Azure Security built-in role
Microsoft Sentinel Responder
Includes Microsoft Sentinel Reader visibility and manages automation rules, cases and incidents, entity playbook runs, threat-intelligence tags, and the published business-application undo operation. Its generic control-plane Actions also create and manage classic metric alerts, deployments, and support tickets. It cannot delete incidents or cases, cannot access ConfidentialWatchlists, and does not by itself grant the Playbook Operator permission required to run a playbook manually.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: 3e150937-b8fe-4cfb-8069-0eaf05ecd056
Control-plane actions (29)
Microsoft.SecurityInsights/*/readMicrosoft.SecurityInsights/dataConnectorsCheckRequirements/actionMicrosoft.SecurityInsights/automationRules/*Microsoft.SecurityInsights/cases/*Microsoft.SecurityInsights/incidents/*Microsoft.SecurityInsights/entities/runPlaybook/actionMicrosoft.SecurityInsights/threatIntelligence/indicators/appendTags/actionMicrosoft.SecurityInsights/threatIntelligence/indicators/query/actionMicrosoft.SecurityInsights/threatIntelligence/bulkTag/actionMicrosoft.SecurityInsights/threatIntelligence/indicators/appendTags/actionMicrosoft.SecurityInsights/threatIntelligence/indicators/replaceTags/actionMicrosoft.SecurityInsights/threatIntelligence/queryIndicators/actionMicrosoft.SecurityInsights/businessApplicationAgents/systems/undoAction/actionMicrosoft.OperationalInsights/workspaces/analytics/query/actionMicrosoft.OperationalInsights/workspaces/*/readMicrosoft.OperationalInsights/workspaces/dataSources/readMicrosoft.OperationalInsights/workspaces/savedSearches/readMicrosoft.OperationsManagement/solutions/readMicrosoft.OperationalInsights/workspaces/query/readMicrosoft.OperationalInsights/workspaces/query/*/readMicrosoft.OperationalInsights/workspaces/dataSources/readMicrosoft.OperationalInsights/querypacks/*/readMicrosoft.Insights/workbooks/readMicrosoft.Insights/myworkbooks/readMicrosoft.Authorization/*/readMicrosoft.Insights/alertRules/*Microsoft.Resources/deployments/*Microsoft.Resources/subscriptions/resourceGroups/readMicrosoft.Support/*
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (4)
Microsoft.SecurityInsights/cases/*/DeleteMicrosoft.SecurityInsights/incidents/*/DeleteMicrosoft.SecurityInsights/ConfidentialWatchlists/*Microsoft.OperationalInsights/workspaces/query/ConfidentialWatchlist/*
Assignable scopes (1)
/
Practical scope
Microsoft recommends assigning the role at the resource group containing the Sentinel workspace. A workspace-only assignment also requires the same assignment on the SecurityInsights solution and can require related resource assignments. Parent-scope access is inherited by every child workspace and extends the classic-alert, deployment, and support Actions across that parent scope.
Common use cases (2)
- Triage, assign, investigate, update, classify, and close Microsoft Sentinel incidents without authoring all Sentinel content.
- Run an approved manual incident-response playbook when the analyst also has Playbook Operator on the playbook resource group.
Prerequisites (3)
- Identify the Sentinel workspace and the incident-response team authorized to modify its incident records.
- For manual playbook execution, separately assign Microsoft Sentinel Playbook Operator on the resource group containing the playbooks.
- Guest users who assign incidents also need the separately documented Microsoft Entra Directory Reader role; this Azure role does not include it.
Best practices (3)
- Assign to the security analyst group at the Sentinel resource-group scope and use Reader for observers who do not change incidents.
- Keep playbook execution, Logic App editing, and Sentinel service automation on their separate roles and resource groups.
- Review incident and automation activity and cumulative role assignments regularly.
Security considerations (3)
- The role can change incident state, ownership, classification, comments, tags, and other response records that drive SOC workflow.
- Its built-in definition includes automation-rule changes, threat-intelligence tagging, entity playbook execution, and a business-application undo operation, but the documented manual playbook workflow still requires Playbook Operator and the service permission path.
- Incident and case deletion plus ConfidentialWatchlist access are explicitly excluded, but classic-alert, deployment, and support-ticket writes remain available even though no Azure RBAC DataActions are present.
Assignment guidance
Assign Microsoft Sentinel Responder to security analysts at the Sentinel resource-group scope. Add Playbook Operator only on approved playbook resource groups, use Reader when Sentinel incident management is unnecessary while accounting for its generic control-plane Actions, and reserve Contributor for engineers who author analytics, automation, workbooks, or Content hub resources.
Related roles (3)
- Microsoft Sentinel Reader: Microsoft documents Responder as Reader plus incident management; the Reader definition still carries generic classic-alert, deployment, and support Actions.
- Microsoft Sentinel Playbook Operator: Separate role required with incident access to run approved playbooks manually.
- Microsoft Sentinel Contributor: Adds Sentinel content and resource creation or editing for security engineers.
Editorial sources (7)
- Azure built-in roles for Security →
Supports: Description, Security considerations. Retrieved 2026-07-16.
- Steps to assign an Azure role →
Supports: Prerequisites, Assignment guidance. Retrieved 2026-07-16.
- Understand scope for Azure RBAC →
Supports: Practical scope, Best practices, Assignment guidance. Retrieved 2026-07-16.
- Best practices for Azure RBAC →
Supports: Best practices, Assignment guidance. Retrieved 2026-07-16.
- Roles and permissions in the Microsoft Sentinel platform →
Supports: Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-16.
- Automate Threat Response with Playbooks in Microsoft Sentinel →
Supports: Common use cases, Prerequisites, Best practices, Security considerations. Retrieved 2026-07-16.
- Automate and run Microsoft Sentinel playbooks →
Supports: Common use cases, Prerequisites, Best practices, Security considerations. Retrieved 2026-07-16.