Skip to content

Commit 8ba4698

Browse files
AbbyMSFTanunesmsCopilot
committed
Document sensitive roles for Defender for Identity integrations
Added sensitive roles for Okta, CyberArk, and SailPoint under Defender for Identity integrations and directory Services Replications addition Co-authored-by: anunesms <[email protected]> Co-authored-by: Copilot <[email protected]>
1 parent 0176ab6 commit 8ba4698

1 file changed

Lines changed: 55 additions & 0 deletions

File tree

defender-for-identity/entity-tags.md

Lines changed: 55 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -76,6 +76,61 @@ In addition to these groups, Defender for Identity identifies the following high
7676
- DHCP Server
7777
- DNS Server
7878
- Microsoft Exchange Server
79+
- Replicating Directory Changes Permissions
80+
81+
## Defender for Identity Integrations
82+
83+
The following roles are designated as Sensitive by Microsoft Defender for Identity. Any entity assigned membership in these roles is automatically classified as sensitive.
84+
85+
### Okta
86+
87+
- Super Administrator
88+
- Application Administrator
89+
- Group Administrator
90+
- API Access Management Administrator
91+
- Group Membership Administrator
92+
- Help Desk Administrator
93+
- Mobile Administrator
94+
- Organization Administrator
95+
- Read-only Administrator
96+
- Report Administrator
97+
98+
### CyberArk
99+
100+
- Administration Role
101+
- Cloud Onboarding Admin
102+
- Connector Management Admin
103+
- Flows Admin
104+
- Privilege Cloud Administrators
105+
- Privilege Cloud Administrators Basic
106+
- Privilege Cloud Administrators Lite
107+
- Privilege Cloud Safe Managers
108+
- Privilege Cloud Safe Managers Basic
109+
- Privilege Cloud Safe Managers Lite
110+
- Privilege Cloud Session Admin
111+
- Privilege Cloud Session Risk Managers
112+
- System Administrator
113+
114+
### SailPoint
115+
116+
#### Entra Id Roles
117+
- Global Administrator
118+
- User Administrator
119+
- Authentication Administrator
120+
- Privileged Authentication Administrator
121+
- Helpdesk Administrator
122+
- Agent ID Administrator
123+
- Application Administrator
124+
- Directory Writers
125+
- Domain Name Administrator
126+
- Password Administrator
127+
- Privileged Role Administrator
128+
- Hybrid Identity Administrator
129+
- Cloud Application Administrator
130+
131+
#### SailPoint Roles
132+
133+
- IdentityNow Administrator
79134

80135

81136
## Related content

0 commit comments

Comments
 (0)