Loading...

Microsoft Defender for Office 365: Changes to Unified RBAC permission mapping for Microsoft Entra Security Operator role

Microsoft Defender for Office 365: Changes to Unified RBAC permission mapping for Microsoft Entra Security Operator role

Microsoft is updating Microsoft Defender for Office 365’s Unified RBAC mapping for the Microsoft Entra Security Operator role, removing default access to email threat policies and Tenant Allow/Block List. This change starts November 2026 and requires manual permission assignment for continued access when Unified RBAC is enabled. We are updating the Microsoft Defender unified role-based access control (Unified RBAC) permission mapping for Microsoft Defender for Office 365 (Email & Collaboration). Currently, the Microsoft Entra Security Operator role includes the Authorization and settings\Security settings permission through the default Unified RBAC mapping. As a result, users assigned this role can view and manage email threat policies and the Tenant Allow/Block List. To align access with documented Microsoft Defender for Office 365 role expectations and least-privilege principles, we are updating the default mapping so that Authorization and settings\Security settings (All permissions) is no longer included by default for the Microsoft Entra Security Operator role mapping for the Microsoft Defender for Office 365 workload. After this change, organizations that have Unified RBAC enabled and rely only on the Microsoft Entra Security Operator role for this access will need to manually assign the appropriate permissions or assign a role that includes those permissions. Rollout schedule General Availability (Worldwide, GCC, GCC High, DoD): Rollout begins in early November 2026 and is expected to complete by early December 2026. Impact on your organization Who is affected Organizations where both of the following conditions apply: Microsoft Defender XDR Unified RBAC is enabled, or will be enabled, for Microsoft Defender for Office 365 (Email & Collaboration). Users assigned the Microsoft Entra Security Operator role. Platforms and services Microsoft Defender for Office 365 (Email & Collaboration) Microsoft Defender XDR Unified RBAC Microsoft Entra ID What will happen The default Unified RBAC mapping for the Microsoft Entra Security Operator role will be updated to align with its documented Microsoft Defender for Office 365 scope and least-privilege principles. When Unified RBAC is enabled for Microsoft Defender for Office 365, by default, the Security Operator role will no longer provide access to view, create, edit, or delete email threat policies, including anti-spam, anti-phishing, […]

The post Microsoft Defender for Office 365: Changes to Unified RBAC permission mapping for Microsoft Entra Security Operator role appeared first on M365 Admin.

Published on:

Learn more
Need help with this product?

We can help you with Microsoft Defender for Office 365: Changes to Unified RBAC permission mapping for Microsoft Entra Security Operator role

If you want help implementing, troubleshooting, or improving this product, contact us and we’ll point you in the right direction.

M365 Admin
M365 Admin

by João Ferreira

Share post:

Related posts

Microsoft OneDrive and SharePoint: Generate smart tables of contents for PDFs on the web with Copilot

Microsoft 365 Copilot users can generate AI-created, hierarchical, clickable tables of contents for PDFs in OneDrive and SharePoint on the web...

2 hours ago

Microsoft 365 Copilot: new guided Copilot onboarding experience

Microsoft 365 Copilot introduces an optional, admin-enabled guided onboarding experience for Frontier participants starting late October 2026....

2 hours ago

Microsoft Purview |Unified Classification Management Experience

Microsoft Purview is launching a unified Classification Management experience for admins to manage classifiers consistently. Public Preview st...

2 hours ago

Microsoft Purview | Data Loss Prevention: Administrative Units support for DLP policies for Microsoft Copilot

Microsoft Purview extends Microsoft Entra Administrative Units support to Copilot DLP policies, enabling delegated management within units whi...

2 hours ago

Action required: Update Teams devices to a minimum app version ahead of the retirement of Exchange Web Services (EWS)

Update Microsoft Teams Rooms on Android, phones, and panels to the minimum app version released in February 2026 before October 2026 to avoid ...

2 hours ago

Microsoft Power Platform governance and administration – Secure Dataverse record with column-based filtering

We are announcing the ability for admins to use filtered views to select and manage record-level access securely by defining security based on...

2 hours ago

Microsoft Teams: Impersonation Protection for Teams meetings

Impersonation Protection for Teams meetings helps users identify potentially deceptive participants and meeting organizers. When Teams detects...

1 day ago

Microsoft Copilot (Microsoft 365): Use Dataverse Business Skills in Sales Agent

Business Skills are natural language instructions authored and stored in Microsoft Dataverse that teach Sales Agent how work gets done within ...

1 day ago

Microsoft Teams: Onboarding workflow for new team members

Help people get started faster by automatically connecting new team members to relevant channels when they join a team. Improve engagement, ac...

1 day ago

Newsletter

Get the latest Dynamics 365 and Power Platform content in your inbox

A curated digest of community blogs, product news, videos, and podcasts — delivered without the noise.

Weekly updates Unsubscribe anytime Fresh community picks
We use your email only for the newsletter and you can unsubscribe at any time.
By subscribing, you agree to the privacy policy.