STIGQter STIGQter: STIG Summary: Microsoft Defender for Endpoint Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 05 Jan 2026:

Roles for use with Microsoft Defender for Endpoint (MDE) must be configured within Entra ID.

DISA Rule

SV-272886r1119409_rule

Vulnerability Number

V-272886

Group Title

SRG-APP-000211

Rule Version

MSDE-00-000300

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Access the Azure Entra ID portal as a Global Admin or other role with the ability to create/assign roles and users/groups.

1. Select Manage >> Roles and administrators.
2. Click on the "Security Administrator" role ,then click "+Add assignments".
3. Under "Select Member(s)" add AO-approved users for this role. This role is a top-level administrator within MDE.
Note: A custom defined, AO-approved role may be created and used in lieu of the built-in "MDE Administrator" role.
4. Return to the Entra ID portal home and select Manage >> Groups. Click "New group".
5. Define at least one sub-level group for MDE administration as defined by the AO and assign users(s) to these groups.

Check Contents

Access the Azure Entra ID portal as a Global Admin or other role with the ability to create/assign roles.

1. Select Manage >> Roles and administrators. Click on the "MDE Administrator" role.
2. Under "Active assignments" ensure one or more authorizing official (AO)-approved users are assigned to this role. This role is a top-level administrator within MDE.
Note: A custom defined, AO-approved role may be created and used in lieu of the built-in MDE Administrator role.

If one or more AO-approved users have not been assigned to the security administrator (or equivalent AO-approved) role, this is a finding.

1. Return to the Entra ID portal home and select Manage >> Groups. Click the number next to "Total Groups".
2. Ensure one or more custom roles have been defined as subordinate roles for MDE administration. The structure of various subordinate groups is to be defined by the AO.
3. Click on each of these groups and ensure one or more users have been assigned.

If one or more subordinate groups do not exist, this is a finding.

If one or more users do not exist in these subordinate groups, this is a finding.

Vulnerability Number

V-272886

Documentable

False

Rule Version

MSDE-00-000300

Severity Override Guidance

Access the Azure Entra ID portal as a Global Admin or other role with the ability to create/assign roles.

1. Select Manage >> Roles and administrators. Click on the "MDE Administrator" role.
2. Under "Active assignments" ensure one or more authorizing official (AO)-approved users are assigned to this role. This role is a top-level administrator within MDE.
Note: A custom defined, AO-approved role may be created and used in lieu of the built-in MDE Administrator role.

If one or more AO-approved users have not been assigned to the security administrator (or equivalent AO-approved) role, this is a finding.

1. Return to the Entra ID portal home and select Manage >> Groups. Click the number next to "Total Groups".
2. Ensure one or more custom roles have been defined as subordinate roles for MDE administration. The structure of various subordinate groups is to be defined by the AO.
3. Click on each of these groups and ensure one or more users have been assigned.

If one or more subordinate groups do not exist, this is a finding.

If one or more users do not exist in these subordinate groups, this is a finding.

Check Content Reference

M

Target Key

5693