Entra SOC Identity Responder — The Right Role for Identity Incident Response

One of the most common anti-patterns in identity security is giving SOC analysts Global Administrator access — or User Administrator — because they need to disable accounts or revoke sessions during an incident. Those roles carry far more permission than incident response actually requires. Microsoft added the Entra SOC Identity Responder role to address exactly this. It is a privileged built-in role designed for one specific job: identity containment during active security incidents from the Microsoft Defender portal. ...

September 4, 2026 · 5 min · Tony Merisan