You have an Azure subscription that contains a Microsoft Sentinel workspace and a resource group named RG1. The workspace is deployed to RG1. The subscription is linked to a Microsoft Entra tenant that contains four users named User1, User2, User3, and User 4. The users are assigned the following roles for RG1: User1 is assigned the Owner role. User2 is assigned the Microsoft Sentinel Responder role. User3 is assigned the Microsoft Sentinel Contributor role. User4 is assigned the Microsoft Sentinel Reader and Workbook Contributor roles. You need to delegate the addition of workbooks to the workspace. Which users can you use? User1 and User4 only Usert only User1, User2, User3, and User4 User1, User3, and User4 only

User1 and User4 have the necessary permissions to delegate the addition of workbooks to the Microsoft Sentinel workspace. User1, as the Owner of the resource group RG1, has wide-ranging permissions that include the ability to add workbooks to the Sentinel workspace. User4, being assigned the Microsoft Sentinel Reader and Workbook Contributor roles, can view the Sentinel workspace and contribute to workbooks, respectively [1] [4] [5]. User2 and User3, however, do not have the required permissions for this task [4] [5]. Therefore, the answer is: User1 and User4 only.

References

Any other questions?