{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-202-separate-analyst-permissions-from-sentinel-s-incident-playbook-authority/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-202-separate-analyst-permissions-from-sentinel-s-incident-playbook-authority/",
        "slug": "dse-20260909-202-separate-analyst-permissions-from-sentinel-s-incident-playbook-authority",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-202-separate-analyst-permissions-from-sentinel-s-incident-playbook-authority/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-202-separate-analyst-permissions-from-sentinel-s-incident-playbook-authority.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-202-separate-analyst-permissions-from-sentinel-s-incident-playbook-authority/"
        },
        "title": "Separate analyst permissions from Sentinel's incident-playbook authority",
        "summary": "Why can an analyst open an incident but still be unable to run its playbook?",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "cyber-defense",
            "label": "Cyber defense",
            "alt": "Layered glass and metal cyber-defense structure with controlled blue and gold signal paths.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "cybersecurity",
                "name": "Cybersecurity",
                "url": "https://update.dsesecurity.com/topic/cybersecurity/"
            },
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:28:34+00:00",
        "modified_at": "2026-09-10T01:20:45+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 2,
        "word_count": 260,
        "potentially_affected": "Microsoft Sentinel incident playbooks run from the Microsoft Defender portal.",
        "dse_recommendation": "Identify whether the missing permission belongs to the operator or Sentinel's service account before changing access.",
        "primary_source": {
            "name": "Automate and run Microsoft Sentinel playbooks | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/azure/sentinel/automation/run-playbooks",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>Sentinel&#8217;s incident-playbook execution uses a service account as well as the analyst&#8217;s own permissions. That service account needs Microsoft Sentinel Automation Contributor on the playbook&#8217;s resource group; the grant permits execution of any playbook in that group. The Defender portal distinguishes Missing permissions for the operator&#8217;s Playbook Operator role from Grant permission for Sentinel&#8217;s missing service role. <a href=\"https://learn.microsoft.com/en-us/azure/sentinel/automation/run-playbooks\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<p>Granting Sentinel that access requires Owner or User Access Administrator authority on the resource group. The source also lists incident access and Logic App Contributor prerequisites; the visible status is not a complete role inventory. <a href=\"https://learn.microsoft.com/en-us/azure/sentinel/automation/run-playbooks\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Review Microsoft Sentinel incident playbooks run from the Microsoft Defender portal. Check the complete current prerequisites for the intended execution path; do not treat permissions for an alert or an entity as interchangeable with incident execution.</p>\n<h2>DSE recommendation</h2>\n<p>DSE recommends identifying the principal named by the failure before requesting a role change. Record the operator, Sentinel service account, playbook and containing resource group separately. Review the other playbooks in that group before approving service execution authority. Route permission changes to the authorized owner rather than granting the analyst broad administration simply to remove a disabled button.</p>\n<h2>Verification</h2>\n<p>Use an approved low-impact playbook against a test incident. Confirm the intended identities have their required scoped permissions, then inspect the resulting run in Logic Apps. Retain the role decision and run outcome without invoking unrelated response actions. A successful manual test should not be reported as verification of every automation rule or playbook in the group.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/azure/sentinel/automation/run-playbooks\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Run Sentinel playbooks</a>.</p>",
        "content_text": "Source facts\nSentinel’s incident-playbook execution uses a service account as well as the analyst’s own permissions. That service account needs Microsoft Sentinel Automation Contributor on the playbook’s resource group; the grant permits execution of any playbook in that group. The Defender portal distinguishes Missing permissions for the operator’s Playbook Operator role from Grant permission for Sentinel’s missing service role. Microsoft Learn.\nGranting Sentinel that access requires Owner or User Access Administrator authority on the resource group. The source also lists incident access and Logic App Contributor prerequisites; the visible status is not a complete role inventory. Microsoft Learn.\nApplicability\nReview Microsoft Sentinel incident playbooks run from the Microsoft Defender portal. Check the complete current prerequisites for the intended execution path; do not treat permissions for an alert or an entity as interchangeable with incident execution.\nDSE recommendation\nDSE recommends identifying the principal named by the failure before requesting a role change. Record the operator, Sentinel service account, playbook and containing resource group separately. Review the other playbooks in that group before approving service execution authority. Route permission changes to the authorized owner rather than granting the analyst broad administration simply to remove a disabled button.\nVerification\nUse an approved low-impact playbook against a test incident. Confirm the intended identities have their required scoped permissions, then inspect the resulting run in Logic Apps. Retain the role decision and run outcome without invoking unrelated response actions. A successful manual test should not be reported as verification of every automation rule or playbook in the group.\nOfficial references\nMicrosoft Learn: Run Sentinel playbooks.",
