Findings
Generator
Configuration
Lucidum Reverse
Architecture
Statistics
← All Findings
Vendor:
Microsoft Defender for Endpoint
FIN-263
Weight:
5
4
3
2
1
Confidence:
High
Medium
Low
Edited:
2026-03-06 09:03
Verified
What It Detects
A device explicitly marked as High value in Microsoft Defender for Endpoint has no RBAC device group assignment. This means a critical asset lacks scoped access controls — any analyst with broad permissions could access it, while the designated team responsible for high-value assets may not have it in their scope. This represents a significant governance failure for the organization's most important assets.
MITRE ATT&CK Techniques
Comma-separated, e.g. T1078, T1190
Checks
read-only
Field
Operator
Value
deviceValue
equals
High
rbacGroupId
equals
0
Remediation
×
×
×
×
+ Add item
Why It Matters
×
×
×
+ Add item
Save Changes
Export Lucidum