Forum Discussion
SKadish
Feb 13, 2024Brass Contributor
Defender XDR Unified RBAC - Cannot manage incidents
I've been configuring the new Defender XDR Unified RBAC roles, and two things that I cannot find permissions for are managing incidents and alerts. No matter what I configure, those buttons stay greyed out. This is despite configuring a role that has all Security Operations and Security Posture read and manage permissions.
Other functions are working, for instance being able to block users via the TABL, or Search & Purge permissions.
Can I please get some help?
Hi ahmedamer ,
have you or someone on the team perhaps turned on the Defender for Endpoint deception features?
You can check the setting for Deception by going to your XDR dashboard > Settings > Endpoints > Advanced features and scroll to find the setting for “Deception” towards the bottom of the features list.
if it’s on, you can confirm that the user you’re seeing is apart of the deception identities by scrolling a bit more on the endpoints menu for the “Deception rules” tab under the Rules header. There may just be one Default rule there. Click it and you should see a list of deception identities.
see more here: Configure the deception capability in Microsoft Defender XDR
Best,
Dylan
6 Replies
Sort By
- Gadi_Palatchi_MSFT
Microsoft
Thank you for contacting us with your inquiry.
May I ask have you activated Unified RBAC with any of the workloads? If so which ones?
Can you also share what data sources have you included in the role assignment?
As for the Email & compliance functions you've mentioned that are working properly - note that if you haven't activated Unified RBAC for Email & compliance (both toggles) - access to these functions is managed via roles defined in Admin Center.- SKadishBrass ContributorHello Gadi,
I have activated the following workloads:
- Endpoints & Vulnerability Management
- Email & Collaboration (both Defender for Office 365 & Exchange Online permissions)
- Secure Store
Identity is greyed out. We do not have on-premise AD.
I enabled all data sources in the assignment (MDE, MDO, MDI, MDC, and Secure Store.)
Thank you,
- Steve- SKadishBrass ContributorHello Gadi,
I just realized that I CAN manage incidents where the detection source is MDO. I CANNOT manage incidents where the detection source is Microsoft Defender for Cloud Apps. Is this not possible currently with the Unified RBAC?