A single place in the Defender portal to control who can do what. Administrators build their own roles and pick permissions that apply across several Defender products at once.
Also called Microsoft Defender unified role-based access control.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Microsoft Defender unified RBAC in context, with comparison tables and the common traps.
Terms in this definition
- CONTROL
Granting this on a securable gives all other permissions on it too, making it the most powerful SQL permission. At database scope that includes UNMASK and ALTER ANY MASK. Warehouse access through the Admin, Member or Contributor workspace roles carries it.
- AGDLP
Nesting pattern: users go into global groups, which go into domain local groups, which receive the permissions. AGUDLP adds universal groups for forests with several domains.
- APPLY
Evaluates a table-valued expression for every row on its left, inside
FROM. Think ofOUTER APPLYas a left outer join andCROSS APPLYas an inner join.