services / Azure / Log Analytics workspace
A Log Analytics workspace, the central log store that ingests and retains telemetry for Azure Monitor and Microsoft Sentinel; it holds the security-relevant logs that every downstream detection and investigation depends on.
The workspace aggregates security and operational logs across many organizational functions and is the evidence store for incident response, so the resource type is HIGH.
Microsoft.OperationalInsights/workspaces/write
Creating or relinking a workspace and changing its retention/ingestion settings can silently shorten log retention or reroute collection, shrinking the evidence trail.
Risks
Scope: HIGH
This privilege may grant access to sensitive data from a single organizational function, or allow interruption of a service supporting a single organizational function.
Links
Contributed by P0 Security