Name | Azure Sentinel Responder Microsoft docs |
Id | 3e150937-b8fe-4cfb-8069-0eaf05ecd056 |
Description | Azure Sentinel Responder |
CreatedOn | 2019-08-28 16:54:07 UTC |
UpdatedOn | 2020-12-08 13:06:10 UTC |
History |
Date/Time (UTC ymd) (i) |
Change |
Change detail |
2020-12-08 15:44:03 |
change: Actions |
Actions: 'add Microsoft.SecurityInsights/automationRules/*' |
2020-11-09 14:42:02 |
change: NotActions |
NotActions: 'add Microsoft.SecurityInsights/cases/*/Delete; add Microsoft.SecurityInsights/incidents/*/Delete' |
2020-11-04 15:39:11 |
change: Actions |
Actions: 'add Microsoft.Insights/myworkbooks/read' |
|
Actions |
Operation |
Description |
Used in other Roles |
Microsoft.Authorization/*/read | no description given |
API Management Service Contributor, API Management Service Operator Role, API Management Service Reader Role 115, Application Group Contributor, Application Insights Component Contributor, Application Insights Snapshot Debugger, Automation Job Operator, Automation Operator, Automation Runbook Operator, Autonomous Development Platform Data Contributor (Preview), Autonomous Development Platform Data Owner (Preview), Autonomous Development Platform Data Reader (Preview), Avere Contributor, Azure Arc Enabled Kubernetes Cluster User Role, Azure Arc Kubernetes Admin, Azure Arc Kubernetes Cluster Admin, Azure Arc Kubernetes Viewer, Azure Arc Kubernetes Writer, Azure Kubernetes Service RBAC Admin, Azure Kubernetes Service RBAC Cluster Admin, Azure Kubernetes Service RBAC Reader, Azure Kubernetes Service RBAC Writer, Azure Sentinel Automation Contributor, Azure Sentinel Contributor, Azure Sentinel Reader, Backup Contributor, Backup Operator, Backup Reader, Billing Reader, BizTalk Contributor, Blueprint Contributor, Blueprint Operator, CDN Endpoint Contributor, CDN Endpoint Reader, CDN Profile Contributor, CDN Profile Reader, Classic Network Contributor, Classic Storage Account Contributor, Classic Virtual Machine Contributor, ClearDB MySQL DB Contributor, Cognitive Services Contributor, Collaborative Data Contributor, Collaborative Runtime Operator, Cosmos DB Account Reader Role, Cosmos DB Operator, Data Box Contributor, Data Box Reader, Data Factory Contributor, Data Lake Analytics Developer, Desktop Virtualization Application Group Contributor, Desktop Virtualization Application Group Reader, Desktop Virtualization Contributor, Desktop Virtualization Host Pool Contributor, Desktop Virtualization Host Pool Reader, Desktop Virtualization Reader, Desktop Virtualization Session Host Operator, Desktop Virtualization User Session Operator, Desktop Virtualization Workspace Contributor, Desktop Virtualization Workspace Reader, Device Update Administrator, Device Update Content Administrator, Device Update Content Reader, Device Update Deployments Administrator, Device Update Deployments Reader, Device Update Reader, DevTest Labs User, Disk Backup Reader, Disk Restore Operator, Disk Snapshot Contributor, DNS Zone Contributor, DocumentDB Account Contributor, EventGrid Contributor, EventGrid EventSubscription Contributor, EventGrid EventSubscription Reader, HDInsight Cluster Operator, Integration Service Environment Contributor, Integration Service Environment Developer, Intelligent Systems Account Contributor, Key Vault Administrator, Key Vault Certificates Officer, Key Vault Contributor, Key Vault Crypto Officer, Key Vault Reader, Key Vault Secrets Officer, Kubernetes Cluster - Azure Arc Onboarding, Lab Creator, Logic App Contributor, Logic App Operator, Managed Identity Contributor, Managed Identity Operator, Network Contributor, New Relic APM Account Contributor, Private DNS Zone Contributor, Quota Request Operator Role, Redis Cache Contributor, Scheduler Job Collections Contributor, Search Service Contributor, Security Admin, Security Manager (Legacy), Security Reader, Services Hub Operator, SignalR AccessKey Reader, SignalR Contributor, Site Recovery Contributor, Site Recovery Operator, Site Recovery Reader, SQL DB Contributor, SQL Managed Instance Contributor, SQL Security Manager, SQL Server Contributor, Storage Account Backup Contributor Role, Storage Account Contributor, Support Request Contributor, Tag Contributor, Traffic Manager Contributor, Virtual Machine Contributor, Web Plan Contributor, Website Contributor |
