Skip to main content

← Back to the article

Sources were checked September 11, 2026. Lab observations span September 11–12 UTC, all on September 11 in America/Chicago. No Defender permission model was activated or modified.

Finding

Global Administrator alone does not establish the generator’s required access. Current unified-RBAC documentation explicitly distinguishes global role authority from workspace permissions. The generator specifically requires Automation: Automation Playbooks (Read and Write). An effective-permission check is warranted, but a missing permission is not yet the established cause of the absent menu.

Microsoft’s current generator guide still says no separate Security Copilot license or SCUs are required. No official generator-specific enablement toggle was identified in the reviewed current documentation. Recreating SCU capacity is not a supported next step from these sources.

Sources and what they establish

SourceVerified detail
Generator guide, August7 updateRequires a Sentinel workspace onboarded to Defender, Automation Playbooks Read/Write for generation/deployment, and scoped Sentinel Contributor for rule authoring. Permission changes can take up to two hours. No SCU prerequisite.
Unified RBAC overview, August7 updateGlobal Administrator does not automatically gain workspace permissions, but can assign them. Sentinel unified RBAC activates per workspace; existing Azure/ARM permissions can also affect access.
Unified RBAC activation, August11 updateWorkload activation changes the enforced permission model. This is a permissions migration, not a documented generator feature toggle.
Permission mappingsGlobal-role mapping lists broad security/settings permissions but does not explicitly map Automation Playbooks. Its global-role section names older Defender workloads, so it cannot prove this new authoring permission is inherited.
Permission catalogue, July14 updateThe current catalogue lacks an Automation Playbooks entry, although the newer generator guide requires it. Documentation coverage is incomplete.
Classical playbook creationIncident/alert/entity/blank entries are the documented Logic Apps creation options. Seeing them confirms that experience; it does not validate AI generation.
August6 expansion announcementGenerator access expanded without Security Copilot enablement, included with Sentinel.

Lab evidence

The signed-in Global Administrator could access two onboarded workspaces, including the primary workspace, and had Azure Owner access. Automation displayed the classic tabs and creation choices; neither Generator nor Integration Profiles was visible. The subscription had zero SCU capacity. The unified-RBAC Roles page showed zero custom roles and its Sentinel workload settings showed no active workspaces. Workspace onboarding to Defender and activation in unified RBAC are separate states.

The native portal screenshots preserve these visible states. The API observations below corroborate the explicit role inventory.

At 00:08:27–00:08:31 UTC on September 12 (September 11 US Central), an authorized delegated request with RoleManagement.Read.Defender read the documented Graph beta roleDefinitions, roleAssignments, and customAppScopes collections. All three completed with zero objects and no nextLink. They corroborate the lack of explicit Defender-role configuration returned by these endpoints; they do not mean inherited Entra/Azure access is absent or prove why the generator menu is missing.

Private source records: work/roundup-evidence/defender-roleDefinitions.json, defender-roleAssignments.json, and defender-customAppScopes.json. No unified-RBAC activation, Defender role creation, assignment write, or generated playbook was performed.

Remaining boundary

The explicit role/scope inventory is now complete for those three endpoints. The Automation Playbooks permission’s effective grant and the generator’s tenant availability remain unverified. A permissions-model migration would be a separate decision; the available evidence does not establish that it would make the menu appear.

Do not infer that broad RBAC activation, another global role, consent expansion or a paid resource will fix the absent menu. If the permission itself is absent from the tenant UI, record that alongside the missing generator surface. This supports an unresolved availability/permissions gap, not a proven licensing defect.

Publication-safe claim

“Microsoft documents the generator as included with Sentinel without SCUs. In our September11 lab preflight, onboarded workspaces exposed only the classic Logic Apps creation options. We could not validate AI generation or execution; its effective authoring permission and tenant availability remained unresolved.”

Do not publish “the generator needs SCUs after all,” “Global Administrator is definitively insufficient for this feature,” “permissions caused the failure,” or “the feature is not GA.” None is established by the available evidence.