Azure Security built-in role

Microsoft Sentinel Playbook Operator

Lists, views, and manually runs Microsoft Sentinel playbooks in the assigned resource group without creating or editing those Logic Apps. Its Actions obtain Logic Apps and Web Apps workflow-trigger callback URLs. It does not itself grant incident access, so an analyst also needs Microsoft Sentinel Responder for incident-driven manual execution.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 51d6186e-6489-4900-b93f-92e23144cca5

Control-plane actions (4)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign on the resource group containing the approved Sentinel playbooks. Parent assignments are inherited and can expose playbooks in additional groups. Microsoft recommends aligning the Sentinel and playbook resource-group design so related assignments remain manageable.

Common use cases (2)

Prerequisites (3)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign Microsoft Sentinel Playbook Operator to analysts on the dedicated playbook resource group and pair it with Sentinel Responder on the Sentinel resource group for incident response. Keep Logic App editing and Sentinel service automation on their separately documented roles.

Related roles (2)

Editorial sources (7)

Official Microsoft Learn documentation →