ASD's Blueprint for Secure Cloud

Permissions

This section describes the configuration of endpoint permissions settings within Microsoft Defender associated with systems built according to the guidance provided by ASD's Blueprint for Secure Cloud.

Estimated reading time: 3 minutes

Roles

Microsoft Defender for Endpoint Administrator (default)

ItemValue
General
All settingsModification disabled
Assigned user groups
Group Name<Defender for Endpoint administration group>

Microsoft Defender for Endpoint Remediation

ItemValue
General
Role nameMicrosoft Defender for Endpoint Remediation
DescriptionNone
View DataChecked
- Security operationsChecked
- Defender Vulnerability ManagementChecked
Active remediation actionsChecked
- Security OperationsChecked
- Defender Vulnerability Management - Exception handlingChecked
- Defender Vulnerability Management - Remediation handlingChecked
- Defender Vulnerability Management - Application handlingChecked
Defender Vulnerability Management - Manage security baselines assessment profilesChecked
Alerts investigationChecked
Manage security settings in Security CenterUnchecked
Live response capabilitiesChecked
- AdvancedSelected
Assigned User groups
Group Name<Defender for Endpoint remediation group>

Microsoft Defender for Endpoint Viewer

ItemValue
General
Role nameMicrosoft Defender for Endpoint Viewer
DescriptionNone
View DataChecked
- Security operationsChecked
- Defender Vulnerability ManagementChecked
Active remediation actionsUnchecked
- Security OperationsUnchecked
- Defender Vulnerability Management - Exception handlingUnchecked
- Defender Vulnerability Management - Remediation handlingUnchecked
- Defender Vulnerability Management - Application handlingUnchecked
Defender Vulnerability Management - Manage security baselines assessment profilesUnchecked
Alerts investigationUnchecked
Manage security settings in Security CenterUnchecked
Live response capabilitiesUnchecked
Assigned User groups
Group Name<Defender for Endpoint view group>

Device groups

Windows 10/11

ItemValue
Rank1
General
Device group nameWindows 10/11
Remediation levelFull remediation
DescriptionNone
Devices
NameNot configured
AND DomainNot configured
AND TagNot configured
AND OSIn - Windows 11, Windows 10
User access
Group Name<Device administration group>

Ungrouped devices

ItemValue
RankNot applicable for the ungrouped devices (default) device group
General
Device group nameUngrouped devices (default)
Remediation levelFull remediation
DevicesNot applicable for the default ungrouped device group
User access
Group Name<Device administration group>

Security and governance

Design

Configuration

  • None identified

References

Do you have a suggestion on how the above page could be improved? Get in touch! ASD's Blueprint for Secure Cloud is an open source project, and we would love to get your input. Submit an issue on our GitHub, or send us an email at blueprint@asd.gov.au

Acknowledgement of Country icon

Acknowledgement of Country
We acknowledge the Traditional Owners and Custodians of Country throughout Australia and their continuing connections to land, sea and communities. We pay our respects to them, their cultures and their Elders; past, present and emerging. We also recognise Australia's First Peoples' enduring contribution to Australia's national security.

Authorised by the Australian Government, Canberra