Microsoft.Insights/alertRules/* | no description given |
API Management Service Contributor, API Management Service Operator Role, API Management Service Reader Role 85, Application Group Contributor, Application Insights Component Contributor, Application Insights Snapshot Debugger, Automation Job Operator, Automation Operator, Automation Runbook Operator, Avere Contributor, Azure Arc Enabled Kubernetes Cluster User Role, Azure Arc Kubernetes Admin, Azure Arc Kubernetes Cluster Admin, Azure Arc Kubernetes Viewer, Azure Arc Kubernetes Writer, Azure Kubernetes Service RBAC Admin, Azure Kubernetes Service RBAC Cluster Admin, Azure Kubernetes Service RBAC Reader, Azure Kubernetes Service RBAC Writer, Azure Sentinel Contributor, Azure Sentinel Reader, BizTalk Contributor, CDN Endpoint Contributor, CDN Endpoint Reader, CDN Profile Contributor, CDN Profile Reader, Classic Network Contributor, Classic Storage Account Contributor, Classic Virtual Machine Contributor, ClearDB MySQL DB Contributor, Cognitive Services Contributor, Collaborative Data Contributor, Collaborative Runtime Operator, Cosmos DB Operator, Data Factory Contributor, Data Lake Analytics Developer, Desktop Virtualization Application Group Contributor, Desktop Virtualization Contributor, Desktop Virtualization Host Pool Contributor, Desktop Virtualization Session Host Operator, Desktop Virtualization User Session Operator, Desktop Virtualization Workspace Contributor, Device Update Administrator, Device Update Content Administrator, Device Update Content Reader, Device Update Deployments Administrator, Device Update Deployments Reader, Device Update Reader, DNS Zone Contributor, DocumentDB Account Contributor, EventGrid Contributor, EventGrid EventSubscription Contributor, HDInsight Cluster Operator, Intelligent Systems Account Contributor, Key Vault Administrator, Key Vault Certificates Officer, Key Vault Contributor, Key Vault Crypto Officer, Key Vault Reader, Key Vault Secrets Officer, Kubernetes Cluster - Azure Arc Onboarding, Log Analytics Contributor, Logic App Contributor, Managed Identity Contributor, Managed Identity Operator, Monitoring Contributor, Network Contributor, New Relic APM Account Contributor, Private DNS Zone Contributor, Quota Request Operator Role, Redis Cache Contributor, Scheduler Job Collections Contributor, Search Service Contributor, Security Admin, Security Manager (Legacy), SignalR Contributor, Site Recovery Contributor, Site Recovery Operator, SQL DB Contributor, SQL Managed Instance Contributor, SQL Security Manager, SQL Server Contributor, Storage Account Contributor, Tag Contributor, Traffic Manager Contributor, Virtual Machine Contributor, Web Plan Contributor, Website Contributor |
Microsoft.Insights/myworkbooks/read | Read a private Workbook |
Azure Sentinel Contributor, Azure Sentinel Reader |
Microsoft.Insights/workbooks/read | Read a workbook |
Azure Sentinel Reader, Workbook Contributor, Workbook Reader |
Microsoft.OperationalInsights/workspaces/*/read | no description given |
Azure Sentinel Contributor, Azure Sentinel Reader, Data Purger 2, Security Admin, Security Reader |
Microsoft.OperationalInsights/workspaces/analytics/query/action | Search using new engine. |
Azure Sentinel Contributor, Azure Sentinel Reader, Log Analytics Reader |
Microsoft.OperationalInsights/workspaces/dataSources/read | Get datasources under a workspace. |
Azure Sentinel Contributor, Azure Sentinel Reader |
Microsoft.OperationalInsights/workspaces/dataSources/read | Get datasources under a workspace. |
Azure Sentinel Contributor, Azure Sentinel Reader |
Microsoft.OperationalInsights/workspaces/query/*/read | no description given |
Azure Sentinel Contributor, Azure Sentinel Reader |
Microsoft.OperationalInsights/workspaces/query/read | Run queries over the data in the workspace |
Azure Sentinel Contributor, Azure Sentinel Reader |
Microsoft.OperationalInsights/workspaces/savedSearches/read | Gets a saved search query |
Azure Sentinel Reader |
Microsoft.OperationsManagement/solutions/read | Get exiting OMS solution |
Azure Sentinel Contributor, Azure Sentinel Reader |
Microsoft.Resources/deployments/* | no description given |
