Microsoft Sentinel
Cloud and workloads

Run Playbooks

In brief

The page clarifies how to assign the Microsoft Sentinel Automation Contributor role through Azure Lighthouse, updates playbook run-history wording, and removes a statement about manually running playbooks on entities in the Defender portal.

What Defender admins need to know

Administrators using Azure Lighthouse should review the revised authorization example. No required action is stated.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Regardless of the context you came from, the last step in this procedure is from the Run playbook on <entity type> panel. This panel shows list of all playbooks that you have access to that were configured with the Microsoft Sentinel Entity Logic Apps trigger for the selected entity type.

On the *Run playbook on *<entity type> pane, select the Runs tab to see the playbook run history for a given entity. It might take a few seconds for any just-completed run to appear in the list. Selecting a specific run opens the full run log in Logic Apps.

Related content

For more information, see: