services / Azure / Security alert suppression rules
Rules in Microsoft Defender for Cloud that automatically dismiss or suppress security alerts matching defined criteria, preventing matching future alerts from surfacing to responders.
These rules govern which detections reach responders; they affect threat-detection visibility rather than production data directly.
Microsoft.Security/alertsSuppressionRules/delete
Deleting a suppression rule alters detection configuration; primarily a tampering primitive against the alert-handling ruleset.
Risks
Scope: MEDIUM
This privilege may grant access to confidential data, or its exploit can incur operational cost.
Links
Contributed by P0 Security
© 2023–present P0 Security and contributors to the IAM Privilege Catalog