Protection against phishing, malware, and other threats targeting email and collaboration tools in Microsoft 365
For least-privilege access to Microsoft Defender > Email & collaboration > Explorer with full Explorer functionality, assign these Unified RBAC permissions:
- Email & collaboration metadata (read)
- Required to view email metadata in Threat Explorer.
- Enables searching messages and viewing message details.
- Email & collaboration content (read)
- Required for email preview and attachment access.
- Enables viewing message content.
- Email & collaboration advanced actions (manage)
- Required to remediate emails from Threat Explorer.
- Enables remediation actions in Explorer.
If users need to move messages to another folder or delete messages from mailboxes, they also need the Search and Purge role in the Email & collaboration permission model. By default, this role is assigned only to the Data Investigator or Organization Management role groups, or it can be assigned through a custom role group.
Key scope notes:
- Unified RBAC applies only in the Defender portal.
- It does not apply to PowerShell, which uses Exchange Online RBAC.
- Some Defender for Office 365 features require additional Exchange Online permissions.
- Microsoft recommends least privilege and limiting use of Global Administrator.
If the organization is still using the legacy Email & collaboration roles model instead of Unified RBAC, the closest built-in full-access role group is:
- Security Administrator or Organization Management for full access to Explorer
- plus Preview to preview/download messages
- plus Search and Purge to move/delete messages from mailboxes
For a least-privilege design, create a custom Unified RBAC role containing only:
- Email & collaboration metadata (read)
- Email & collaboration content (read)
- Email & collaboration advanced actions (manage)
Then add Search and Purge only if mailbox move/delete actions are required.