Azure Security built-in role
Security Admin
Administers Microsoft Defender for Cloud security policy, standards, recommendations, alerts, plans, security components, IoT security, and firmware-defense configuration within the assigned Azure scope. It also reads Log Analytics workspace data and manages Azure Policy definitions, initiatives, assignments, exemptions, classic metric alerts, deployments, and support tickets. It has no DataActions.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: fb1c8493-542b-48eb-b624-b4c8fea62acd
Control-plane actions (14)
Microsoft.Authorization/*/readMicrosoft.Authorization/policyAssignments/*Microsoft.Authorization/policyDefinitions/*Microsoft.Authorization/policyExemptions/*Microsoft.Authorization/policySetDefinitions/*Microsoft.Insights/alertRules/*Microsoft.Management/managementGroups/readMicrosoft.operationalInsights/workspaces/*/readMicrosoft.Resources/deployments/*Microsoft.Resources/subscriptions/resourceGroups/readMicrosoft.Security/*Microsoft.IoTSecurity/*Microsoft.IoTFirmwareDefense/*Microsoft.Support/*
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
Assign at the subscription or other Azure scope whose Defender for Cloud posture the administrator owns. Parent-scope assignments are inherited by child subscriptions, resource groups, and resources. Some Defender plan and policy operations are subscription-level, and Microsoft notes that Owner is still required to enable every capability of a plan.
Common use cases (2)
- Configure Defender for Cloud plans, security policies, standards, recommendations, alert handling, exemptions, and notifications for an approved subscription.
- Operate Defender for Cloud security components and related Azure Policy configuration without granting general Contributor access to all workload resources.
Prerequisites (3)
- Identify the management group, subscription, or resource-group security boundary and the Defender plans, standards, policies, alerts, and integrations the administrator owns.
- Confirm whether the task also requires Owner for a plan capability or a workload-specific role to deploy monitoring components or remediate a resource.
- The assigning administrator needs Microsoft.Authorization/roleAssignments/write at the target scope.
Best practices (3)
- Assign the least permissive role and scope; use Security Reader for visibility and workload roles for resource remediation.
- Use eligible access for human security administrators and require review for plan, policy, exemption, alert-dismissal, and automation changes.
- Review service principals and roles created by plan auto-provisioning because Defender remediation can deploy agents, extensions, and managed identities.
Security considerations (3)
- The Microsoft.Security, Microsoft.IoTSecurity, and Microsoft.IoTFirmwareDefense wildcards grant broad security configuration authority that can alter coverage and alert behavior as providers evolve.
- Policy assignment, definition, initiative, and exemption authority can materially change compliance evaluation across the assigned scope.
- The role can dismiss alerts and recommendations, disable Defender plans, view Log Analytics data, and change classic alerts, deployments, or support tickets even though it has no workload DataActions.
Assignment guidance
Assign Security Admin to the Defender for Cloud administration team at the subscription or narrower supported scope it owns. Use Security Reader for monitoring, add workload remediation roles separately, and do not imply that Security Admin replaces Owner where Microsoft documents Owner as required for all plan capabilities.
Related roles (2)
- Security Reader: Microsoft documents Security Admin as Security Reader visibility plus security policy, alert, recommendation, and plan administration.
- Owner: Microsoft documents Owner as required to enable all capabilities of a Defender for Cloud plan; Security Admin does not replace that separate authority.
Editorial sources (5)
- Azure built-in roles for Security →
Supports: Description, Security considerations. Retrieved 2026-07-16.
- Steps to assign an Azure role →
Supports: Prerequisites, Assignment guidance. Retrieved 2026-07-16.
- Understand scope for Azure RBAC →
Supports: Practical scope, Best practices, Assignment guidance. Retrieved 2026-07-16.
- Best practices for Azure RBAC →
Supports: Best practices, Assignment guidance. Retrieved 2026-07-16.
- User roles and permissions - Microsoft Defender for Cloud →
Supports: Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-16.