A cloud-native SIEM solution that provides intelligent security analytics and threat detection across systems
Hi Charles,
The 403 AUTOMATION_INSUFFICIENT_PERMISSIONS error indicates that the user is missing permissions in Microsoft Defender Unified RBAC, even if the required Azure RBAC roles are already assigned to the Sentinel workspace. Defender Unified RBAC centrally controls permissions for supported Defender and Sentinel experiences. [learn.microsoft.com], [learn.microsoft.com]
Please ask a Global Administrator or Security Administrator to:
- Go to Microsoft Defender portal > System > Permissions > Roles.
- Create or edit a Defender Unified RBAC role for the user.
- Grant the Manage permissions corresponding to:
- Detection tuning/configuration
- Security data automation rules
- Detection tuning/configuration
- Assign the role to
securityadmin1, ensuring that the assignment includes the required Sentinel workspace or applicable data source scope. - Allow time for permission propagation, then sign out, sign back in, and retry creating the automation rule.
The permissions reported in the error are:
microsoft.xdr/configuration/security/detectiontuning/manage
microsoft.xdr/secops/securitydata/automation/rules/manage
Also verify that the user has an appropriate Microsoft Sentinel Azure role, such as Microsoft Sentinel Contributor, at the workspace or resource-group scope. Sentinel continues to use Azure RBAC for SIEM workspace resources, while Defender portal functionality can additionally depend on Defender Unified RBAC. [learn.microsoft.com], [learn.microsoft.com]
As a diagnostic step, try creating the same rule from Azure portal > Microsoft Sentinel > Automation. If it works there but fails in the Defender portal, that strongly indicates a missing Defender Unified RBAC permission rather than a workspace-role problem. Microsoft supports automation rules in both portals. [learn.microsoft.com]
If all permissions are present and the 403 continues, capture the request ID, timestamp, tenant ID, workspace resource ID, and browser network response, then open a Microsoft support case because the role assignment may not be propagating correctly