last sync: 2025-May-30 17:23:17 UTC

Microsoft Sentinel Playbook Operator

Azure BuiltIn RBAC Role definition

NameMicrosoft Sentinel Playbook Operator
Microsoft Learn
Id51d6186e-6489-4900-b93f-92e23144cca5
DescriptionMicrosoft Sentinel Playbook Operator
CategorySecurity
Microsoft Learn
CreatedOn2022-09-20 17:17:53 UTC
UpdatedOn2022-12-07 18:28:46 UTC
Permissions summary Effective control plane and data plane operations: 4 (unique operations)
•action: 2
•read: 2

Actions: 4
Resolved control plane operations from Actions: 4
Effective control plane operations: 4
•action: 2
•read: 2

NotActions: 0
Resolved control plane operations from NotActions: 0
Effective denied control plane operations: 16579

DataActions: 0
Resolved data plane operations: 0
Effective data plane operations: 0

NotDataActions: 0
Resolved data plane operations from NotDataActions: 0
Effective denied data plane operations: 3558
Actions
Operation Description
Microsoft.Logic/workflows/readReads the workflow.
Microsoft.Logic/workflows/triggers/listCallbackUrl/actionGets the callback URL for trigger.
Microsoft.Web/sites/hostruntime/webhooks/api/workflows/triggers/listCallbackUrl/actionGet Web Apps Hostruntime Workflow Trigger Uri.
Microsoft.Web/sites/readGet the properties of a Web App
NotActions n/a
DataActions n/a
NotDataActions n/a
Used in
BuiltIn Policy
none
History
Date/Time (UTC ymd) (i) Change Change detail
2022-12-08 17:44:50 change: Actions Actions: 'add Microsoft.Web/sites/hostruntime/webhooks/api/workflows/triggers/listCallbackUrl/action; add Microsoft.Web/sites/read'
2022-10-24 16:44:14 change: Actions Actions: 'remove Microsoft.SecurityInsights/*/read'
2022-09-26 16:35:37 change: Actions Actions: 'add Microsoft.Logic/workflows/read; add Microsoft.Logic/workflows/triggers/listCallbackUrl/action'
2022-09-20 16:36:14 add: Role 51d6186e-6489-4900-b93f-92e23144cca5
JSON
api-version=2023-07-01-preview
{9 items
  • roleName: "Microsoft Sentinel Playbook Operator",
  • type: "BuiltInRole",
  • description: "Microsoft Sentinel Playbook Operator",
  • assignableScopes: [1 item
    • "/"
    ],
  • permissions: [1 item
    • {4 items
      • actions: [4 items
        • "Microsoft.Logic/workflows/read",
        • "Microsoft.Logic/workflows/triggers/listCallbackUrl/action",
        • "Microsoft.Web/sites/hostruntime/webhooks/api/workflows/triggers/listCallbackUrl/action",
        • "Microsoft.Web/sites/read"
        ],
      • notActions: [],
      • dataActions: [],
      • notDataActions: []
      }
    ],
  • createdOn: "2022-09-20T17:17:53.1732035Z",
  • updatedOn: "2022-12-07T18:28:46.3977543Z",
  • createdBy: null,
  • updatedBy: null
}
Condition none