mirror of
https://github.com/MicrosoftDocs/windows-itpro-docs.git
synced 2025-05-14 06:17:22 +00:00
Update user-roles.md
This commit is contained in:
parent
e62b69d9e7
commit
fa0e4e027f
@ -39,31 +39,31 @@ The following steps guide you on how to create roles in Microsoft Defender Secur
|
|||||||
- **Role name**
|
- **Role name**
|
||||||
- **Description**
|
- **Description**
|
||||||
- **Permissions**
|
- **Permissions**
|
||||||
- **View data** - Users can view information in the portal.
|
- **View data** - Users can view information in the portal.
|
||||||
>[!NOTE]
|
>[!NOTE]
|
||||||
>To view Threat & Vulnerability Management data, select **Threat and vulnerability management**
|
>To view Threat & Vulnerability Management data, select **Threat and vulnerability management**
|
||||||
|
|
||||||
- **Alerts investigation** - Users can manage alerts, initiate automated investigations, collect investigation packages, manage machine tags, and export machine timeline.
|
- **Alerts investigation** - Users can manage alerts, initiate automated investigations, collect investigation packages, manage machine tags, and export machine timeline.
|
||||||
- **Active remediation actions** - Users can take response actions and approve or dismiss pending remediation actions.
|
- **Active remediation actions** - Users can take response actions and approve or dismiss pending remediation actions.
|
||||||
>[!NOTE]
|
>[!NOTE]
|
||||||
>To enable your Security operation personnel to choose remediation options and file exceptions, select **Threat and vulnerability management - Remediation handling**, and **Threat and vulnerability management - Exception handling**.
|
>To enable your Security operation personnel to choose remediation options and file exceptions, select **Threat and vulnerability management - Remediation handling**, and **Threat and vulnerability management - Exception handling**.
|
||||||
|
|
||||||
- **Manage portal system settings** - Users can configure storage settings, SIEM and threat intel API settings (applies globally), advanced settings, automated file uploads, roles and machine groups.
|
- **Manage portal system settings** - Users can configure storage settings, SIEM and threat intel API settings (applies globally), advanced settings, automated file uploads, roles and machine groups.
|
||||||
|
|
||||||
> [!NOTE]
|
> [!NOTE]
|
||||||
> This setting is only available in the Microsoft Defender ATP administrator (default) role.
|
> This setting is only available in the Microsoft Defender ATP administrator (default) role.
|
||||||
|
|
||||||
- **Manage security settings** - Users can configure alert suppression settings, manage allowed/blocked lists for automation, create and manage custom detections, manage folder exclusions for automation, onboard and offboard machines, and manage email notifications.
|
- **Manage security settings** - Users can configure alert suppression settings, manage allowed/blocked lists for automation, create and manage custom detections, manage folder exclusions for automation, onboard and offboard machines, and manage email notifications.
|
||||||
|
|
||||||
- **Live response capabilities** - Users can take basic or advanced live response commands.
|
- **Live response capabilities** - Users can take basic or advanced live response commands.
|
||||||
- Basic commands allow users to:
|
- Basic commands allow users to:
|
||||||
- Start a live response session
|
- Start a live response session
|
||||||
- Run read only live response commands on a remote machine
|
- Run read only live response commands on a remote machine
|
||||||
- Advanced commands allow users to:
|
- Advanced commands allow users to:
|
||||||
- Run basic actions
|
- Run basic actions
|
||||||
- Download a file from the remote machine
|
- Download a file from the remote machine
|
||||||
- View a script from the files library
|
- View a script from the files library
|
||||||
- Run a script on the remote machine from the files library take read and write commands.
|
- Run a script on the remote machine from the files library take read and write commands.
|
||||||
|
|
||||||
For more information on the available commands, see [Investigate machines using Live response](live-response.md).
|
For more information on the available commands, see [Investigate machines using Live response](live-response.md).
|
||||||
|
|
||||||
|
Loading…
x
Reference in New Issue
Block a user