Forum Discussion

mergene's avatar
mergene
Brass Contributor
Aug 27, 2020

Custom Permissions for Azure Sentinel

Hi,

 

I want to give specific permissions to someone on Sentinel like below:

- full access to Threat Management(Incidents, Workbooks, Hunting, Notebooks) and Logs section

- read only access to all other sections.

 

is this possible? I couldn't see some of these settings on https://docs.microsoft.com/en-us/azure/role-based-access-control/resource-provider-operations#microsoftoperationalinsights

 

I especially want to limit analytic rule creation and playbook creation. 

 

2 Replies

  • Chi_Nguyen's avatar
    Chi_Nguyen
    Former Employee

    mergene , that is possible to customize the access as you described. Please refer to this article  for Playbook custom access, and this doc for more details on Alert Rule Creation custom access.

    • mergene's avatar
      mergene
      Brass Contributor

      Chi_Nguyen 

       

      If I give read permission to analytic rules and playbooks, how can I give full permission to Hunting and Workbook section? I can't find the permission for the Hunting. If I give several permission, it will be the union of those permissions I guess and won't work. 

Resources