Built-in Azure role whose holders manage security policy, alerts and recommendations in Microsoft Defender for Cloud. Role assignment and the creation of general policy definitions fall outside what it allows.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Security Admin in context, with comparison tables and the common traps.
Terms in this definition
- Role
How an actor normally or expectedly behaves, or the part a person takes in a process. A single actor may hold more than one role.
- MANAGE
A Unity Catalog privilege allowing a principal to grant and revoke access on an object, hand over its ownership and drop it, all without being the owner. It gives no data access by itself and is not part of
ALL PRIVILEGES. - Security policy
Implements row-level security for Fabric warehouses or SQL analytics endpoints by attaching an inline table-valued function, acting as filter predicate, onto a table. Excluded rows vanish quietly from reads, updates and deletes.
- Microsoft Defender for Cloud
Combines security posture management with workload protection: a free foundational CSPM tier, paid Defender plans, Secure Score and recommendations. Its regulatory compliance dashboard shows status only and blocks nothing.
- Role assignment
Gives access in Azure RBAC by binding three things together: who (a security principal), what (a role definition) and where (a scope).
- Exclusions
Scopes taken out of a policy assignment; they can only narrow its coverage, never widen it.
Related terms
- Azure Virtual Network Manager
Service for centrally managing connectivity, as hub-and-spoke or mesh, and security admin rules across VNets in many subscriptions. VNets in other tenants must be added as static members, because dynamic membership driven by Azure Policy works only within one tenant.
- Rule collection
A set of security admin rules, aimed at one or more network groups, held inside a security admin configuration of Azure Virtual Network Manager.
- Security admin configuration
In Azure Virtual Network Manager, the container for one or more collections of security admin rules. Each region accepts just one deployed configuration, so extra rules belong in new rule collections, not further configurations.