services / Azure / Log Analytics workspace

A Log Analytics workspace, the central log store that ingests and retains telemetry for Azure Monitor and Microsoft Sentinel; it holds the security-relevant logs that every downstream detection and investigation depends on.

The workspace aggregates security and operational logs across many organizational functions and is the evidence store for incident response, so the resource type is HIGH.


Microsoft.​OperationalInsights/​workspaces/​write

Creating or relinking a workspace and changing its retention/ingestion settings can silently shorten log retention or reroute collection, shrinking the evidence trail.

Risks

Scope: HIGH

This privilege may grant access to sensitive data from a single organizational function, or allow interruption of a service supporting a single organizational function.

Links

  • https:​/​/​azure.​permissions.​cloud/​iam/​Microsoft.​OperationalInsights
  • https:​/​/​learn.​microsoft.​com/​en-​us/​azure/​role-​based-​access-​control/​resource-​provider-​operations
  • Contributed by P0 Security

    © 2023–present P0 Security and contributors to the IAM Privilege Catalog