Skip to content

Commit dd43bc6

Browse files
Merge pull request #253299 from austinmccollum/austinmc--roles-update
update roles
2 parents 86b7da8 + 922673f commit dd43bc6

7 files changed

+16
-14
lines changed

articles/sentinel/connect-mdti-data-connector.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -16,7 +16,7 @@ Bring high fidelity indicators of compromise (IOC) generated by Microsoft Defend
1616
>
1717
1818
## Prerequisites
19-
- In order to install, update and delete standalone content or solutions in content hub, you need the **Template Spec Contributor** role at the resource group level. See [Azure RBAC built in roles](../role-based-access-control/built-in-roles.md#template-spec-contributor) for details on this role.
19+
- In order to install, update and delete standalone content or solutions in content hub, you need the **Microsoft Sentinel Contributor** role at the resource group level.
2020
- To configure this data connector, you must have read and write permissions to the Microsoft Sentinel workspace.
2121

2222
## Install the Threat Intelligence solution in Microsoft Sentinel

articles/sentinel/connect-threat-intelligence-taxii.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -22,7 +22,7 @@ To import STIX formatted threat indicators to Microsoft Sentinel from a TAXII se
2222
Learn more about [Threat Intelligence](understand-threat-intelligence.md) in Microsoft Sentinel, and specifically about the [TAXII threat intelligence feeds](threat-intelligence-integration.md#taxii-threat-intelligence-feeds) that can be integrated with Microsoft Sentinel.
2323

2424
## Prerequisites
25-
- In order to install, update and delete standalone content or solutions in content hub, you need the **Template Spec Contributor** role at the resource group level. See [Azure RBAC built in roles](../role-based-access-control/built-in-roles.md#template-spec-contributor) for details on this role.
25+
- In order to install, update and delete standalone content or solutions in content hub, you need the **Microsoft Sentinel Contributor** role at the resource group level.
2626
- You must have read and write permissions to the Microsoft Sentinel workspace to store your threat indicators.
2727
- You must have a TAXII 2.0 or TAXII 2.1 **API Root URI** and **Collection ID**.
2828

articles/sentinel/connect-threat-intelligence-tip.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -28,7 +28,7 @@ Learn more about [Threat Intelligence](understand-threat-intelligence.md) in Mic
2828

2929
## Prerequisites
3030

31-
- In order to install, update and delete standalone content or solutions in content hub, you need the **Template Spec Contributor** role at the resource group level. See [Azure RBAC built in roles](../role-based-access-control/built-in-roles.md#template-spec-contributor) for details on this role.
31+
- In order to install, update and delete standalone content or solutions in content hub, you need the **Microsoft Sentinel Contributor** role at the resource group level.
3232
- You must have either the **Global administrator** or **Security administrator** Azure AD roles in order to grant permissions to your TIP product or to any other custom application that uses direct integration with the Microsoft Graph Security tiIndicators API.
3333
- You must have read and write permissions to the Microsoft Sentinel workspace to store your threat indicators.
3434

articles/sentinel/connect-threat-intelligence-upload-api.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -27,7 +27,7 @@ Learn more about [Threat Intelligence](understand-threat-intelligence.md) in Mic
2727
**See also**: [Connect Microsoft Sentinel to STIX/TAXII threat intelligence feeds](connect-threat-intelligence-taxii.md)
2828

2929
## Prerequisites
30-
- In order to install, update and delete standalone content or solutions in content hub, you need the **Template Spec Contributor** role at the resource group level. See [Azure RBAC built in roles](../role-based-access-control/built-in-roles.md#template-spec-contributor) for details on this role.
30+
- In order to install, update and delete standalone content or solutions in content hub, you need the **Microsoft Sentinel Contributor** role at the resource group level.
3131
- You must have read and write permissions to the Microsoft Sentinel workspace to store your threat indicators.
3232
- You must be able to register an Azure Active Directory (Azure AD) application.
3333
- The Azure AD application must be granted the Microsoft Sentinel contributor role at the workspace level.

articles/sentinel/quickstart-onboard.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -27,8 +27,8 @@ Microsoft Sentinel comes with many data connectors for Microsoft products such a
2727

2828
- To enable Microsoft Sentinel, you need **contributor** permissions to the subscription in which the Microsoft Sentinel workspace resides.
2929

