Playbooks not listed and "Failed to fetch playbook runs in one or more selected subscriptions" appeared suddenly across multiple tenants

Ayax OC 20 Reputation points
2026-08-27T16:17:22.7166667+00:00

We are an MSSP managing multiple Microsoft Sentinel workspaces across separate customer tenants via Azure Lighthouse. As of today, the Automation / Active playbooks view fails to list playbooks and returns "Failed to fetch playbook runs in one or more selected subscriptions". The "Run playbook" panel on an incident also comes up empty.

User's image This started suddenly and affects more than one tenant, with no configuration changes on our side. I found this thread reporting what looks like the same behaviour today:

https://learn.microsoft.com/en-us/answers/questions/5987108/microsoft-sentinel-failed-to-fetch-playbook-runs-i

We have already worked through the full checklist suggested there, and none of it applies:

  1. Playbooks are present under Automation > Active playbooks, Status = Enabled, Trigger kind = Microsoft Sentinel Incident. They open correctly in Logic Apps.
  2. Subscription scope is correct. The right directory and subscriptions are selected in the portal header, and the playbooks live in subscriptions that are in scope. The same error appears regardless of the subscription filter.
  3. Permissions are in place. Microsoft Sentinel Automation Contributor is assigned on the resource groups hosting the playbooks, and our operators hold Logic App Contributor / Microsoft Sentinel Playbook Operator on those same resource groups. Playbook permissions are also granted from Sentinel > Settings > Playbook permissions.
  4. Nothing was moved. Resource IDs and resource groups are unchanged; the automation rules still resolve to valid playbook paths.
  5. No access restriction policies are configured on the Logic Apps.
  6. All subscriptions involved are active, enabled and not read-only.
  7. This leaves point 7 "a possible service-side issue". The problem appeared suddenly, across multiple tenants, at the same time as portal errors, with no customer-side change.

Is there a known service-side incident affecting playbook enumeration and run history retrieval? If so, is there a tracking ID we can follow? If there is no active incident on your side, could you advise on what else we should check beyond the steps already listed above, or confirm whether this warrants a support case for deeper investigation?

Microsoft Security | Microsoft Sentinel
0 comments No comments

1 answer

Sort by: Most helpful
  1. Konstantinos Lianos 830 Reputation points Student Ambassador
    2026-08-31T11:02:58.68+00:00

    Hi @Ayax OC

    Based on the checks already completed, this looks more like a service-side Sentinel/portal issue than a playbook configuration or RBAC problem.

    The main indicator is that the issue started suddenly across multiple independent tenants at approximately the same time, without any configuration changes, and another user has reported the same behavior.

    I would only suggest two additional checks:

    Verify whether automation rules are still triggering the playbooks successfully. If they are, while Active playbooks and Run playbook remain empty, the issue is likely limited to playbook enumeration in the portal.

    Check Azure Service Health and capture the failed browser request/correlation ID from Developer Tools.

    If there is no related Service Health notification, I would recommend opening a Microsoft support case, including the affected tenant/workspace IDs, UTC start time, screenshots, and correlation IDs.

    I would also avoid recreating playbooks or changing RBAC at this stage, since the simultaneous multi-tenant behavior strongly suggests a backend issue.

    If my answers helps dont forget to check it as resolved! :)

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.