You can delegate the below-listed Defender roles to the users or groups you want. If necessary, you can delegate two or more roles to the same user.
| 
 Role  | 
 Description  | 
| 
 Administrator  | 
 Members of this role can modify any Defender object and have complete control over the Defender configuration. This includes modification of all user-based Defender items. Members of this role can: 
  | 
| 
 Basic Helpdesk  | 
 Members of this role can: 
  | 
| 
 Provisioning  | 
 Members of this role can: 
  | 
| 
 Enhanced Helpdesk  | 
 Members of this role can: 
  | 
| 
 Auditor  | 
 Members of this role have read-only access to 
  |