services / Azure / Microsoft Sentinel incident playbook run
Runs a playbook (Logic App) against a Microsoft Sentinel incident on demand, executing the playbook's automation under its configured identity.
Playbooks run under their own managed identity, which often holds broad permissions to act on incidents and connected systems; on-demand invocation can drive that identity, so this is HIGH.
Microsoft.SecurityInsights/incidents/runPlaybook/action
Triggering a playbook executes its Logic App under the playbook's managed identity, letting an attacker drive that (often broadly permissioned) identity's access to connected systems.
Risks
Scope: HIGH
This privilege may grant access to sensitive data from a single organizational function, or allow interruption of a service supporting a single organizational function.
Links
Contributed by P0 Security
© 2023–present P0 Security and contributors to the IAM Privilege Catalog