Granting Defender XDR Unified RBAC permission to send alert email notifications under least privilege

Configure automation for Microsoft Defender XDR and Microsoft Sentinel
Answer Correct answer: D — Only the Manage security settings permission lets a user configure email notifications for alerts, meeting least privilege.

You have a Microsoft 365 subscription that uses Microsoft Defender for Endpoint and contains a user named User1 and a Microsoft 365 group named Group1. All users are assigned a Defender for Endpoint Plan 1 license. You enable Microsoft Defender XDR Unified role-based access control (RBAC) for Endpoints & Vulnerability Management. You need to ensure that User1 can configure alerts that will send email notifications to Group1. The solution must follow the principle of least privilege. Which permissions should you assign to User1?

  1. Defender Vulnerability Management - Remediation handling
  2. Alerts investigation
  3. Live response capabilities: Basic
  4. Manage security settings Correct Answer

Community Votes

D
75%
B
25%

75% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Under Defender XDR Unified RBAC, only the 'Manage security settings' permission allows configuring email notifications for alerts; Alerts investigation covers triage but not notification configuration.

With Defender XDR Unified RBAC enabled for Endpoints, User1 must configure alerts that email a Microsoft 365 group; the 'Manage security settings' permission covers managing email notifications, satisfying least privilege.

Picking Alerts investigation because the task mentions alerts — that permission handles investigating and managing alerts but not configuring who receives email notifications, which belongs to Manage security settings.

Community Discussion (9 comments)

liveup2it 👍 11 Selected: D
You can configure Microsoft Defender XDR to send email notifications to specified recipients for new alerts. This feature enables you to identify a group of individuals who will immediately be informed and can act on alerts based on their severity. If you're using Defender for Business, you can set up email notifications for specific users (not roles or groups). Note Only users with 'Manage security settings' permissions can configure email notifications. If you've chosen to use basic permissions management, users with Security Administrator or Global Administrator roles can configure email notifications. Device group creation is supported in Defender for Endpoint Plan 1 and Plan 2. https://learn.microsoft.com/en-us/defender-xdr/configure-email-notifications
xrxss 👍 2
Answer is for sure D based on https://learn.microsoft.com/en-us/defender-endpoint/user-roles
Syncure 👍 1 Selected: B
It's B Manage Alerts can be done by the following Roles: Security operations \ Security data \ Security data basics (read) Security operations \ Security data \ Alerts (manage) https://learn.microsoft.com/en-us/defender-xdr/compare-rbac-roles
smosmo 👍 1 Selected: D
Manage security settings in Security Center - Configure alert suppression settings, manage folder exclusions for automation, onboard and offboard devices, manage email notifications, manage evaluation lab, and manage allowed/blocked lists for indicators
Hawklx 👍 1 Selected: D
Based on docs
Sekpluz 👍 2 Selected: D
its D 100%
laddu001 👍 2
Manage Security settings
rsanx42 👍 3 Selected: B
Correct answer is B. Alerts Investigation "Alerts investigation - Security operations \ Security data \ Alerts (manage)" https://learn.microsoft.com/en-us/defender-xdr/compare-rbac-roles
madscientist23 👍 1 Selected: B
B is correct

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Within Defender XDR Unified RBAC for Endpoints, the 'Manage security settings' permission includes managing email notifications for alerts, along with alert suppression, exclusions, onboarding, and indicator allowed/blocked lists. Assigning only this permission lets User1 configure the email-to-group notification while honoring least privilege.

Why the Other Options Are Wrong

Alerts investigation (B) grants security-data alert management and triage but does not include the right to configure email notification recipients. Live response capabilities: Basic (C) is for remote device investigation, unrelated to notification configuration. Defender Vulnerability Management - Remediation handling (A) covers vulnerability remediation tasks, not alert email notifications.

Community Comment Notes

liveup2it (11 likes) and smosmo both cite https://learn.microsoft.com/en-us/defender-endpoint/user-roles, noting that only users with 'Manage security settings' can manage email notifications. rsanx42 argues for Alerts investigation, but the documented permission scope places notification configuration under Manage security settings.

Official Reference

Related Analysis

Practice All SC-200 Questions

Access 80 questions with complete answers and detailed explanations.

View Full SC-200 Practice Test →

← Back to SC-200 Study Guide