Azure Security built-in role

Microsoft Sentinel Contributor

Provides Microsoft Sentinel Reader and Responder capabilities and manages Microsoft Sentinel resources, content, incidents, analytics and automation rules, saved searches, and workbooks. Its generic control-plane Actions also create and manage classic metric alerts, deployments, and support tickets. The definition excludes ConfidentialWatchlists and grants no DataActions.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: ab8e14d6-4a74-4a29-9ba8-549422addade

Control-plane actions (16)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (2)

Assignable scopes (1)

Practical scope

Microsoft recommends assignment at the resource group containing the Sentinel workspace so related resources are covered consistently. A workspace-only assignment also requires the same role on the SecurityInsights solution resource and can require additional resource assignments. Parent assignments are inherited by every child workspace and extend the classic-alert, deployment, and support Actions across that parent scope.

Common use cases (2)

Prerequisites (3)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign Microsoft Sentinel Contributor to security engineers at the Sentinel resource-group scope. Use Responder for incident operations and Reader when Sentinel incident and content changes are not required, while accounting for each role's generic control-plane Actions. Grant separate Logic App, Playbook Operator, and Automation Contributor assignments for the exact playbook workflow.

Related roles (2)

Common questions

When should I assign the Microsoft Sentinel Contributor Azure role?

Assign Microsoft Sentinel Contributor when you need to: Let a security engineer create and maintain analytics rules, automation rules, workbooks, hunting content, incidents, and other Sentinel resources.; and Install or update Microsoft Sentinel Content hub solutions and perform trusted automated management of a Sentinel workspace.. Practical scope: Microsoft recommends assignment at the resource group containing the Sentinel workspace so related resources are covered consistently. A workspace-only assignment also requires the same role on the SecurityInsights solution resource and can require additional resource assignments. Parent assignments are inherited by every child workspace and extend the classic-alert, deployment, and support Actions across that parent scope.

What permissions does the Microsoft Sentinel Contributor Azure role grant?

The role definition grants 16 combined control-plane and data-plane actions. Representative operations include: Microsoft.SecurityInsights/*; Microsoft.OperationalInsights/workspaces/analytics/query/action; Microsoft.OperationalInsights/workspaces/*/read; Microsoft.OperationalInsights/workspaces/savedSearches/*; Microsoft.OperationsManagement/solutions/read; and Microsoft.OperationalInsights/workspaces/query/read. Review the permission sections above for the complete definition and exclusions.

What are the security risks of the Microsoft Sentinel Contributor Azure role?

Key considerations when assigning Microsoft Sentinel Contributor: Changing analytics or automation rules can suppress detections, create false alerts, or trigger response playbooks.; The role can manage incidents and broad Sentinel content but is explicitly denied ConfidentialWatchlists access by the built-in definition.; and The role reads workspace security data through control-plane query actions and can change classic alerts, deployments, and support tickets even though the definition contains no Azure RBAC DataActions.. Follow the assignment guidance above and use the narrowest practical scope.

Editorial sources (7)

Official Microsoft Learn documentation →