ASD's Blueprint for Secure Cloud

Permissions

This section describes the configuration of endpoint permissions within Microsoft Defender associated with systems built according to the guidance provided by ASD's Blueprint for Secure Cloud.

Estimated reading time: 3 minutes

Roles

Microsoft Defender for Endpoint Administrator (default)

ItemValue
General
All SettingsLeave as default
Assigned user groups
Group NameAzure ATP tenant name Administrators

Microsoft Defender for Endpoint Remediation

ItemValue
General
Role nameMicrosoft Defender for Endpoint Remediation
View DataEnabled
- Security operationsEnabled
- Defender Vulnerability ManagementEnabled
Active remediation actionsEnabled
- Security OperationsEnabled
- Defender Vulnerability Management - Exception handlingEnabled
- Defender Vulnerability Management - Remediation handlingEnabled
- Defender Vulnerability Management - Application handlingEnabled
Defender Vulnerability Management - Manage security baselines assessment profilesEnabled
Alerts investigationEnabled
Manage security settings in Security CenterDisabled
Live response capabilitiesEnabled
- AdvancedSelected
Assigned User groups
Group NameAzure ATP tenant name Users

Microsoft Defender for Endpoint Viewer

ItemValue
General
Role nameMicrosoft Defender for Endpoint Viewer
View DataEnabled
- Security operationsEnabled
- Defender Vulnerability ManagementEnabled
Assigned User groups
Group NameAzure ATP tenant name Viewers

Device groups

Windows 10/11

ItemValue
Rank1
General
Device group nameWindows 10/11
Remediation levelFull - remediate threats automatically
Devices
NameNot configured
AND DomainNot configured
AND TagNot configured
AND OSIn - Windows 10, Windows 11
User access
Group NameAzure ATP tenant name Administrators, Azure ATP tenant name Users, Azure ATP tenant name Viewers

Ungrouped devices

ItemValue
RankNot applicable for the default ungrouped device group
General
Device group nameUngrouped devices (default)
Remediation levelFull - remediate threats automatically
DevicesNot applicable for the default ungrouped device group
User access
Group NameAzure ATP tenant name Administrators, Azure ATP tenant name Users, Azure ATP tenant name Viewers

Security & Governance

Design

Configuration

References

Do you have a suggestion on how the above page could be improved? Get in touch! ASD's Blueprint for Secure Cloud is an open source project, and we would love to get your input. Submit an issue on our GitHub, or send us an email at blueprint@asd.gov.au

Acknowledgement of Country icon

Acknowledgement of Country
We acknowledge the Traditional Owners and Custodians of Country throughout Australia and their continuing connections to land, sea and communities. We pay our respects to them, their cultures and their Elders; past, present and emerging. We also recognise Australia's First Peoples' enduring contribution to Australia's national security.

Authorised by the Australian Government, Canberra