Attention needed: Your tenant will be auto enabled to Microsoft Defender Unified RBAC (URBAC)
Microsoft announcement
[What and Why:]
Microsoft is automatically enabling Unified RBAC (URBAC) for eligible Microsoft Defender and Microsoft Sentinel workloads in selected tenants. Unified RBAC provides a single access management system for Defender portal experiences, adds enhanced scoping capabilities, and supports future permissions and workloads through a unified authorization model. Existing role assignments will be automatically imported and mapped before activation.
[Rollout Schedule:
- Notification will occur in late July 2026 with activation to follow in late September.
- Activation occurs approximately 60 days after the in-portal notification is received.
[Impact on Your Organization:]
Who is affected:
- Organizations that receive an in-portal notification indicating that Unified RBAC (URBAC) will be activated for eligible Microsoft Defender and Microsoft Sentinel workloads in their tenant.
- Security administrators responsible for managing Defender and Sentinel roles, permissions, and access.
- Organizations using custom Defender or Sentinel role assignments or role-management APIs.
Platforms/Services:
- Microsoft Defender Portal
- Microsoft Defender XDR
- Microsoft Sentinel
- Microsoft Defender for Office 365
- Microsoft Entra ID
- Microsoft Defender for Identity
- Microsoft Defender for Cloud Apps
- Microsoft Defender for Endpoint
What will happen:
- Unified RBAC role assignments will be automatically imported from existing Defender/Sentinel role configurations.
- Imported roles will have no operational impact until URBAC activation occurs.
- After activation, Defender and Sentinel portal authorization will use URBAC by default.
- Legacy Defender/Sentinel RBAC assignments will no longer be required for portal access after activation.
- Organizations can review, modify, or re-import role mappings before activation.
- Existing B2B and GDAP delegated access assignments remain supported and are migrated during import.
- Entra directory roles (Global Administrator, Security Administrator, Security Operator, and Security Reader) continue to grant Microsoft Defender portal access.
- Azure RBAC continues governing Azure resources such as Logic Apps and Workbooks.
- Exchange Online permissions and Microsoft Purview permissions remain unchanged for Exchange and Purview workloads.
- Defender for Office 365 portal access will rely on URBAC after activation rather than Exchange Online permissions.
- Organizations using role-management APIs must migrate to the Unified RBAC API.
- Self-service rollback is available after activation through the URBAC workload settings experience.
- The feature is enabled automatically following the 60-day notification period unless administrators choose to opt out afterward.
[Action Required/Recommendations:]
Complete the following tasks before activation:
- Review imported URBAC role assignments in Microsoft Defender portal > Permissions > Roles (under Microsoft Defender XDR)
- Validate that users, groups, and scopes were mapped correctly.
- Update internal operational procedures, runbooks, and access-control documentation to reflect URBAC.
- If you automate role assignments, begin planning migration to the Unified RBAC API.
- Communicate the upcoming authorization model change to security administrators and help desk teams.
- Document the opt-out process should a rollback to legacy RBAC become necessary after activation.
Learn more: Map existing RBAC permissions to Microsoft Defender unified RBAC permissions | Microsoft Learn
[Compliance Considerations:]
| Compliance Area | Explanation |
| Does the change alter how existing customer data is processed, stored, or accessed? | Authorization and access management for Microsoft Defender and Microsoft Sentinel portal experiences will transition from legacy RBAC models to Unified RBAC (URBAC). The underlying data is unchanged, but access governance and permissions management are modified. |
| Does the change alter how admins can monitor, report on, or demonstrate compliance activities? | Administrators will manage roles, permissions, and scopes through Unified RBAC. Organizations may need to update access review processes, audit procedures, and compliance documentation related to privileged access management. |
| Does the change include an admin control and can it be controlled through Entra ID group membership? | Administrators can review imported role assignments, modify permissions, re-run imports, and opt out after activation. Existing Entra directory roles continue to map into Unified RBAC permissions. |
| Does the change allow a user to enable and disable the feature themselves? | Authorized administrators can opt out of Unified RBAC after activation using the Unified RBAC workload settings experience in the Microsoft Defender portal. |
| Does the change modify Conditional Access policies? | No direct changes are described. Organizations should validate that migrated role assignments continue to align with existing Conditional Access policies and administrative access requirements. |
| Does the change modify Audit logging capabilities? | No audit logging changes are announced. However, organizations should verify whether reporting, access reviews, or audit workflows are affected by the new authorization model. |
| Does the change modify eDiscovery or Content Search capabilities? | No direct impact is stated. Organizations should confirm that users who perform investigations retain the appropriate permissions after role migration. |
| Does the change modify how users can access, export, delete, or correct personal data (GDPR/DSR)? | No changes to Data Subject Rights processes are described. Organizations should ensure privacy and compliance personnel retain necessary access. |
Change history
- 2026-08-07 · Created · All