Skip to content

Commit 9cf6995

Browse files
authored
Merge pull request #5639 from Chirouette/patch-2
Document permissions for Advanced Hunting access
2 parents 2f0b485 + bb24dd5 commit 9cf6995

File tree

1 file changed

+29
-5
lines changed

1 file changed

+29
-5
lines changed

defender-xdr/advanced-hunting-overview.md

Lines changed: 29 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -22,7 +22,7 @@ appliesto:
2222
- Microsoft Defender XDR
2323
- Microsoft Sentinel in the Microsoft Defender portal
2424
search.appverid: met150
25-
ms.date: 09/09/2025
25+
ms.date: 11/19/2025
2626

2727
---
2828

@@ -55,10 +55,34 @@ For more information on advanced hunting in Microsoft Defender for Cloud Apps da
5555

5656
## Get access
5757

58-
To use advanced hunting or other [Microsoft Defender XDR](microsoft-365-defender.md) capabilities, you need an appropriate role in Microsoft Entra ID. [Read about required roles and permissions for advanced hunting](custom-roles.md).
59-
60-
Also, your access to endpoint data is determined by role-based access control (RBAC) settings in Microsoft Defender for Endpoint. [Read about managing access to Microsoft Defender XDR](m365d-permissions.md).
61-
58+
You need to be assigned permissions before you can run Advanced Hunting queries. You have the following options:
59+
60+
- [Microsoft Defender XDR Unified role based access control (URBAC)](manage-rbac.md):
61+
- **Read-only Advanced Hunting access (Email & Collaboration tables)**: Membership assigned with the **Security operations** \> **Security data** \> **Security data basic (read)** URBAC permission. This permission provides access to:
62+
- **EmailEvents**
63+
- **EmailUrlInfo**
64+
- **EmailAttachmentInfo**
65+
- **UrlClickEvents**
66+
- **Email entity metadata**
67+
68+
- [Email & collaboration permissions in the Microsoft Defender portal](/defender-office-365/mdo-portal-permissions): Membership in one of the following Email & Collaboration role groups provides access to email data tables in Advanced Hunting:
69+
- **Security Administrator**
70+
- **Security Operator**
71+
- **Security Reader**
72+
73+
- [Exchange Online permissions](/exchange/permissions-exo/permissions-exo): To access Exchange Online data surfaced in Advanced Hunting, users must be members of one of the following Exchange Online role groups:
74+
- **View-Only Organization Management**
75+
- **View-Only Configuration**
76+
- **Security Reader**
77+
- **Global Reader**
78+
79+
- [Microsoft Entra permissions](/entra/identity/role-based-access-control/manage-roles-portal): Membership in one of the following Microsoft Entra roles grants full read access to all Advanced Hunting data:
80+
- **Global Administrator**
81+
- **Security Administrator**
82+
- **Security Reader**
83+
- **Global Reader**
84+
85+
Also, your access to endpoint data is determined by role-based access control (RBAC) settings in Microsoft Defender for Endpoint. For more information, see [Manage access to Microsoft Defender XDR with Microsoft Entra global roles](m365d-permissions.md).
6286

6387
## Data freshness and update frequency
6488

0 commit comments

Comments
 (0)