Entra ID P2 License - Grant Red Canary analysts Read-Only access to Microsoft Defender
    • 09 Aug 2024
    • 3 Minutes to read
    • PDF

    Entra ID P2 License - Grant Red Canary analysts Read-Only access to Microsoft Defender

    • PDF

    Article summary

    After you grant permissions to your Microsoft Defender for Endpoint API, you can give Red Canary read-only access to your Defender for Endpoint console using role-based access control; see Manage portal access using role-based access control in Microsoft Docs for more information. This enables your Red Canary teams, such as your threat hunting and detection engineering teams, to perform ad-hoc hunting and investigation of potential threats in your environment.

    Note: This process requires an Entra AD Premium P2 license. If you have an Entra AD Premium P1 license, see P1 Azure License - Granting Red Canary analysts read-only access to Microsoft Defender.

    Step 1: Prepare your Microsoft Entra group for Role-Based Access Control, and link the Red Canary active directory tenant

    1. Navigate to https://portal.azure.com, and log in with your global administrator account.

    2. Expand the navigation pane, and then select Entra Active Directory | Groups | New Group.

    3. Fill in the group parameters with the following values:

      • Group Type: Security

      • Group Name: Red Canary

      • Group Description: Red Canary Access Group

      • Entra AD roles can be assigned to the group (Preview): Yes

      • Roles: Security Reader

      • Membership Type: Assigned

      • Owners: No owners selected

      • Members: No members selected

    4. Click Create, and then click Identity Governance. (You may need to enter this in the search bar) 

    5. Under Entitlement Management, select Connected organizations, and then Add connected organization.

    6. Fill out the form with the following values:

      • Basics

        • Name: Red Canary

          • Description: Red Canary Access Group

          • State: Configured

        • Directory + domain

          1. Click Add directory + domain.

          2. Type redcanary.com into the tenant ID search bar.

          3. Highlight the entry, and click Select.

        • Sponsors

          1. Under Add Internal Sponsor, click Add/Remove.

          2. Search for the name of your active directory administrator, highlight the account, and click  Select.

    7. Review the parameters, and then click Create.

    Step 2: Enable Microsoft Defender XDR Unified Role-based Access (RBAC) in Microsoft Defender for Endpoint

    Create a RBAC role within Defender for your endpoint, and then assign the Red Canary Entra AD security group to the role.

    1. Navigate to https://security.microsoft.com, and log in with your global administrator account. 

    2. Select Settings | Endpoints | Roles | Create Custom Role.

    3. Fill out the form with the following values:

      • Role Name: Red Canary

      • Description: Red Canary Access Role

    4. Click Next.

    5. Under Permissions, select Security Operations.

    6. Check the following boxes:

      1. Select custom permissions

      2. Security data

        1. Select custom permissions

          1. Security data basics (read)

      3. Raw data (Email and collaboration)

        1. Select custom permissions

          1. Email & collaboration metadata (read)

    7. Click Apply.

    8. Click Authorization and settings, then click Next.

    9. Check the following boxes.

      1. Select custom permissions.

      2. Authorization

        1. Select Read-only.

      3. Security Settings

        1. Select custom permissions.

          1. Core security settings (read)

      4. System settings

        1. Read-only (Defender for Office, Defender for Identity)

    10. Click Apply.

    11. Click Next.

    12. Click Create assignment (or +add assignment).

    13. Click Next.

    14. Add the Assignment name.

      Note: The name should reflect the assignment.

    15. Assign the users and groups.

    16. From Data Sources ensure all the boxes are checked.

    17. Click Add.

    18. Click Next.

    19. Review the content and click Submit.

    Step 3: Configure your Microsoft Entra Identity Governance Access Packages

    1. Navigate to https://portal.azure.com and log in with your global administrator account. 

    2. Expand the navigation pane, and then select Entra Active Directory | Identity Governance.  

    3. Under Entitlement Management, select Catalogs, and then New Catalog.

    4. Fill out the form with the following values:

      • Name: Red Canary Access

      • Description: Red Canary MTP Service Access Catalog

      • Enabled: Yes

      • Enabled for external users: Yes

    5. Under Entitlement Management, select Access Package, and then New Access Package.

    6. Fill out the forms with the following values:

      • Basics

        • Name: Red Canary Access Package

        • Description: Red Canary Access

        • Catalog: Red Canary Access

      • Resource Roles

        • Select Groups and Teams | Red Canary | Member | Select.

          • Important: In order to select the Red Canary Group, make sure to select See all Group and Team(s) not in the Red Canary Access catalog. You must have the correct permissions to add them in this access package.

      • Requests

        • Select For users not in your directory, Specific connected organizations, and then Red Canary.

        • Require Approval: No

        • Enable new requests and assignments: Yes

      • Lifecycle

        • Access package assignments expire: Never 

        • Users can request specific timeline*: No

        • Require access reviews: Yes

        • Starting on: [today's date]

        • Review frequency: Bi-annually

        • Duration in days: 90

        • Reviewers: Specific reviewers

          1. Click Add reviewers

          2. Select the members of your organization responsible for IAM review procedures.

    7. Review the parameters, and then click Create.

    8. Select the newly created access package under Entra Portal | Active Directory | Identity Governance | Access Packages | Red Canary.  

    9. Under Properties, copy the My access portal link.

    10. Provide the link to your Red Canary contact.


    Was this article helpful?