Apr 02 2017 06:55 PM
Hi,
The Security & Compliance portal has a 'security administrator' role, why couldn't members of that role been granted access to Secure Score?
At least the same security team that looks after the compliances can also use the Secure Store.
Thank you,
Eduardo
Apr 03 2017 03:14 PM
I thought they already did. @Brandon Koeller should be able to confirm/deny.
Apr 03 2017 03:28 PM
Apr 03 2017 06:41 PM
Jun 27 2017 06:28 AM
Eduardo - did you get any further with delegating Secure Score portal access to accounts other than Global Administrators?
One of my colleagues has been working on Secure Score for the past few months as we use it for our security adoption and tracking. Not being able to follow "least privilege" principles in a sceutiy product is quite annoying and it would be good to understand if MS are going to address this
Paul
Jun 27 2017 11:03 AM
SolutionHey Gents,
The non-global-admin access has been in place since April 2017. Any users with admin roles are able to access the Secure Score experience, but will not be able to make changes unless that change is in scope for the admin role they are assigned. If you aren't seeing that behavior, please do escalate to Microsoft support so they can help get it resolved.
Thanks!
Brandon Koeller
Jun 28 2017 02:33 AM
@Brandon Koeller thanks for the information. Any plans to allow the "Security Reader" role the ability to view the data in the Secure Score portal? For example in our organisation we would like to be able to provide management a view on the state of compliance but don't want them to have admin rights . They could inadvertently change a setting with admin privileges but more importantly we don't want to contaminent an on-prem user identity with access to email and the web having admin privileges in O365.
The other solution would be if you plan to produce a PowerBI content pack that consumes the data from Secure Score portal
Many thanks
Paul
Jun 28 2017 10:20 AM
Jan 30 2018 07:23 AM
Hello, everyone
Did you manage to fix this? I'm having the same problem, I was appointed as a security admin yesterday, and have no way of seeing the secure score.
Secure score website, brings me to the 403 error as well.
Any tips on how you got this working?
Thanks
Feb 28 2018 07:08 AM - edited May 16 2018 03:23 AM
Hi Brandon, Any news on the Security Reader role getting access to the Security Score pages?
Sep 18 2018 06:28 AM
+1 on having the Security Reader or Security Administrator role access to securescore without having the ability to modify settings. I lead the InfoSec team and the system admins do not want my team to have modify access. We are also getting the 403 "You are not an administrator for your tenancy. The Secure Score requires some kind of administrative role for access" error. Is there a status? Thanks!
Nov 14 2018 06:43 AM
@Brandon Koeller - adding another vote to allow 'Security Reader' to … um … read … security … kind of sounds like what's it mean to do, huh?
I would absolutely love the ability visit https://securescore.office.com or see the data from a widget on https://protection.office.com without bothering my O365 Administrators.
Can you please add these abilities to the 'Security Reader' role?
Nov 14 2018 10:36 AM
Hey Everyone, Apologies for the delayed response here. The Security Reader role now has access to the Secure Score (as of September, 2018). Thanks for the feedback!
Brandon Koeller
Nov 21 2018 10:20 AM
In my company's tenant, the two of us that just got Security Reader still can't see Secure Score. Do you have any suggestions?
Jan 11 2019 01:46 AM - edited Jan 11 2019 01:47 AM
This article should be updated:
https://docs.microsoft.com/en-us/office365/securitycompliance/office-365-secure-score
[You must be an Office 365 administrator, such as a global admin or security admin, to access Secure Score.]
There is no "Secure Score widget" in the Security & Compliance portal for "Security Reader" Role members. However, the M365 secure score can be accessed via https://securescore.microsoft.com.
This role also have access to the Identity Secure Score via https://portal.azure.com / Azure AD / Identity secure score.
Nov 06 2019 02:12 PM - edited Nov 06 2019 02:14 PM
I had the same issue (granting access to the secure score portal). Unfortunately i didn't found the answer here therefor I started troubleshooting.
Yes! Today I have found the solution.
Assigning the security reader rol will fix the issue but you should do that in azure portal rol assignments en not in the office 365 security & compliane / permissions.
It seams that these two section are not the same/ or not in synch.
Jun 27 2017 11:03 AM
SolutionHey Gents,
The non-global-admin access has been in place since April 2017. Any users with admin roles are able to access the Secure Score experience, but will not be able to make changes unless that change is in scope for the admin role they are assigned. If you aren't seeing that behavior, please do escalate to Microsoft support so they can help get it resolved.
Thanks!
Brandon Koeller