Azure Security built-in role

Security Admin

Administers Microsoft Defender for Cloud security policy, standards, recommendations, alerts, plans, security components, IoT security, and firmware-defense configuration within the assigned Azure scope. It also reads Log Analytics workspace data and manages Azure Policy definitions, initiatives, assignments, exemptions, classic metric alerts, deployments, and support tickets. It has no DataActions.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: fb1c8493-542b-48eb-b624-b4c8fea62acd

Control-plane actions (14)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign at the subscription or other Azure scope whose Defender for Cloud posture the administrator owns. Parent-scope assignments are inherited by child subscriptions, resource groups, and resources. Some Defender plan and policy operations are subscription-level, and Microsoft notes that Owner is still required to enable every capability of a plan.

Common use cases (2)

Prerequisites (3)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign Security Admin to the Defender for Cloud administration team at the subscription or narrower supported scope it owns. Use Security Reader for monitoring, add workload remediation roles separately, and do not imply that Security Admin replaces Owner where Microsoft documents Owner as required for all plan capabilities.

Related roles (2)

Editorial sources (5)

Official Microsoft Learn documentation →