API Management Service Contributor, API Management Service Operator Role, API Management Service Reader Role 82, Application Group Contributor, Application Insights Component Contributor, Application Insights Snapshot Debugger, Automation Job Operator, Automation Operator, Automation Runbook Operator, Avere Contributor, Azure Kubernetes Service Contributor Role, Azure Sentinel Contributor, Azure Sentinel Reader, Backup Contributor, Backup Operator, BizTalk Contributor, Blueprint Contributor, Blueprint Operator, CDN Endpoint Contributor, CDN Endpoint Reader, CDN Profile Contributor, CDN Profile Reader, Classic Network Contributor, Classic Storage Account Contributor, Classic Virtual Machine Contributor, ClearDB MySQL DB Contributor, Cognitive Services Contributor, Collaborative Data Contributor, Collaborative Runtime Operator, Cosmos DB Operator, Data Box Contributor, Data Factory Contributor, Data Lake Analytics Developer, Desktop Virtualization Application Group Contributor, Desktop Virtualization Contributor, Desktop Virtualization Host Pool Contributor, Desktop Virtualization Session Host Operator, Desktop Virtualization User Session Operator, Desktop Virtualization Workspace Contributor, Device Update Administrator, Device Update Content Administrator, Device Update Content Reader, Device Update Deployments Administrator, Device Update Deployments Reader, Device Update Reader, DNS Zone Contributor, DocumentDB Account Contributor, EventGrid Contributor, EventGrid EventSubscription Contributor, Intelligent Systems Account Contributor, Key Vault Administrator, Key Vault Certificates Officer, Key Vault Contributor, Key Vault Crypto Officer, Key Vault Reader, Key Vault Secrets Officer, Log Analytics Contributor, Logic App Contributor, Managed Application Contributor Role, Managed Applications Reader, Managed Identity Contributor, Managed Identity Operator, Network Contributor, New Relic APM Account Contributor, Private DNS Zone Contributor, Quota Request Operator Role, Redis Cache Contributor, Scheduler Job Collections Contributor, Search Service Contributor, Security Admin, Security Manager (Legacy), Services Hub Operator, SignalR Contributor, Site Recovery Contributor, Site Recovery Operator, SQL DB Contributor, SQL Managed Instance Contributor, SQL Security Manager, SQL Server Contributor, Storage Account Contributor, Tag Contributor, Traffic Manager Contributor, Virtual Machine Contributor, Web Plan Contributor, Website Contributor |
Microsoft.Resources/subscriptions/resourceGroups/read | Gets or lists resource groups. |
API Management Service Contributor, API Management Service Operator Role, API Management Service Reader Role 115, Application Group Contributor, Application Insights Component Contributor, Application Insights Snapshot Debugger, Automation Job Operator, Automation Operator, Automation Runbook Operator, Autonomous Development Platform Data Contributor (Preview), Autonomous Development Platform Data Owner (Preview), Autonomous Development Platform Data Reader (Preview), Avere Contributor, Avere Operator, Azure Arc Enabled Kubernetes Cluster User Role, Azure Arc Kubernetes Admin, Azure Arc Kubernetes Cluster Admin, Azure Arc Kubernetes Viewer, Azure Arc Kubernetes Writer, Azure Kubernetes Service RBAC Admin, Azure Kubernetes Service RBAC Cluster Admin, Azure Kubernetes Service RBAC Reader, Azure Kubernetes Service RBAC Writer, Azure Sentinel Contributor, Azure Sentinel Reader, Backup Contributor, Backup Operator, BizTalk Contributor, Blueprint Contributor, Blueprint Operator, CDN Endpoint Contributor, CDN Endpoint Reader, CDN Profile Contributor, CDN Profile Reader, Classic Network Contributor, Classic Storage Account Contributor, Classic Virtual Machine Contributor, ClearDB MySQL DB Contributor, Cognitive Services Contributor, Cognitive Services User, Collaborative Data Contributor, Collaborative Runtime Operator, Cosmos DB Account Reader Role, Cosmos DB Operator, Cost Management Contributor, Cost Management Reader, Data Box Contributor, Data Factory Contributor, Data Lake Analytics Developer, Desktop Virtualization Application Group Contributor, Desktop Virtualization Application Group Reader, Desktop Virtualization Contributor, Desktop Virtualization Host Pool Contributor, Desktop Virtualization