Granting Defender XDR Unified RBAC permission to send alert email notifications under least privilege
You have a Microsoft 365 subscription that uses Microsoft Defender for Endpoint and contains a user named User1 and a Microsoft 365 group named Group1. All users are assigned a Defender for Endpoint Plan 1 license. You enable Microsoft Defender XDR Unified role-based access control (RBAC) for Endpoints & Vulnerability Management. You need to ensure that User1 can configure alerts that will send email notifications to Group1. The solution must follow the principle of least privilege. Which permissions should you assign to User1?
Community Votes
75% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Under Defender XDR Unified RBAC, only the 'Manage security settings' permission allows configuring email notifications for alerts; Alerts investigation covers triage but not notification configuration.
With Defender XDR Unified RBAC enabled for Endpoints, User1 must configure alerts that email a Microsoft 365 group; the 'Manage security settings' permission covers managing email notifications, satisfying least privilege.
Picking Alerts investigation because the task mentions alerts — that permission handles investigating and managing alerts but not configuring who receives email notifications, which belongs to Manage security settings.
Community Discussion (9 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Within Defender XDR Unified RBAC for Endpoints, the 'Manage security settings' permission includes managing email notifications for alerts, along with alert suppression, exclusions, onboarding, and indicator allowed/blocked lists. Assigning only this permission lets User1 configure the email-to-group notification while honoring least privilege.Why the Other Options Are Wrong
Alerts investigation (B) grants security-data alert management and triage but does not include the right to configure email notification recipients. Live response capabilities: Basic (C) is for remote device investigation, unrelated to notification configuration. Defender Vulnerability Management - Remediation handling (A) covers vulnerability remediation tasks, not alert email notifications.Community Comment Notes
liveup2it (11 likes) and smosmo both cite https://learn.microsoft.com/en-us/defender-endpoint/user-roles, noting that only users with 'Manage security settings' can manage email notifications. rsanx42 argues for Alerts investigation, but the documented permission scope places notification configuration under Manage security settings.Official Reference
Related Analysis
Practice All SC-200 Questions
Access 80 questions with complete answers and detailed explanations.
View Full SC-200 Practice Test →