30-
- To use Microsoft Sentinel, you need either **contributor** or **reader** permissions on the resource group that the workspace belongs to.
31-
- To install or manage solutions in the content hub, you need the **Template Spec Contributor** role on the resource group that the workspace belongs to.
30+
- To use Microsoft Sentinel, you need either **Microsoft Sentinel Contributor** or **Microsoft Sentinel Reader** permissions on the resource group that the workspace belongs to.
31+
- To install or manage solutions in the content hub, you need the **Microsoft Sentinel Contributor** role on the resource group that the workspace belongs to.
3232

3333
- **Microsoft Sentinel is a paid service**. Review the [pricing options](https://go.microsoft.com/fwlink/?linkid=2104058) and the [Microsoft Sentinel pricing page](https://azure.microsoft.com/pricing/details/azure-sentinel/).
3434

articles/sentinel/roles.md

Lines changed: 8 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -3,7 +3,7 @@ title: Roles and permissions in Microsoft Sentinel
33
description: Learn how Microsoft Sentinel assigns permissions to users using Azure role-based access control, and identify the allowed actions for each role.
44
author: yelevin
55
ms.topic: conceptual
6-
ms.date: 06/06/2023
6+
ms.date: 09/29/2023
77
ms.author: yelevin
88
---
99

@@ -23,7 +23,7 @@ Use Azure RBAC to create and assign roles within your security operations team t
2323

2424
- [**Microsoft Sentinel Responder**](../role-based-access-control/built-in-roles.md#microsoft-sentinel-responder) can, in addition to the above, manage incidents (assign, dismiss, etc.).
2525

26-
- [**Microsoft Sentinel Contributor**](../role-based-access-control/built-in-roles.md#microsoft-sentinel-contributor) can, in addition to the above, create and edit workbooks, analytics rules, and other Microsoft Sentinel resources.
26+
- [**Microsoft Sentinel Contributor**](../role-based-access-control/built-in-roles.md#microsoft-sentinel-contributor) can, in addition to the above, install and update solutions from content hub, create and edit workbooks, analytics rules, and other Microsoft Sentinel resources.
2727

2828
- [**Microsoft Sentinel Playbook Operator**](../role-based-access-control/built-in-roles.md#microsoft-sentinel-playbook-operator) can list, view, and manually run playbooks.
2929

@@ -41,7 +41,7 @@ Users with particular job requirements may need to be assigned other roles or sp
4141

4242
- **Install and manage out-of-the-box content**
4343

44-
Find packaged solutions for end-to-end products or standalone content from the content hub in Microsoft Sentinel. To install and manage content from the content hub, assign the [**Template Spec Contributor**](../role-based-access-control/built-in-roles.md#template-spec-contributor) role at the resource group level.
44+
Find packaged solutions for end-to-end products or standalone content from the content hub in Microsoft Sentinel. To install and manage content from the content hub, assign the **Microsoft Sentinel Contributor** role at the resource group level. For some solutions, the [**Template Spec Contributor**](../role-based-access-control/built-in-roles.md#template-spec-contributor) role is still required.
4545

4646
- **Automate responses to threats with playbooks**
4747

@@ -83,13 +83,15 @@ This table summarizes the Microsoft Sentinel roles and their allowed actions in
8383
|---|---|---|---|---|---|--|
8484
| Microsoft Sentinel Reader | -- | -- | --[*](#workbooks) | -- | ✓ | --|
8585
| Microsoft Sentinel Responder | -- | -- | --[*](#workbooks) | ✓ | ✓ | --|
86-
| Microsoft Sentinel Contributor | -- | -- | ✓ | ✓ | ✓ | --|
86+
| Microsoft Sentinel Contributor | -- | -- | ✓ | ✓ | ✓ | ✓|
8787
| Microsoft Sentinel Playbook Operator | ✓ | -- | -- | -- | -- | --|
8888
| Logic App Contributor | ✓ | ✓ | -- | -- | -- |-- |
89-
| Template Spec Contributor | -- | -- | -- | -- | -- |✓ |
89+
| Template Spec Contributor | -- | -- | -- | -- | -- |✓[**](#content-hub) |
9090

