お客様は、Microsoft Defender XDRを使用するMicrosoft 365 E5サブスクリプションをご利用で、User1という名前のユーザーが含まれています。
User1がMicrosoft Defender XDRのカスタム検出ルールとエンドポイントセキュリティポリシーを管理できるようにする必要があります。このソリューションは、最小権限の原則に従う必要があります。
User1にはどの役割を割り当てるべきですか?
正解:C
In Microsoft 365 E5 environments that use Microsoft Defender XDR , role-based access control (RBAC) is enforced across the Microsoft Defender portal to align with least-privilege principles. To manage custom detection rules (such as scheduled analytics rules in Defender XDR) and endpoint security policies (such as antivirus, firewall, or attack surface reduction policies in Microsoft Defender for Endpoint), the required role is Security Administrator .
According to Microsoft documentation, the Security Administrator role:
* "Can manage security settings in Microsoft 365 Defender, Microsoft Defender for Endpoint, Microsoft Defender for Identity, and Microsoft Defender for Cloud Apps."
* "Has full permissions to create, edit, and delete security policies, alerts, and detections."
* "Can configure and manage custom detection rules, automated investigation settings, and advanced hunting queries." By contrast:
* Security Operator can view alerts and incidents and take limited response actions but cannot create or manage detection rules or policies.
* Desktop Analytics Administrator relates to Windows analytics and endpoint readiness reporting, not Defender XDR management.
* Cloud Device Administrator primarily manages device onboarding and enrollment in Microsoft Intune or Azure AD, not Defender policies or detections.
Following the principle of least privilege , Security Administrator grants exactly the rights needed to manage Defender XDR custom detection rules and endpoint security policies-without assigning excessive administrative permissions across the tenant.
Therefore, the correct and verified answer is C. Security Administrator .