You have integrated Azure Sentinel to view and eliminate threats to your cloud before they cause problems. You need to assign users the following permissions:
Match the appropriate role(s) with the appropriate user. You must use the principle of least privilege. Some roles may have more than one permission, and permissions can be used more than once.
Explanation
You should choose the following:
The Azure Sentinel Reader role allows users to view incidents, dashboards, data, and other resources in Azure Sentinel.
The Azure Sentinel Responder role allows users to manage incidents such as dismissing incidents and assign incidents to others. This role also includes all permissions assigned to the Azure Sentinel Reader role.
The Azure Sentinel Contributor role includes all permissions from the Azure Sentinel Reader role and the Azure Sentinel Responder role plus the ability to create and edit analytic rules, dashboards, and other resources in Azure Sentinel.
You must assign Azure Sentinel Contributor as well as the Logic App Contributor to have the ability to create and run playbooks and edit analytic rules.
Objective:
Describe security, privacy, compliance, and trust
Sub-Objective:
Describe Azure security features
References:
Azure > Azure Sentinel > Permissions in Azure Sentinel
Post a Comment
Thanks for your comment