Host Pool Reader, Desktop Virtualization Reader, Desktop Virtualization Session Host Operator, Desktop Virtualization User Session Operator, Desktop Virtualization Workspace Contributor, Desktop Virtualization Workspace Reader, Device Update Administrator, Device Update Content Administrator, Device Update Content Reader, Device Update Deployments Administrator, Device Update Deployments Reader, Device Update Reader, DevTest Labs User, Disk Restore Operator, Disk Snapshot Contributor, DNS Zone Contributor, DocumentDB Account Contributor, EventGrid Contributor, EventGrid EventSubscription Contributor, EventGrid EventSubscription Reader, Experimentation Administrator, Experimentation Contributor, HDInsight Cluster Operator, Intelligent Systems Account Contributor, Key Vault Administrator, Key Vault Certificates Officer, Key Vault Contributor, Key Vault Crypto Officer, Key Vault Reader, Key Vault Secrets Officer, Kubernetes Cluster - Azure Arc Onboarding, Lab Creator, Logic App Contributor, Logic App Operator, Managed Identity Contributor, Managed Identity Operator, Monitoring Metrics Publisher, Network Contributor, New Relic APM Account Contributor, Private DNS Zone Contributor, Quota Request Operator Role, Redis Cache Contributor, Reservation Purchaser, Scheduler Job Collections Contributor, Search Service Contributor, Security Admin, Security Manager (Legacy), Security Reader, Services Hub Operator, SignalR AccessKey Reader, SignalR Contributor, Site Recovery Contributor, Site Recovery Operator, SQL DB Contributor, SQL Managed Instance Contributor, SQL Security Manager, SQL Server Contributor, Storage Account Backup Contributor Role, Storage Account Contributor, Support Request Contributor, Tag Contributor, Traffic Manager Contributor, Virtual Machine Contributor, Web Plan Contributor, Website Contributor |
Microsoft.SecurityInsights/*/read | no description given |
Azure Sentinel Reader |
Microsoft.SecurityInsights/automationRules/* | no description given |
none |
Microsoft.SecurityInsights/cases/* | no description given |
none |
Microsoft.SecurityInsights/dataConnectorsCheckRequirements/action | Check user authorization and license |
Azure Sentinel Reader |
Microsoft.SecurityInsights/incidents/* | no description given |
none |
Microsoft.SecurityInsights/threatIntelligence/bulkTag/action | Bulk Tags Threat Intelligence |
none |
Microsoft.SecurityInsights/threatIntelligence/indicators/appendTags/action | Append tags to Threat Intelligence Indicator |
none |
Microsoft.SecurityInsights/threatIntelligence/indicators/appendTags/action | Append tags to Threat Intelligence Indicator |
none |
Microsoft.SecurityInsights/threatIntelligence/indicators/query/action | Query Threat Intelligence Indicators |
Azure Sentinel Reader |
Microsoft.SecurityInsights/threatIntelligence/indicators/replaceTags/action | Replace Tags of Threat Intelligence Indicator |
none |
Microsoft.SecurityInsights/threatIntelligence/queryIndicators/action | Query Threat Intelligence Indicators |
Azure Sentinel Reader |
Microsoft.Support/* | no description given |
API Management Service Contributor, API Management Service Operator Role, API Management Service Reader Role 112, Application Group Contributor, Application Insights Component Contributor, Application Insights Snapshot Debugger, Automation Job Operator, Automation Operator, Automation Runbook Operator, Avere Contributor, Azure Arc Enabled Kubernetes Cluster User Role, Azure Arc Kubernetes Admin, Azure Arc Kubernetes Cluster Admin, Azure Arc Kubernetes Viewer, Azure Arc Kubernetes Writer, Azure Kubernetes Service RBAC Admin, Azure Kubernetes Service RBAC Cluster Admin, Azure Kubernetes Service RBAC Reader, Azure Kubernetes Service RBAC Writer, Azure Sentinel Contributor, Azure Sentinel Reader, Backup Contributor, Backup Operator, Billing Reader, BizTalk Contributor, Blueprint Contributor, Blueprint Operator, CDN Endpoint Contributor, CDN Endpoint Reader, CDN Profile Contributor, CDN Profile Reader, Classic Network Contributor, Classic Storage Account Contributor, Classic Virtual Machine Contributor, ClearDB MySQL DB Contributor, Cognitive Services Contributor, Cognitive Services User, Collaborative Data Contributor, Collaborative Runtime Operator, Cosmos DB Account