services / Azure / Log Analytics search
Executes a search query against the log data stored in a workspace.
Query access reads back stored log data, which can include sensitive records; it is closer to bulk read than to targeted export, so it is HIGH.
Microsoft.OperationalInsights/workspaces/search/action
Runs arbitrary queries over stored logs, allowing bulk read-out of telemetry and inventory of what data the workspace holds.
Risks
Scope: HIGH
This privilege may grant access to sensitive data from a single organizational function, or allow interruption of a service supporting a single organizational function.
Links
Contributed by P0 Security
© 2023–present P0 Security and contributors to the IAM Privilege Catalog