A cloud-native solution that protects workloads across hybrid and multi-cloud environments with threat detection and security recommendations
Hello @Ravi Singh,
However, there are some limitations and considerations:
- The
RbacGroupNameproperty is included in the data returned by the API, which indicates the role-based access control (RBAC) group associated with a device. If a device isn’t assigned to any RBAC group, the value will be “Unassigned”. If there are no RBAC groups in the organization, it will show as “None”. - The RBAC model used in Microsoft Defender is separate from Azure RBAC, meaning it must be configured independently. This separation can lead to complexities when filtering data based on RBAC scopes. Additionally, some known issues include that the global scopes filter is not fully integrated, and there may be limitations in visualizations and aggregated scores due to permission boundaries.
- If the
RbacNamefilter is not functioning as expected, consider using theRbacGroupNameproperty directly in your API calls to filter the results based on the available RBAC groups. Ensure that you have the necessary permissions to access the data, as permissions likeVulnerability.Read.Allare required to call this API.
If this answers your query, do click Accept Answer and Up-Vote for the same. And, if you have any further query do let us know.