STIGQter STIGQter: STIG Summary: Microsoft Defender for Endpoint Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 05 Jan 2026:

Microsoft Defender for Endpoint (MDE) must be configured for a least privilege model by implementing Unified Role-Based Access Control (RBAC).

DISA Rule

SV-272887r1156554_rule

Vulnerability Number

V-272887

Group Title

SRG-APP-000211

Rule Version

MSDE-00-000350

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Access the MDE portal as a user with at least an MDE Administrator or equivalent role:

1. In the navigation pane, select Settings >> Microsoft Defender XDR >> Permissions and Roles.
2. Select "+Add role".
3. Enter a Role Name, select "Permissions" as defined by the AO, and then click "Next".
4. Select the appropriate group as defined in MSDE-00-000300.

Check Contents

Access the MDE portal as a user with at least an MDE Administrator or equivalent role:

1. In the navigation pane, select Settings >> Microsoft Defender XDR >> Permissions and Roles.
2. For each defined role:
- Click the role to enter the edit role screen.
- Verify the Permissions are configured as defined by the authorizing official (AO).
- Verify the appropriate user groups are assigned as defined by the AO.
- Click "Cancel".

If Settings >> Microsoft Defender XDR >> Permissions and Roles does not display roles as defined by the AO, this is a finding.

When selecting each role individually, if the permissions and user groups are not as defined by the AO, this is a finding.

Vulnerability Number

V-272887

Documentable

False

Rule Version

MSDE-00-000350

Severity Override Guidance

Access the MDE portal as a user with at least an MDE Administrator or equivalent role:

1. In the navigation pane, select Settings >> Microsoft Defender XDR >> Permissions and Roles.
2. For each defined role:
- Click the role to enter the edit role screen.
- Verify the Permissions are configured as defined by the authorizing official (AO).
- Verify the appropriate user groups are assigned as defined by the AO.
- Click "Cancel".

If Settings >> Microsoft Defender XDR >> Permissions and Roles does not display roles as defined by the AO, this is a finding.

When selecting each role individually, if the permissions and user groups are not as defined by the AO, this is a finding.

Check Content Reference

M

Target Key

5693