You can delegate the below-listed Defender roles to the users or groups you want. If necessary, you can delegate two or more roles to the same user.
| Role | Description | 
| Administrator | Members of this role can modify any Defender object and have complete control over the Defender configuration. This includes modification of all user-based Defender items. Members of this role can: 
 | 
| Basic Helpdesk | Members of this role can: 
 | 
| Provisioning | Members of this role can: 
 | 
| Enhanced Helpdesk | Members of this role can: 
 | 
| Auditor | Members of this role have read-only access to 
 | 
