Skip to main content Link Menu Expand (external link) Document Search Copy Copied

Task 03: Assign permissions for custom detection rules

This task is a prerequisite for creating custom detection rules.

  1. Open a new browser tab, go to MS Defender, and sign in.

  2. In the Defender portal’s leftmost pane, go to System > Permissions.

  3. Select Microsoft Defender XDR > Roles.

  4. Select Create custom role.

    MonitorInvestigate-3.png

  5. Name the role +++Custom Detection Rule Creator+++, then select Next.

    MonitorInvestigate-4.png

  6. Under Choose permissions, select Authorization and settings.

  7. In the flyout, select Select custom permissions.

  8. Under Security settings, select Select custom permissions > Core security settings (manage) > Apply.

    MonitorInvestigate-5.png

    MonitorInvestigate-7.png

  9. Under Choose permissions, select Security operations.

    Notice this automatically added Security data basics (Read).

    MonitorInvestigate-6.png

  10. Close the flyout.

  11. Select Next to move to the Assignments step.

  12. Select Create assignment.

  13. In the flyout pane, under Assignment name, enter +++CustomDetectionRule+++.

  14. Under Employees, select any other username in your tenant other than your username. If you don’t have any other users, enter your Azure username.

  15. Leave the defaults for Data and scope, then select Add at the bottom of the pane.

    MonitorInvestigate-9.png

  16. Back on the Assignments step, select Next, then select Submit.

    MonitorInvestigate-11.png

  17. Select Done once the role’s been created.

  18. Confirm the new role appears in the table.

    63588xjw.jpg

Permissions may take 10-15 minutes to take effect.