Azure Security built-in role

Security Admin

Administers Microsoft Defender for Cloud security policy, standards, recommendations, alerts, plans, security components, IoT security, and firmware-defense configuration within the assigned Azure scope. It also reads Log Analytics workspace data and manages Azure Policy definitions, initiatives, assignments, exemptions, classic metric alerts, deployments, and support tickets. It has no DataActions.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: fb1c8493-542b-48eb-b624-b4c8fea62acd

Control-plane actions (14)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign at the subscription or other Azure scope whose Defender for Cloud posture the administrator owns. Parent-scope assignments are inherited by child subscriptions, resource groups, and resources. Some Defender plan and policy operations are subscription-level, and Microsoft notes that Owner is still required to enable every capability of a plan.

Common use cases (2)

Prerequisites (3)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign Security Admin to the Defender for Cloud administration team at the subscription or narrower supported scope it owns. Use Security Reader for monitoring, add workload remediation roles separately, and do not imply that Security Admin replaces Owner where Microsoft documents Owner as required for all plan capabilities.

Related roles (2)

Common questions

When should I assign the Security Admin Azure role?

Assign Security Admin when you need to: Configure Defender for Cloud plans, security policies, standards, recommendations, alert handling, exemptions, and notifications for an approved subscription.; and Operate Defender for Cloud security components and related Azure Policy configuration without granting general Contributor access to all workload resources.. Practical scope: Assign at the subscription or other Azure scope whose Defender for Cloud posture the administrator owns. Parent-scope assignments are inherited by child subscriptions, resource groups, and resources. Some Defender plan and policy operations are subscription-level, and Microsoft notes that Owner is still required to enable every capability of a plan.

What permissions does the Security Admin Azure role grant?

The role definition grants 14 combined control-plane and data-plane actions. Representative operations include: Microsoft.Authorization/*/read; Microsoft.Authorization/policyAssignments/*; Microsoft.Authorization/policyDefinitions/*; Microsoft.Authorization/policyExemptions/*; Microsoft.Authorization/policySetDefinitions/*; and Microsoft.Insights/alertRules/*. Review the permission sections above for the complete definition and exclusions.

What are the security risks of the Security Admin Azure role?

Key considerations when assigning Security Admin: The Microsoft.Security, Microsoft.IoTSecurity, and Microsoft.IoTFirmwareDefense wildcards grant broad security configuration authority that can alter coverage and alert behavior as providers evolve.; Policy assignment, definition, initiative, and exemption authority can materially change compliance evaluation across the assigned scope.; and The role can dismiss alerts and recommendations, disable Defender plans, view Log Analytics data, and change classic alerts, deployments, or support tickets even though it has no workload DataActions.. Follow the assignment guidance above and use the narrowest practical scope.

Editorial sources (5)

Official Microsoft Learn documentation →