Skip to content

Commit a4cad24

Browse files
committed
Update MDE security configuration content for built-in Intune role for managing.
1 parent 5f6f400 commit a4cad24

3 files changed

Lines changed: 3 additions & 7 deletions

File tree

memdocs/intune/protect/includes/security-config-mgt-prerequisites.md

Lines changed: 3 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -4,7 +4,7 @@ description: include file
44
author: brenduns
55
ms.service: microsoft-intune
66
ms.author: brenduns
7-
ms.date: 05/12/2022
7+
ms.date: 09/12/2022
88
ms.topic: include
99
---
1010
## Prerequisites
@@ -123,13 +123,9 @@ To support Microsoft Defender for Endpoint security configuration management thr
123123
> [!TIP]
124124
> Use pilot mode and the proper device tags to test and validate your rollout on a small number of devices. Without using pilot mode, any device that falls into the scope configured will automatically be enrolled.
125125
126-
1. Make sure the relevant users have permissions to manage endpoint security settings in Microsoft Endpoint Manager or grant those permissions by configuring a role in the Microsoft 365 Defender portal. Go to **Settings** > **Roles** > **Add item**:
127-
:::image type="content" source="../media/mde-security-integration/add-role-in-mde.png" alt-text="Create a new role in the Defender portal.":::
128-
> [!TIP]
129-
> You can modify existing roles and add the necessary permissions versus creating additional roles in Microsoft Defender for Endpoint
130-
1. When configuring the role, add users and be sure to select **Manage endpoint security settings in Microsoft Endpoint Manager**:
126+
1. Make sure the relevant users have permissions to manage endpoint security settings in Microsoft Endpoint Manager. If not already provided, request for your IT administrator to grant applicable users the Microsoft Endpoint Manager’s **Endpoint Security Manager** [built-in RBAC role](../fundamentals/role-based-access-control.md).
127+
131128

132-
:::image type="content" source="../media/mde-security-integration/add-role.png" alt-text="Grant users permissions to manage settings.":::
133129
1. Sign in to the [Microsoft Endpoint Manager admin center](https://go.microsoft.com/fwlink/?linkid=2109431).
134130
1. Select **Endpoint security** > **Microsoft Defender for Endpoint**, and set **Allow Microsoft Defender for Endpoint to enforce Endpoint Security Configurations** to **On**.
135131

Binary file not shown.
-65.3 KB
Binary file not shown.

0 commit comments

Comments
 (0)