Assigning Security Administrator so a user can manage Defender XDR custom detection rules and Endpoint security policies

Configure automation for Microsoft Defender XDR and Microsoft Sentinel
Answer Correct answer: A — Security Administrator is the role that can manage Defender XDR custom detection rules and Endpoint security policies; Operator is view/investigate only.

You have a Microsoft 365 E5 subscription that uses Microsoft Defender XDR and contains a user named User1. You need to ensure that User1 can manage Microsoft Defender XDR custom detection rules and Endpoint security policies. The solution must follow the principle of least privilege. Which role should you assign to User1?

  1. Security Administrator Correct Answer
  2. Security Operator
  3. Cloud Device Administrator
  4. Desktop Analytics Administrator

Community Votes

A
100%

100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Managing detection rules and security policies is a configuration task, not an operations task; Security Administrator holds the settings/policy management rights, whereas Security Operator can only view and investigate alerts.

User1 must manage Microsoft Defender XDR custom detection rules and Endpoint security policies under least privilege; the Security Administrator role is the role that can configure both, while Security Operator is limited to viewing and investigating.

Choosing Security Operator because the question mentions Defender XDR — Operator is read/investigate only and cannot create or modify detection rules or endpoint security policies.

Community Discussion (8 comments)

Max_DeJaV 👍 7 Selected: A
Regarding "endpoint security policies", the role should be Security Admin, as per this link: https://learn.microsoft.com/en-us/defender-endpoint/mde-security-settings-management "The Endpoint Security Policies page in Microsoft Defender XDR is available only for users with the security administrator role in Microsoft Defender XDR. Any other user role, such as Security Reader, cannot access the portal. When a user has the required permissions to view policies in the Microsoft Defender portal, the data is presented based on Intune permissions. If the user is in scope for Intune role-based access control, it applies to the list of policies presented in the Microsoft Defender portal. We recommend granting security administrators with the Intune built-in role, "Endpoint Security Manager" to effectively align the level of permissions between Intune and Microsoft Defender XDR."
sapphire 👍 1 Selected: A
Security Administrator is correct answer Operator has less privileges - View, investigate, and respond to active threats to your Microsoft 365 users, devices, and content. For more information, see Security Operator. https://learn.microsoft.com/en-us/defender-office-365/mdo-portal-permissions
talosDevbot 👍 1 Selected: A
Remember that the Security Administrator role is focused on configuration and settings management. As soon as you see managing rules or policies in the question, that answer should be Security Administrator. The Security Operator role focuses on the day-to-day operations like viewing and investigating alerts (think of L1 SOC analyst)
g_man_rap 👍 1 Selected: A
Security Administrator (Option A): This role allows full management of security-related features across Microsoft 365, including the ability to manage security settings, policies, alerts, and more. However, this role grants broad permissions that go beyond just managing Microsoft Defender XDR custom detection rules and Endpoint security policies. Security Operator (Option B): This role focuses more on handling alerts, investigating incidents, and responding to threats. It provides access to review and remediate alerts but doesn't allow managing custom detection rules or security policies.
7d801bf 👍 1
Security Admin because the operator can't change or modify anything only read
uday1985 👍 1
One of the following roles is required for Defender for Office 365 Manage alerts Security admin if its O365 then its Secuirty Admin
RedZtopics 👍 1
I think it should be B:Security Operator
ServerBrain 👍 1 Selected: B
B. Security Operator

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The Endpoint Security Policies page and the ability to manage custom detection rules in Microsoft Defender XDR require the Security Administrator role. Security Administrator can manage security settings, policies, and alert configurations across the Defender XDR estate, which matches both stated tasks.

Why the Other Options Are Wrong

Security Operator (B) is limited to viewing, investigating, and responding to active threats; it cannot change or modify policies or rules. Cloud Device Administrator (C) governs Intune device administration, not Defender XDR policies. Desktop Analytics Administrator (D) is unrelated to Defender XDR.

Community Comment Notes

Max_DeJaV (7 likes) cites https://learn.microsoft.com/en-us/defender-endpoint/mde-security-settings-management, noting the Endpoint Security Policies page is available only to Security Administrator. talosDevbot reinforces that any 'managing rules or policies' question points to Security Administrator, with Operator being the L1 investigate-only role.

Official Reference

Related Analysis

Practice All SC-200 Questions

Access 80 questions with complete answers and detailed explanations.

View Full SC-200 Practice Test →

← Back to SC-200 Study Guide