Bemærk
Adgang til denne side kræver godkendelse. Du kan prøve at logge på eller ændre mapper.
Adgang til denne side kræver godkendelse. Du kan prøve at ændre mapper.
Import roles to Microsoft Defender unified RBAC from individual RBAC models
You can import existing roles that are maintained as part of individual supported products in Microsoft Defender (for example, Microsoft Defender for Endpoint) to the Microsoft Defender unified RBAC model.
Importing roles migrates and maintains the roles with full parity in relation to their permissions and user assignments in the Microsoft Defender unified RBAC model.
Note
Once roles are migrated, you can modify the imported roles and change the level of permissions as needed.
The following steps guide you on how to import roles into Microsoft Defender unified RBAC:
Important
You must be a Security Administrator or higher in Microsoft Entra ID, or have all the Authorization permissions assigned in Microsoft Defender Unified RBAC to perform this task. For more information on permissions, see Permissions prerequisites for Defender unified RBAC.
Sign in to the Microsoft Defender portal.
In the navigation pane, select Permissions.
Select Roles under Microsoft Defender XDR to get to the Permissions and roles page.
Select Import role.
Select the products you want to import roles from.
Select Next to choose the roles to import. You can choose all roles or select specific roles from the list. Select the role name to review the permissions and assigned users or groups for that specific role.
Select the roles you want to import and select Next.
Note
If the role you want to import appears in the Roles not eligible for import list, it contains assignments for users or user groups that no longer exist in Entra ID.
To import this role to Microsoft Defender unified RBAC, remove the user or user group from the role in the original RBAC model. Select the role to view the list of users that still exist for that role to determine which user or group to remove.
Select Submit.
Select Done on the confirmation page.
After importing your roles, you are be able to View and edit Defender unified RBAC roles and activate the workloads.
You need to activate the new Defender unified RBAC model to start enforcing the permissions and assignments configured in your new or imported roles within the Microsoft Defender portal. For more information, see Activate Microsoft Defender unified RBAC.
Imported roles appear in the Permissions and roles list together with any custom roles you created. All imported roles are marked as Imported in the description. Once you edit an imported role, it will no longer be marked as Imported.
Note
You can import roles as frequently as required. After you edit an imported role, the changes don't affect the source role in the original RBAC model. Because changes to an imported role don't affect the source role, you can delete the imported role and re-import it from the original RBAC model, if necessary. If you import the same role twice, you create a duplicate role.
Related content
Tip
Do you want to learn more? Engage with the Microsoft Security community in our Tech Community: Microsoft Defender XDR Tech Community.