Assigning Security Administrator so a user can manage Defender XDR custom detection rules and Endpoint security policies
You have a Microsoft 365 E5 subscription that uses Microsoft Defender XDR and contains a user named User1. You need to ensure that User1 can manage Microsoft Defender XDR custom detection rules and Endpoint security policies. The solution must follow the principle of least privilege. Which role should you assign to User1?
Community Votes
100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Managing detection rules and security policies is a configuration task, not an operations task; Security Administrator holds the settings/policy management rights, whereas Security Operator can only view and investigate alerts.
User1 must manage Microsoft Defender XDR custom detection rules and Endpoint security policies under least privilege; the Security Administrator role is the role that can configure both, while Security Operator is limited to viewing and investigating.
Choosing Security Operator because the question mentions Defender XDR — Operator is read/investigate only and cannot create or modify detection rules or endpoint security policies.
Community Discussion (8 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
The Endpoint Security Policies page and the ability to manage custom detection rules in Microsoft Defender XDR require the Security Administrator role. Security Administrator can manage security settings, policies, and alert configurations across the Defender XDR estate, which matches both stated tasks.Why the Other Options Are Wrong
Security Operator (B) is limited to viewing, investigating, and responding to active threats; it cannot change or modify policies or rules. Cloud Device Administrator (C) governs Intune device administration, not Defender XDR policies. Desktop Analytics Administrator (D) is unrelated to Defender XDR.Community Comment Notes
Max_DeJaV (7 likes) cites https://learn.microsoft.com/en-us/defender-endpoint/mde-security-settings-management, noting the Endpoint Security Policies page is available only to Security Administrator. talosDevbot reinforces that any 'managing rules or policies' question points to Security Administrator, with Operator being the L1 investigate-only role.Official Reference
Related Analysis
Practice All SC-200 Questions
Access 80 questions with complete answers and detailed explanations.
View Full SC-200 Practice Test →