The Microsoft Sentinel Responder role allows users to investigate, triage, and resolve security incidents, which includes the ability to assign incidents to other users. This role is designed to provide the necessary permissions for incident management and response while still adhering to the principle of least privilege. Other roles such as Logic App Contributor and Microsoft Sentinel Contributor would have more permissions than necessary and may not be suitable for the analyst ' s needs. Microsoft Sentinel Reader role is not sufficient as it doesn ' t have permission to assign and resolve incidents. Reference: https://docs.microsoft.com/en-us/azur e/sentinel/role-based-access-control-rbac