You use Azure Sentinel.
You need to use a built-in role to provide a security analyst with the ability to edit the queries of custom Azure Sentinel workbooks. The solution must use the principle of least privilege.
Which role should you assign to the analyst?
Azure Sentinel Contributor can create and edit workbooks, analytics rules, and other Azure Sentinel resources.
Currently there are no comments in this discussion, be the first to comment!