        "content_markdown": "## Source facts\n\nSentinel’s incident-playbook execution uses a service account as well as the analyst’s own permissions. That service account needs Microsoft Sentinel Automation Contributor on the playbook’s resource group; the grant permits execution of any playbook in that group. The Defender portal distinguishes Missing permissions for the operator’s Playbook Operator role from Grant permission for Sentinel’s missing service role. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/sentinel/automation/run-playbooks).\n\nGranting Sentinel that access requires Owner or User Access Administrator authority on the resource group. The source also lists incident access and Logic App Contributor prerequisites; the visible status is not a complete role inventory. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/sentinel/automation/run-playbooks).\n\n## Applicability\n\nReview Microsoft Sentinel incident playbooks run from the Microsoft Defender portal. Check the complete current prerequisites for the intended execution path; do not treat permissions for an alert or an entity as interchangeable with incident execution.\n\n## DSE recommendation\n\nDSE recommends identifying the principal named by the failure before requesting a role change. Record the operator, Sentinel service account, playbook and containing resource group separately. Review the other playbooks in that group before approving service execution authority. Route permission changes to the authorized owner rather than granting the analyst broad administration simply to remove a disabled button.\n\n## Verification\n\nUse an approved low-impact playbook against a test incident. Confirm the intended identities have their required scoped permissions, then inspect the resulting run in Logic Apps. Retain the role decision and run outcome without invoking unrelated response actions. A successful manual test should not be reported as verification of every automation rule or playbook in the group.\n\n## Official references\n\n[Microsoft Learn: Run Sentinel playbooks](https://learn.microsoft.com/en-us/azure/sentinel/automation/run-playbooks)."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-202-separate-analyst-permissions-from-sentinel-s-incident-playbook-authority/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-202-separate-analyst-permissions-from-sentinel-s-incident-playbook-authority/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-202-separate-analyst-permissions-from-sentinel-s-incident-playbook-authority/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Separate analyst permissions from Sentinel's incident-playbook authority",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-202-separate-analyst-permissions-from-sentinel-s-incident-playbook-authority/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-202-separate-analyst-permissions-from-sentinel-s-incident-playbook-authority/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-202-separate-analyst-permissions-from-sentinel-s-incident-playbook-authority/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-202-separate-analyst-permissions-from-sentinel-s-incident-playbook-authority/",
                "headline": "Separate analyst permissions from Sentinel's incident-playbook authority",
                "description": "Why can an analyst open an incident but still be unable to run its playbook?",
                "abstract": "Why can an analyst open an incident but still be unable to run its playbook?",
                "articleBody": "Source facts\nSentinel’s incident-playbook execution uses a service account as well as the analyst’s own permissions. That service account needs Microsoft Sentinel Automation Contributor on the playbook’s resource group; the grant permits execution of any playbook in that group. The Defender portal distinguishes Missing permissions for the operator’s Playbook Operator role from Grant permission for Sentinel’s missing service role. Microsoft Learn.\nGranting Sentinel that access requires Owner or User Access Administrator authority on the resource group. The source also lists incident access and Logic App Contributor prerequisites; the visible status is not a complete role inventory. Microsoft Learn.\nApplicability\nReview Microsoft Sentinel incident playbooks run from the Microsoft Defender portal. Check the complete current prerequisites for the intended execution path; do not treat permissions for an alert or an entity as interchangeable with incident execution.\nDSE recommendation\nDSE recommends identifying the principal named by the failure before requesting a role change. Record the operator, Sentinel service account, playbook and containing resource group separately. Review the other playbooks in that group before approving service execution authority. Route permission changes to the authorized owner rather than granting the analyst broad administration simply to remove a disabled button.\nVerification\nUse an approved low-impact playbook against a test incident. Confirm the intended identities have their required scoped permissions, then inspect the resulting run in Logic Apps. Retain the role decision and run outcome without invoking unrelated response actions. A successful manual test should not be reported as verification of every automation rule or playbook in the group.\nOfficial references\nMicrosoft Learn: Run Sentinel playbooks.",
                "datePublished": "2026-09-10T00:28:34+00:00",
                "dateModified": "2026-09-10T01:20:45+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-202-separate-analyst-permissions-from-sentinel-s-incident-playbook-authority/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-202-separate-analyst-permissions-from-sentinel-s-incident-playbook-authority/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/cyber-defense-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Separate analyst permissions from Sentinel's incident-playbook authority"
                },
                "articleSection": [
                    "Cybersecurity",
                    "IT"
                ],
                "keywords": [
                    "Cybersecurity",
                    "IT",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Cybersecurity",
                        "url": "https://update.dsesecurity.com/topic/cybersecurity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    }
                ],
                "wordCount": 260,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Automate and run Microsoft Sentinel playbooks | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/azure/sentinel/automation/run-playbooks"
                }
            }
        ]
    }
}