services / Azure / Log Analytics saved search schedule
A schedule attached to a saved search that runs the query on an interval, turning it into a recurring Log Analytics alert rule.
The schedule is what makes a saved search fire as a detection; disabling or removing it stops the alert from ever running; HIGH.
Microsoft.OperationalInsights/workspaces/savedSearches/schedules/delete
Deleting a schedule stops the saved search from running, removing the detection entirely.
Risks
Scope: HIGH
This privilege may grant access to sensitive data from a single organizational function, or allow interruption of a service supporting a single organizational function.
Links
Contributed by P0 Security
© 2023–present P0 Security and contributors to the IAM Privilege Catalog