Courseiva

SC-200 Manage a security operations environment Practice Question

Which TWO permissions are required for a user to manage Microsoft Sentinel playbooks?

⚠ Common exam trap

Many candidates assume only a Sentinel-specific role (like Microsoft Sentinel Contributor) is sufficient, forgetting that playbooks are built on Azure Logic Apps and thus require the Logic App Contributor role for direct management of the playbook resource itself.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Logic App Contributor

Microsoft Sentinel playbooks are built on Azure Logic Apps, so managing them requires the Logic App Contributor role to create, edit, and delete the underlying logic app resources. Additionally, Microsoft Sentinel Contributor is needed to attach playbooks to analytics rules or automation rules within Sentinel, as this involves modifying Sentinel-specific configurations. Without both roles, a user cannot fully manage playbooks in the Sentinel context.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Microsoft Sentinel Reader

    Why it's wrong here

    Microsoft Sentinel Reader grants read-only access to Sentinel resources, including playbooks, but lacks write and execute permissions. Managing playbooks requires creating or modifying the underlying Logic App definitions, which this role cannot do. Users with Reader can only view playbook configurations, not edit or run them, so it cannot satisfy either required permission.

  • ✓

    Logic App Contributor

    Why this is correct

    Logic App Contributor is one of the two required permissions because Sentinel playbooks are implemented as Azure Logic Apps. This role provides full management authority over Logic Apps, enabling users to create, edit, and execute the workflows that playbooks depend on. Without it, even with Sentinel-level permissions, the underlying playbook logic cannot be altered or run, making it essential for managing playbooks.

  • ✓

    Microsoft Sentinel Contributor

    Why this is correct

    Microsoft Sentinel Contributor is the second required permission because it grants write access to Sentinel resources, including the ability to attach playbooks to analytics rules and manage automation within the Sentinel workspace. This role allows users to create and edit playbook metadata in Sentinel, while the actual execution relies on Logic Apps permissions. Combining this with Logic App Contributor provides the two specific roles needed for full playbook management.

  • ✗

    Automation Operator

    Why it's wrong here

    Automation Operator is not applicable because it only permits listing and starting runbooks in Azure Automation, not managing them. Sentinel playbooks are based on Logic Apps, not Azure Automation runbooks, so this role does not grant any control over playbook definitions or execution. It also lacks write permissions entirely, making it insufficient for any playbook management task.

  • ✗

    Global Administrator

    Why it's wrong here

    Global Administrator provides tenant-wide permissions that include access to Sentinel and Logic Apps, but it is overprivileged and not the precise, least-privilege assignment for playbook management. The two required permissions are specifically Microsoft Sentinel Contributor and Logic App Contributor, which together grant exactly the necessary access. Using Global Administrator would work in practice but violates the principle of least privilege and is not the intended answer for managing playbooks.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on SC-200

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Which THREE permissions are required for a user to manage Microsoft Sentinel playbooks using Azure Logic Apps? (Choose three.)

hard
  • ✓ A.Microsoft Sentinel Contributor
  • ✓ B.Log Analytics Contributor
  • C.Global Administrator in Microsoft Entra ID
  • D.Reader on the Logic App
  • ✓ E.Contributor on the resource group containing the Logic App

Why A: Microsoft Sentinel Contributor is required because it grants the necessary permissions to create, update, and delete playbooks within Microsoft Sentinel, which are built on Azure Logic Apps. This role allows the user to manage playbooks as part of the security operations environment, including assigning playbooks to automation rules and incident triggers.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.