Reader Role, Cosmos DB Operator, Cost Management Contributor, Cost Management Reader, Data Box Contributor, Data Box Reader, Data Factory Contributor, Data Lake Analytics Developer, Desktop Virtualization Application Group Contributor, Desktop Virtualization Application Group Reader, Desktop Virtualization Contributor, Desktop Virtualization Host Pool Contributor, Desktop Virtualization Host Pool Reader, Desktop Virtualization Reader, Desktop Virtualization Session Host Operator, Desktop Virtualization User Session Operator, Desktop Virtualization Workspace Contributor, Desktop Virtualization Workspace Reader, Device Update Administrator, Device Update Content Administrator, Device Update Content Reader, Device Update Deployments Administrator, Device Update Deployments Reader, Device Update Reader, DNS Zone Contributor, DocumentDB Account Contributor, EventGrid Contributor, EventGrid EventSubscription Contributor, HDInsight Cluster Operator, Integration Service Environment Contributor, Integration Service Environment Developer, Intelligent Systems Account Contributor, Key Vault Administrator, Key Vault Certificates Officer, Key Vault Contributor, Key Vault Crypto Officer, Key Vault Reader, Key Vault Secrets Officer, Kubernetes Cluster - Azure Arc Onboarding, Lab Creator, Log Analytics Contributor, Log Analytics Reader, Logic App Contributor, Logic App Operator, Managed Identity Contributor, Managed Identity Operator, Monitoring Contributor, Monitoring Metrics Publisher, Monitoring Reader, Network Contributor, New Relic APM Account Contributor, Private DNS Zone Contributor, Quota Request Operator Role, Redis Cache Contributor, Resource Policy Contributor, Scheduler Job Collections Contributor, Search Service Contributor, Security Admin, Security Manager (Legacy), SignalR AccessKey Reader, SignalR Contributor, Site Recovery Contributor, Site Recovery Operator, Site Recovery Reader, SQL DB Contributor, SQL Managed Instance Contributor, SQL Security Manager, SQL Server Contributor, Storage Account Contributor, Support Request Contributor, Tag Contributor, Traffic Manager Contributor, User Access Administrator, Virtual Machine Contributor, Web Plan Contributor, Website Contributor |
|
NotActions |
Operation |
Description |
Used in other Roles |
Microsoft.SecurityInsights/cases/*/Delete | no description given |
none |
Microsoft.SecurityInsights/incidents/*/Delete | no description given |
none |
|
DataActions |
n/a |
NotDataActions |
n/a |
Used in Policy |
none |
JSON |
{
"Name": "Azure Sentinel Responder",
"Id": "3e150937-b8fe-4cfb-8069-0eaf05ecd056",
"IsCustom": false,
"Description": "Azure Sentinel Responder",
"Actions": [
"Microsoft.SecurityInsights/*/read",
"Microsoft.SecurityInsights/dataConnectorsCheckRequirements/action",
"Microsoft.SecurityInsights/automationRules/*",
"Microsoft.SecurityInsights/cases/*",
"Microsoft.SecurityInsights/incidents/*",
"Microsoft.SecurityInsights/threatIntelligence/indicators/appendTags/action",
"Microsoft.SecurityInsights/threatIntelligence/indicators/query/action",
"Microsoft.SecurityInsights/threatIntelligence/bulkTag/action",
"Microsoft.SecurityInsights/threatIntelligence/indicators/appendTags/action",
"Microsoft.SecurityInsights/threatIntelligence/indicators/replaceTags/action",
"Microsoft.SecurityInsights/threatIntelligence/queryIndicators/action",
"Microsoft.OperationalInsights/workspaces/analytics/query/action",
"Microsoft.OperationalInsights/workspaces/*/read",
"Microsoft.OperationalInsights/workspaces/dataSources/read",
"Microsoft.OperationalInsights/workspaces/savedSearches/read",
"Microsoft.OperationsManagement/solutions/read",
"Microsoft.OperationalInsights/workspaces/query/read",
"Microsoft.OperationalInsights/workspaces/query/*/read",
"Microsoft.OperationalInsights/workspaces/dataSources/read",
"Microsoft.Insights/workbooks/read",
"Microsoft.Insights/myworkbooks/read",
"Microsoft.Authorization/*/read",
"Microsoft.Insights/alertRules/*",
"Microsoft.Resources/deployments/*",
"Microsoft.Resources/subscriptions/resourceGroups/read",
"Microsoft.Support/*"
],
"NotActions": [
"Microsoft.SecurityInsights/cases/*/Delete",
"Microsoft.SecurityInsights/incidents/*/Delete"
],
"DataActions": [
],
"NotDataActions": [
],
"AssignableScopes": [
"/"
]
}
|