services / Azure / Microsoft Sentinel incident playbook run

Runs a playbook (Logic App) against a Microsoft Sentinel incident on demand, executing the playbook's automation under its configured identity.

Playbooks run under their own managed identity, which often holds broad permissions to act on incidents and connected systems; on-demand invocation can drive that identity, so this is HIGH.


Microsoft.​SecurityInsights/​incidents/​runPlaybook/​action

Triggering a playbook executes its Logic App under the playbook's managed identity, letting an attacker drive that (often broadly permissioned) identity's access to connected systems.

Risks

Scope: HIGH

This privilege may grant access to sensitive data from a single organizational function, or allow interruption of a service supporting a single organizational function.

Links

  • https:​/​/​azure.​permissions.​cloud/​iam/​Microsoft.​SecurityInsights
  • https:​/​/​learn.​microsoft.​com/​en-​us/​azure/​role-​based-​access-​control/​resource-​provider-​operations
  • Contributed by P0 Security

    © 2023–present P0 Security and contributors to the IAM Privilege Catalog