate their permissions when needed:
https://learn.microsoft.com/en-us/entra/id-governance/privileged-identity-management/pim-getting-started
Hi Youri,
Thank you. We already use PIM, but I'm trying to get people away from using Security Administrator for things like releasing emails.
In the article you cited, I'm referring to THIS section:
https://learn.microsoft.com/en-us/defender-xdr/manage-rbac
- Microsoft Defender for Endpoint remediation: Security operations \ Security data \ Response (manage).
- Microsoft Defender for Office 365 remediation (Office content and email, if Email & collaboration > Defender for Office 365 permissions is
Active. Affects the Defender portal only, not PowerShell):- Read access for email and Teams message headers: Security operations/Raw data (email & collaboration)/Email & collaboration metadata (read).
- Remediate malicious email: Security operations/Security data/Email & collaboration advanced actions (manage).
I already have a custom role configured with these permissions, but that role can't approve/reject pending actions.
Best regards,
- Steve