Microsoft Sentinel - Unable to see resource group when configuring playbook permissions

JackMondu 5 Reputation points
2023-06-16T07:53:03.9+00:00

Hi all,

I am trying to create an Azure Logic App with Microsoft Sentinel as a trigger. I am faced with some blockers. Microsoft Sentinel does not have enough permission to run the playbooks.

I have created playbooks (with Sentinel as a trigger and others) in the same resource groups but I can't see any here.

My current roles:
Owner and Logic App Contributor

User's image

Pic#1

I have seen in other posts, support seemed to have mentioned about "Manage playbook permissions" as referenced in pic#2.Screenshot that shows the actions section with run playbook selected.

Pic#2

However, in my UI, I do not see that option.

User's image

Pic#3

Microsoft Security | Microsoft Sentinel
{count} vote

1 answer

Sort by: Most helpful
  1. JamesTran-MSFT 37,231 Reputation points Microsoft Employee Moderator
    2023-06-21T17:57:43.5533333+00:00

    @JackMondu

    Thank you for your post and I apologize for the delayed response!

    I understand that you're trying to create a Logic App (Playbook) within Microsoft Sentinel and are running into a potential permissions issue as detailed within your screenshots. To hopefully point you in the right direction or resolve your issue, I'll share some of my findings below.


    Findings:

    Referencing your first two screenshots, from the Manage Permissions page - It looks like your Sentinel Resource Group might already have the correct permission since it isn't populating under the Browse tab.

    To confirm this, can you share what you see under the Current Permissions tab?

    Note: If your Sentinel Resource Group isn't populating under the Current Permissions tab and you still aren't able to configure these permissions, please let me know. Additionally, I'd also make sure that your signed in user has Owner permissions on any resource group to which you want to grant Microsoft Sentinel permissions, and you have the Logic App Contributor role on any resource group containing playbooks you want to run. For more info.

    User's image

    I also noticed you mentioned not running into issues within your UI, as shown from your Automation rules page, and this is most likely due to your Resource Group already having the correct permission.

    You can see which Resource Group your Playbook is created in from the Active Playbooks tab.

    User's image


    Additional Links:

    I hope this helps!

    If you have any other questions, please let me know. Thank you for your time and patience throughout this issue.


    If the information helped address your question, please Accept the answer. This will help us and also improve searchability for others in the community who might be researching similar information.


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.