Azure Security built-in role

Microsoft Sentinel Playbook Operator

Lists, views, and manually runs Microsoft Sentinel playbooks in the assigned resource group without creating or editing those Logic Apps. Its Actions obtain Logic Apps and Web Apps workflow-trigger callback URLs. It does not itself grant incident access, so an analyst also needs Microsoft Sentinel Responder for incident-driven manual execution.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 51d6186e-6489-4900-b93f-92e23144cca5

Control-plane actions (4)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign on the resource group containing the approved Sentinel playbooks. Parent assignments are inherited and can expose playbooks in additional groups. Microsoft recommends aligning the Sentinel and playbook resource-group design so related assignments remain manageable.

Common use cases (2)

Prerequisites (3)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign Microsoft Sentinel Playbook Operator to analysts on the dedicated playbook resource group and pair it with Sentinel Responder on the Sentinel resource group for incident response. Keep Logic App editing and Sentinel service automation on their separately documented roles.

Related roles (2)

Common questions

When should I assign the Microsoft Sentinel Playbook Operator Azure role?

Assign Microsoft Sentinel Playbook Operator when you need to: Allow a security analyst to manually run an approved playbook from an incident, alert, or entity during investigation and response.; and List and inspect available Sentinel playbooks and their run entry points without granting playbook editing.. Practical scope: Assign on the resource group containing the approved Sentinel playbooks. Parent assignments are inherited and can expose playbooks in additional groups. Microsoft recommends aligning the Sentinel and playbook resource-group design so related assignments remain manageable.

What permissions does the Microsoft Sentinel Playbook Operator Azure role grant?

The role definition grants 4 combined control-plane and data-plane actions. Representative operations include: Microsoft.Logic/workflows/read; Microsoft.Logic/workflows/triggers/listCallbackUrl/action; Microsoft.Web/sites/hostruntime/webhooks/api/workflows/triggers/listCallbackUrl/action; and Microsoft.Web/sites/read. Review the permission sections above for the complete definition and exclusions.

What are the security risks of the Microsoft Sentinel Playbook Operator Azure role?

Key considerations when assigning Microsoft Sentinel Playbook Operator: Running a playbook can isolate machines, block accounts, modify tickets, or perform any other downstream action authorized to its connectors and managed identities.; The operator cannot edit the Logic App, but it can obtain trigger callback URLs and invoke a dangerous or compromised existing playbook.; and Playbook Operator without Responder does not authorize access to a Sentinel incident, and Responder without Playbook Operator does not authorize the manual playbook run.. Follow the assignment guidance above and use the narrowest practical scope.

Editorial sources (7)

Official Microsoft Learn documentation →