MC708505 - Unified RBAC provides centralized role-based administration controls for Microsoft Defender for Office 365

Message Center

This announcement expired on Sep 16, 2024 and is no longer active in Message Center.

Summary

Unified RBAC for Microsoft Defender for Office 365 offers centralized controls and is now generally available. The "Defender Platform for Office 365" Service Plan rollout completion is rescheduled for early August 2024. Organizations can opt-in to URBAC, which requires configuring new roles to replace existing RBAC permissions. A wizard is available to assist with importing roles from Microsoft Defender for Office 365. Exchange Online permissions need manual setup. Existing Microsoft Entra global roles will be respected under the new URBAC model. For more information, visit Microsoft 365 Defender Unified role-based access control (RBAC) | Microsoft Learn.

Last Updated

Aug 2, 2024

Published Jan 20, 2024

View version history

Service

Microsoft Defender XDR

Tag

Updated message
New feature
User impact
Admin impact

More information

Updated August 2, 2024: We have updated the timing of the "Defender Platform for Office 365" Service Plan availability to complete by late July 2024. Thank you for your patience.

Microsoft Defender XDR unified role-based access control (URBAC) provides an alternative to traditional Microsoft Defender for Office 365 (MDO/EOP) and Exchange Online (EXO) RBAC.

When this will happen:

Microsoft Defender XDR unified role-based access control (URBAC) is generally available.

How this will affect your organization:

Microsoft Defender XDR unified role-based access control (URBAC) enables organizations to configure a single set of permissions for their security teams that work for Defender for Office, as well as the other Defender solutions. URBAC is currently in opt-in mode. 
The new Service Plan has no impact on your organization. 

What you need to do to prepare:

Microsoft Defender XDR unified role-based access control (URBAC) provides an alternative to traditional Microsoft Defender for Office 365 (MDO/EOP) and Exchange Online (EXO) RBAC. By default, there are no changes to your security portal permissions. If you want to enable Unified RBAC, then you must first configure the new URBAC roles for your organization. Once you have configured these roles, then you can enable use of URBAC for ‘Microsoft Defender for Office’ permissions and/or ‘Exchange Online’ permissions. Doing so replaces your existing RBAC with the new roles. You can find more information over here - Microsoft 365 Defender Unified role-based access control (RBAC) | Microsoft Learn

Unified RBAC provides an import roles wizard which will help migrate the permissions from your Microsoft Defender for Office 365 role groups. It will create URBAC role groups with permissions that mirror the legacy permissions and groups you have already set up. It will not migrate/replicate Exchange Online permissions – these will require manual configuration in URBAC role groups. 

Please note that URBAC will continue to respect existing Microsoft Entra global roles when you activate the Microsoft Defender XDR Unified RBAC model for Defender for Office 365. i.e. Global Admins and Security Admins will retain assigned admin privileges.

Version history

5 versions tracked

Updated 4 times since Jan 20, 2024. Microsoft Message Center only ever shows the current version; this archive preserves the history.

Compare any two versions

From
To
  1. Aug 2, 2024 · 06:39 PMLatest · v5

    Changed: Body, End date

  2. Apr 15, 2024 · 06:13 PMv4

    Changed: Body

  3. Apr 12, 2024 · 08:50 PMv3

    Changed: Body, Tags, End date

  4. Jan 20, 2024 · 12:16 AMv2

    Changed: Body

  5. Jan 20, 2024 · 12:16 AMOriginal · v1

    Changed: Initial version