Azure Security built-in role
Microsoft Sentinel Automation Contributor
Allows the Microsoft Sentinel service account to invoke playbooks in a resource group for incident-triggered manual runs and automation rules. Microsoft explicitly states that this role is for the Sentinel service account and is not used for user accounts; it reads workflow triggers and run state and can obtain trigger callback URLs.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: f4c81013-99ee-4d62-a7ee-b3f1f648599a
Control-plane actions (7)
Microsoft.Authorization/*/readMicrosoft.Logic/workflows/triggers/readMicrosoft.Logic/workflows/triggers/listCallbackUrl/actionMicrosoft.Logic/workflows/runs/readMicrosoft.Web/sites/hostruntime/webhooks/api/workflows/triggers/readMicrosoft.Web/sites/hostruntime/webhooks/api/workflows/triggers/listCallbackUrl/actionMicrosoft.Web/sites/hostruntime/webhooks/api/workflows/runs/read
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
Assign to the Azure Security Insights service principal on the resource group containing the approved playbooks. Once assigned, Microsoft Sentinel can run any playbook in that resource group. Broader scope is inherited and can expose additional playbooks, so playbook resource-group boundaries are security boundaries.
Common use cases (2)
- Allow Microsoft Sentinel automation rules to run approved incident or alert playbooks.
- Allow the Sentinel service account to run an incident-triggered playbook when an analyst starts it manually through Sentinel.
Prerequisites (3)
- Create and test the Logic Apps playbooks and place only mutually trusted playbooks in the resource group.
- Identify the Microsoft Sentinel Azure Security Insights service principal; do not assign this role to a user account.
- The administrator granting the service permission needs Owner or User Access Administrator on the playbook resource group.
Best practices (3)
- Use a dedicated playbook resource group and assign the role only to the Sentinel service account.
- Review each playbook trigger, connector identity, API connection, downstream permission, and automation rule before placing it in the authorized group.
- Monitor playbook invocations and remove the assignment from resource groups that no longer contain active Sentinel playbooks.
Security considerations (3)
- After assignment, Sentinel can run any playbook in the resource group, and those playbooks can perform the downstream remediation allowed by their connectors and managed identities.
- Trigger callback URL access is sensitive because it participates in workflow invocation.
- Assigning this service role to a human does not grant the documented analyst workflow and creates unsupported standing access.
Assignment guidance
Assign Microsoft Sentinel Automation Contributor to the Azure Security Insights service principal on the dedicated playbook resource group. Use Playbook Operator for analysts who run playbooks manually, and review all Logic App identities and connectors before granting the Sentinel service access.
Related roles (2)
- Microsoft Sentinel Playbook Operator: Microsoft documents Playbook Operator for a user to run playbooks manually, while Automation Contributor authorizes the Sentinel service account.
- Owner: Microsoft documents Owner, or User Access Administrator, as the authority required to grant Sentinel service access to the playbook resource group.
Editorial sources (7)
- Azure built-in roles for Security →
Supports: Description, Security considerations. Retrieved 2026-07-16.
- Steps to assign an Azure role →
Supports: Prerequisites, Assignment guidance. Retrieved 2026-07-16.
- Understand scope for Azure RBAC →
Supports: Practical scope, Best practices, Assignment guidance. Retrieved 2026-07-16.
- Best practices for Azure RBAC →
Supports: Best practices, Assignment guidance. Retrieved 2026-07-16.
- Roles and permissions in the Microsoft Sentinel platform →
Supports: Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-16.
- Automate Threat Response with Playbooks in Microsoft Sentinel →
Supports: Common use cases, Prerequisites, Best practices, Security considerations. Retrieved 2026-07-16.
- Automate and run Microsoft Sentinel playbooks →
Supports: Common use cases, Prerequisites, Best practices, Security considerations. Retrieved 2026-07-16.