Forum Discussion
Azure Sentinel Automation (Preview) - Issue with Permission assignment
Javier-Soriano - I noticed an intresting one here.
Scenario 1: Unable to see Manage Permission Link
Although being a owner of the azure subscription and adding logic app contributor role to my user id within the customer tenant. I am not able to see the Manage Permission link at the sentinel automation rule. Why cant one edit the permission in this case ??
Do you expect the user to have Azure Sentinel Contributor role other than owner and logic app contributor. ??
Scenario 2: Able to see Manage Permission Link but cannot modify.
With Azure lighthouse after including delegation of Azure Security Insights with Azure Sentinel Contributor role from the service provider tenant I am able to check its permission but not change it, this is acceptable as I am NOT in the service provider tenant and with Azure Lighthouse a user can max have a contributor role.
For scenario #2, azure security insights app must have Azure Sentinel Automation Contributor (not Azure Sentinel Contributor).
- Dec 09, 2021
In my scenario i am using analytical rule and runbook both in primary tenant. I have contributor level permissions on resource group containing sentinel and logic apps, rg containing runbook is already allowed permission to run runbook from Sentinel Setting runbook permissions.
When I try to run the runbook from incident alerts I am getting Missing Permissions to view playbook runs.
We are using Lighthouse but here we are not doing anything cross tenant in terms of Sentinel.I have Sentinel Contributor role on the Lighthouse level as well.
- PrashTechTalkJun 15, 2021Brass ContributorAdding more details to those scenarios.
Scenario #1
I never mentioned I am the owner through Azure Lighthouse instead I am the guest user existing in the primary tenant.
Scenario 2.
Already assigned the Azure Sentinel Automation Contributor through Azure Lighthouse template deployment as stated earlier in my message.