Azure Security built-in role
Microsoft Sentinel Contributor
Provides Microsoft Sentinel Reader and Responder capabilities and manages Microsoft Sentinel resources, content, incidents, analytics and automation rules, saved searches, and workbooks. Its generic control-plane Actions also create and manage classic metric alerts, deployments, and support tickets. The definition excludes ConfidentialWatchlists and grants no DataActions.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: ab8e14d6-4a74-4a29-9ba8-549422addade
Control-plane actions (16)
Microsoft.SecurityInsights/*Microsoft.OperationalInsights/workspaces/analytics/query/actionMicrosoft.OperationalInsights/workspaces/*/readMicrosoft.OperationalInsights/workspaces/savedSearches/*Microsoft.OperationsManagement/solutions/readMicrosoft.OperationalInsights/workspaces/query/readMicrosoft.OperationalInsights/workspaces/query/*/readMicrosoft.OperationalInsights/workspaces/dataSources/readMicrosoft.OperationalInsights/querypacks/*/readMicrosoft.Insights/workbooks/*Microsoft.Insights/myworkbooks/readMicrosoft.Authorization/*/readMicrosoft.Insights/alertRules/*Microsoft.Resources/deployments/*Microsoft.Resources/subscriptions/resourceGroups/readMicrosoft.Support/*
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (2)
Microsoft.SecurityInsights/ConfidentialWatchlists/*Microsoft.OperationalInsights/workspaces/query/ConfidentialWatchlist/*
Assignable scopes (1)
/
Practical scope
Microsoft recommends assignment at the resource group containing the Sentinel workspace so related resources are covered consistently. A workspace-only assignment also requires the same role on the SecurityInsights solution resource and can require additional resource assignments. Parent assignments are inherited by every child workspace and extend the classic-alert, deployment, and support Actions across that parent scope.
Common use cases (2)
- Let a security engineer create and maintain analytics rules, automation rules, workbooks, hunting content, incidents, and other Sentinel resources.
- Install or update Microsoft Sentinel Content hub solutions and perform trusted automated management of a Sentinel workspace.
Prerequisites (3)
- Identify the Sentinel workspace, its resource group, related solution resource, playbooks, and any data connectors with separate permissions.
- Use a separate Logic Apps role to create or edit playbooks and Playbook Operator or Automation Contributor for the documented run paths.
- The assigning administrator needs Microsoft.Authorization/roleAssignments/write at the Sentinel resource-group scope.
Best practices (3)
- Assign to security engineers at the Sentinel resource group and use Reader or Responder for analysts who do not author detection or automation content.
- Keep playbooks and connectors in reviewed resource groups and grant their separate Logic Apps and service-account permissions only when required.
- Review cumulative roles because another Azure, Log Analytics, or Sentinel assignment can add permissions beyond this role.
Security considerations (3)
- Changing analytics or automation rules can suppress detections, create false alerts, or trigger response playbooks.
- The role can manage incidents and broad Sentinel content but is explicitly denied ConfidentialWatchlists access by the built-in definition.
- The role reads workspace security data through control-plane query actions and can change classic alerts, deployments, and support tickets even though the definition contains no Azure RBAC DataActions.
Assignment guidance
Assign Microsoft Sentinel Contributor to security engineers at the Sentinel resource-group scope. Use Responder for incident operations and Reader when Sentinel incident and content changes are not required, while accounting for each role's generic control-plane Actions. Grant separate Logic App, Playbook Operator, and Automation Contributor assignments for the exact playbook workflow.
Related roles (2)
- Microsoft Sentinel Responder: Microsoft documents Responder as Reader plus incident management, while Contributor additionally creates and edits Sentinel resources and Content hub solutions.
- Microsoft Sentinel Playbook Operator: Separate role Microsoft documents for manually running playbooks; Sentinel Contributor alone does not supply the complete manual-run permission set.
Editorial sources (7)
- Azure built-in roles for Security →
Supports: Description, Security considerations. Retrieved 2026-07-16.
- Steps to assign an Azure role →
Supports: Prerequisites, Assignment guidance. Retrieved 2026-07-16.
- Understand scope for Azure RBAC →
Supports: Practical scope, Best practices, Assignment guidance. Retrieved 2026-07-16.
- Best practices for Azure RBAC →
Supports: Best practices, Assignment guidance. Retrieved 2026-07-16.
- Roles and permissions in the Microsoft Sentinel platform →
Supports: Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-16.
- Automate Threat Response with Playbooks in Microsoft Sentinel →
Supports: Common use cases, Prerequisites, Best practices, Security considerations. Retrieved 2026-07-16.
- Automate and run Microsoft Sentinel playbooks →
Supports: Common use cases, Prerequisites, Best practices, Security considerations. Retrieved 2026-07-16.