How to set up differnet roles to only see specific devices

Wilson, David 0 Reputation points
2025-08-22T15:06:56.2833333+00:00

Im trying to set up different roles based on device groups so that different support teams can only view their managed devices but not getting the results I expected.

  • New Entra ID group set up and required users added to it
  • All servers tagged as appropriate team names
  • Device Group created with Devices selected based on the Tag
  • Device Group Assigned to the required Entra ID group from step 1
  • Defender XDR role created with permissions to Vuln Mgmt Read
  • Assignment to the required Entra ID group from step 1

When logging in as a user in the Entra ID group, under the Devices option, all specific tag along with all untagged devices are visible. I was expecting this to only show the specific tag which was filtered in the device group.

Have I missed something, everything Ive read says it should hide untagged devices as well

Microsoft Security | Microsoft Defender | Other
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Marcin Policht 54,995 Reputation points MVP Volunteer Moderator
    2025-08-22T15:20:01.1233333+00:00

    Assigning a device group to an RBAC role does not automatically filter the Devices page for those users. Instead, it limits actions the user can perform to only the devices in that group. The Devices list still shows untagged/all devices for usability, but attempting an action (like querying or changing settings) outside the assigned group is blocked. Similarly, device groups filter actions, not the UI list. This is why untagged devices appear. Effectively, AFAIK, there is currently no way to completely hide unassigned devices from the Devices list in the portal.

    As a workaround, consider setting up dashboards filtered by device group (views filtered by device group).


    If the above response helps answer your question, remember to "Accept Answer" so that others in the community facing similar issues can easily find the solution. Your contribution is highly appreciated.

    hth

    Marcin


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.