A cloud-native solution that protects workloads across hybrid and multi-cloud environments with threat detection and security recommendations
Adding or editing exclusions in a Defender EASM discovery group requires the same permissions as managing discovery groups and seeds. Being able to sign in to EASM is not sufficient if the account lacks the necessary role/rights on the discovery configuration.
To adjust exclusions successfully:
- Verify that the account has the appropriate security/administrative role in the tenant that grants rights to manage Defender EASM discovery (for example, the role that allows creating and editing discovery groups and seeds). If the account is only a reader or has limited security roles, exclusion changes will fail even though the portal is accessible.
- If role changes were just made, sign out of the Azure portal/EASM and sign back in to refresh the token, then retry adding the exclusion.
- Ensure that exclusions are being added within an existing discovery group from the Discovery page, where seeds and exclusions are managed together. Exclusions are tied to a specific discovery group and only affect future runs for that group.
- If the error persists after confirming roles and reauthentication, have a higher-privileged admin (such as a security admin for Defender EASM) attempt the same exclusion change to confirm it is a permission issue, then open a support case if both accounts fail.
References: