Skip to Content

MC1486293 Microsoft Defender for Office 365 Changes to Unified RBAC permission mapping for Microsoft Entra Security Operator role

Summary

Microsoft is updating Microsoft Defender for Office 365’s Unified RBAC mapping for the Microsoft Entra Security Operator role, removing default access to email threat policies and Tenant Allow/Block List. This change starts November 2026 and requires manual permission assignment for continued access when Unified RBAC is enabled.

Message ID: MC1486293
Service: Microsoft Defender XDR
Category: Plan for change
Tags: Major change, Feature update, User impact, Admin impact
Rollout: November 2026, December 2026

Microsoft Message

We are updating the Microsoft Defender unified role-based access control (Unified RBAC) permission mapping for Microsoft Defender for Office 365 (Email & Collaboration). Currently, the Microsoft Entra Security Operator role includes the Authorization and settings\Security settings permission through the default Unified RBAC mapping. As a result, users assigned this role can view and manage email threat policies and the Tenant Allow/Block List.

To align access with documented Microsoft Defender for Office 365 role expectations and least-privilege principles, we are updating the default mapping so that Authorization and settings\Security settings (All permissions) is no longer included by default for the Microsoft Entra Security Operator role mapping for the Microsoft Defender for Office 365 workload. After this change, organizations that have Unified RBAC enabled and rely only on the Microsoft Entra Security Operator role for this access will need to manually assign the appropriate permissions or assign a role that includes those permissions.

Rollout schedule

General Availability (Worldwide, GCC, GCC High, DoD): Rollout begins in early November 2026 and is expected to complete by early December 2026.

Impact on your organization

Who is affected

  • Organizations where both of the following conditions apply:
  • Microsoft Defender XDR Unified RBAC is enabled, or will be enabled, for Microsoft Defender for Office 365 (Email & Collaboration).
  • Users assigned the Microsoft Entra Security Operator role.

Platforms and services

  • Microsoft Defender for Office 365 (Email & Collaboration)
  • Microsoft Defender XDR Unified RBAC
  • Microsoft Entra ID

What will happen

  • The default Unified RBAC mapping for the Microsoft Entra Security Operator role will be updated to align with its documented Microsoft Defender for Office 365 scope and least-privilege principles.
  • When Unified RBAC is enabled for Microsoft Defender for Office 365, by default, the Security Operator role will no longer provide access to view, create, edit, or delete email threat policies, including anti-spam, anti-phishing, anti-malware, Safe Links, Safe Attachments, and preset security policies. The role will also no longer provide access to view, add, edit, or remove Tenant Allow/Block List entries.
  • This change applies only to Microsoft Defender for Office 365 when Unified RBAC is enabled. Tenants that have not enabled Unified RBAC are not affected.
  • Organizations that want operators to retain access can manually assign the appropriate Unified RBAC permissions, including Core security settings and Detection tuning, or assign a role that already includes those permissions, such as Security Administrator.
  • Other role mappings and existing Exchange Online PowerShell authorization are unchanged.

Action required and recommendations

We recommend that you:

  • Review users who are assigned the Microsoft Entra Security Operator role and determine whether they rely on that role to view or manage email threat policies or the Tenant Allow/Block List.
  • If continued access is required, assign an appropriate role or grant the required Unified RBAC permissions, including Core security settings and Detection tuning.
  • Update internal operational procedures, runbooks, and access-control documentation as needed.
  • Communicate this change to security operations teams and help desk staff.

Learn more

  • Activate Microsoft Defender unified role-based access control (URBAC) – Microsoft Defender XDR | Microsoft Learn
  • Create custom roles with Microsoft Defender unified role-based access control (RBAC) – Microsoft Defender XDR | Microsoft Learn
  • Map Microsoft Defender unified role-based access control (RBAC) permissions – Microsoft Defender XDR | Microsoft Learn
  • Permissions in Microsoft Defender unified role-based access control (RBAC) – Microsoft Defender XDR | Microsoft Learn

Compliance considerations

No compliance considerations identified. Review as appropriate for your organization.