9191
<a name=workbooks></a>* Users with these roles can create and delete workbooks with the [Workbook Contributor](../role-based-access-control/built-in-roles.md#workbook-contributor) role. Learn about [Other roles and permissions](#other-roles-and-permissions).
9292

93+
<a name=content-hub></a>** The requirement for the Template Spec Contributor role to install and manage content from content hub is still required for some edge cases in addition to Microsoft Sentinel Contributor.
94+
9395
Review the [role recommendations](#role-and-permissions-recommendations) for which roles to assign to which users in your SOC.
9496

9597
## Custom roles and advanced Azure RBAC
@@ -112,7 +114,7 @@ After understanding how roles and permissions work in Microsoft Sentinel, you ca
112114
| --------- | --------- | --------- | --------- |
113115
| **Security analysts** | [Microsoft Sentinel Responder](../role-based-access-control/built-in-roles.md#microsoft-sentinel-responder) | Microsoft Sentinel's resource group | View data, incidents, workbooks, and other Microsoft Sentinel resources. <br><br>Manage incidents, such as assigning or dismissing incidents. |
114116
| | [Microsoft Sentinel Playbook Operator](../role-based-access-control/built-in-roles.md#microsoft-sentinel-playbook-operator) | Microsoft Sentinel's resource group, or the resource group where your playbooks are stored | Attach playbooks to analytics and automation rules. <br>Run playbooks. |
115-
|**Security engineers** | [Microsoft Sentinel Contributor](../role-based-access-control/built-in-roles.md#microsoft-sentinel-contributor) |Microsoft Sentinel's resource group | View data, incidents, workbooks, and other Microsoft Sentinel resources. <br><br>Manage incidents, such as assigning or dismissing incidents. <br><br>Create and edit workbooks, analytics rules, and other Microsoft Sentinel resources. |
117+
|**Security engineers** | [Microsoft Sentinel Contributor](../role-based-access-control/built-in-roles.md#microsoft-sentinel-contributor) |Microsoft Sentinel's resource group | View data, incidents, workbooks, and other Microsoft Sentinel resources. <br><br>Manage incidents, such as assigning or dismissing incidents. <br><br>Create and edit workbooks, analytics rules, and other Microsoft Sentinel resources.<br><br>Install and update solutions from content hub. |
116118
| | [Logic Apps Contributor](../role-based-access-control/built-in-roles.md#logic-app-contributor) | Microsoft Sentinel's resource group, or the resource group where your playbooks are stored | Attach playbooks to analytics and automation rules. <br>Run and modify playbooks. |
117119
||[Template Spec Contributor](../role-based-access-control/built-in-roles.md#template-spec-contributor)|Microsoft Sentinel's resource group |Install and manage content from the content hub.|
118120
| **Service Principal** | [Microsoft Sentinel Contributor](../role-based-access-control/built-in-roles.md#microsoft-sentinel-contributor) | Microsoft Sentinel's resource group | Automated configuration for management tasks |

articles/sentinel/sentinel-solutions-deploy.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -3,7 +3,7 @@ title: Discover and deploy Microsoft Sentinel out-of-the-box content from Conten
33
description: Learn how to find and deploy Sentinel packaged solutions containing data connectors, analytics rules, hunting queries, workbooks, and other content.
44
author: austinmccollum
55
ms.topic: how-to
6-
ms.date: 06/22/2023
6+
ms.date: 09/29/2023
77
ms.author: austinmc
88
---
99

@@ -25,7 +25,7 @@ If you're a partner who wants to create your own solution, see the [Microsoft Se
2525

2626
## Prerequisites
2727

28-
In order to install, update and delete standalone content or solutions in content hub, you need the **Template Spec Contributor** role at the resource group level. See [Azure RBAC built in roles](../role-based-access-control/built-in-roles.md#template-spec-contributor) for details on this role.
28+
In order to install, update and delete standalone content or solutions in content hub, you need the **Microsoft Sentinel Contributor** role at the resource group level. In addition, the **Template Spec Contributor** role is still required for some edge cases. See [Azure RBAC built in roles](../role-based-access-control/built-in-roles.md#template-spec-contributor) for details on this role.
2929

3030
This is in addition to Sentinel specific roles. For more information about other roles and permissions supported for Microsoft Sentinel, see [Permissions in Microsoft Sentinel](roles.md).
3131

0 commit comments

Comments
 (0)