Entra ID P1 License - Grant Red Canary Read-Only Access to Microsoft Defender
    • 09 Aug 2024
    • 2 Minutes to read
    • PDF

    Entra ID P1 License - Grant Red Canary Read-Only Access to Microsoft Defender

    • PDF

    Article summary

    Red Canary Managed Security Service Provider (MSSP) Access Instructions for Entra ID P1 license will provide Red Canary organization Cyber Incident Response Team (CIRT) members with direct access to your Microsoft 365 Defender console. 

    These instructions are intended for customers who use Microsoft Entra ID P1 type licenses, which does not allow access to the Identity Governance features of Entra ID. If you have an E5/A5 license, see Integrate Microsoft Defender for Endpoint with Red Canary.

    Prerequisites

    Step 1: Entra ID–Create a security group

    Create the Entra ID security group that will contain the Red Canary shared user account.

    1. Navigate to your Azure portal and log in with your Global or Security Administrator Microsoft account. 

    2. Expand the navigation pane and click Entra ID

    3. Click Groups

    4. Click New Group.

    5. Fill in the group parameters with the following: 

      • Group Type: Security

      • Group Name: Red Canary

      • Group Description: Red Canary Access Group

      • Azure AD roles can be assigned to the group: Yes

      • Roles: Security Reader.

      • Membership Type: Assigned

      • Owners: No owners selected

      • Members: No members selected

    6. Click Create.

    Step 2: Enable Microsoft Defender XDR Unified Role-based Access (RBAC) in Microsoft Defender for Endpoint

    Create a RBAC role within Defender for your endpoint, and then assign the Red Canary Entra AD security group to the role.

    1. Navigate to https://security.microsoft.com, and log in with your global administrator account. 

    2. Select Settings | Endpoints | Roles | Create Custom Role.

    3. Fill out the form with the following values:

      • Role Name: Red Canary

      • Description: Red Canary Access Role

    4. Click Next.

    5. Under Permissions, select Security Operations.

    6. Check the following boxes:

      1. Select custom permissions

      2. Security data

        1. Select custom permissions

          1. Security data basics (read)

      3. Raw data (Email and collaboration)

        1. Select custom permissions

          1. Email & collaboration metadata (read)

    7. Click Apply.

    8. Click Authorization and settings, then click Next.

    9. Check the following boxes.

      1. Select custom permissions.

      2. Authorization

        1. Select Read-only.

      3. Security Settings

        1. Select custom permissions.

          1. Core security settings (read)

      4. System settings

        1. Read-only (Defender for Office, Defender for Identity)

    10. Click Apply.

    11. Click Next.

    12. Click Create assignment (or +add assignment).

    13. Click Next.

    14. Add the Assignment name.

      Note: The name should reflect the assignment.

    15. Assign the users and groups.

    16. From Data Sources ensure all the boxes are checked.

    17. Click Add.

    18. Click Next.

    19. Review the content and click Submit.

    Step 3: Entra ID–Add a Red Canary shared user account

    Invite the Red Canary shared user account to Azure AD, and then add the account to the Azure AD security group that was created in Step 1.

    1. Navigate to your Azure Portal and log in with your Global or Security Administrator Microsoft account. 

    2. Expand the navigation pane and click Entra ID

    3. Click Users

    4. Click Invite User.

    5. Fill in the group parameters with the following: 

      1. Identity

        • User Name: redcanary

        • Email Address:

        • Name: Red Canary

        • First Name: Leave blank

        • Last Name: Leave blank

      2. Groups and Roles

        • Groups: Select the Red Canary group you just created

        • Roles: Don't select a role

      3. Settings

        • Block Login: Off

        • Usage Location: United States

      4. Job Info: Leave blank

    6. Click Create.


    Was this article helpful?