services / Azure / Security alert suppression rules

Rules in Microsoft Defender for Cloud that automatically dismiss or suppress security alerts matching defined criteria, preventing matching future alerts from surfacing to responders.

These rules govern which detections reach responders; they affect threat-detection visibility rather than production data directly.


Microsoft.​Security/​alertsSuppressionRules/​delete

Deleting a suppression rule alters detection configuration; primarily a tampering primitive against the alert-handling ruleset.

Risks

Scope: MEDIUM

This privilege may grant access to confidential data, or its exploit can incur operational cost.

Links

  • https:​/​/​azure.​permissions.​cloud/​iam/​Microsoft.​Security
  • https:​/​/​learn.​microsoft.​com/​en-​us/​azure/​role-​based-​access-​control/​resource-​provider-​operations
  • Contributed by P0 Security

    © 2023–present P0 Security and contributors to the IAM Privilege Catalog