services / Azure / Log Analytics storage insight configuration
A storage insight configuration that pulls log data from a linked storage account (e.g. diagnostic logs, WAD/LAD tables) into the workspace.
These configs are an ingestion path from storage into the workspace; removing them stops that telemetry from being read in; HIGH.
Microsoft.OperationalInsights/workspaces/storageinsightconfigs/write
Altering a storage insight config can stop or narrow the log data pulled from storage, suppressing future telemetry.
Risks
Scope: HIGH
This privilege may grant access to sensitive data from a single organizational function, or allow interruption of a service supporting a single organizational function.
Links
Contributed by P0 Security
© 2023–present P0 Security and contributors to the IAM Privilege Catalog