Microsoft sentinel Playbook permission issue

Anusree Pal 0 Reputation points
2023-12-27T13:10:49.6966667+00:00

We are receiving this error whener trying to integrate any logic app with the automation rule. We have added the Sentinel contributor rolein te system assigned MI and also added a few roles in the resource group and log analytics workspace as shown below. we are also not getting the option in the settings of the microsoft sentinel to add playbook permission , please help. User's image

User's image

enter image description here

Azure Logic Apps
Azure Logic Apps
An Azure service that automates the access and use of data across clouds without writing code.
Microsoft Security | Microsoft Sentinel
{count} votes

1 answer

Sort by: Most helpful
  1. SamiL 0 Reputation points
    2024-01-02T14:09:50.7033333+00:00

    Hello,

    Based on the information provided it seems that Sentinel itself doesn't have permissions defined to the RG where playbooks are located. Also, the figure above seems to show permissions for 'incident-playbook' so at least for me it's unknown which permissions your own account is having. Could you share more details about the permissions set at the moment?

    When you open up Sentinel playbook permissions blade you should see all RGs as from the sub (based on your permissions) as well as defined permissions to Sentinel SP underneath 'Current permissions', see figures 1 & 2 below.

    If you have down-level permissions (for example Sentinel Contributor) and don't have owner permissions to all RGs you should still see the RGs but there should be mention 'No permissions. Only owner on the resource group can add permissions' at the end of the each RG.

    Browse RGsSentinel-1

    Current permissions

    Sentinel-2

    When you set permissions from Sentinel, it sets permissions to Entra ID Service Principal (Azure Security Insights) and you can confirm this from the RG where you're defining the permissions.

    Sentinel-3

    Let me know are you able to see the RGs and set permissions to Sentinel SP to the RG where playbook(s) are located. Lastly, I assume that all the resources are in the same subscription?

    Here is just in case links to relevant Sentinel documentation:

    https://learn.microsoft.com/en-us/azure/sentinel/roles

    https://learn.microsoft.com/en-us/azure/role-based-access-control/built-in-roles#microsoft-sentinel-playbook-operator

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.