Azure Security built-in role

Microsoft Sentinel Responder

Includes Microsoft Sentinel Reader visibility and manages automation rules, cases and incidents, entity playbook runs, threat-intelligence tags, and the published business-application undo operation. Its generic control-plane Actions also create and manage classic metric alerts, deployments, and support tickets. It cannot delete incidents or cases, cannot access ConfidentialWatchlists, and does not by itself grant the Playbook Operator permission required to run a playbook manually.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 3e150937-b8fe-4cfb-8069-0eaf05ecd056

Control-plane actions (29)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (4)

Assignable scopes (1)

Practical scope

Microsoft recommends assigning the role at the resource group containing the Sentinel workspace. A workspace-only assignment also requires the same assignment on the SecurityInsights solution and can require related resource assignments. Parent-scope access is inherited by every child workspace and extends the classic-alert, deployment, and support Actions across that parent scope.

Common use cases (2)

Prerequisites (3)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign Microsoft Sentinel Responder to security analysts at the Sentinel resource-group scope. Add Playbook Operator only on approved playbook resource groups, use Reader when Sentinel incident management is unnecessary while accounting for its generic control-plane Actions, and reserve Contributor for engineers who author analytics, automation, workbooks, or Content hub resources.

Related roles (3)

Editorial sources (7)

Official Microsoft Learn documentation →