services / Azure / Security alert suppression rules

Rules in Microsoft Defender for Cloud that automatically dismiss or suppress security alerts matching defined criteria, preventing matching future alerts from surfacing to responders.

These rules govern which detections reach responders; they affect threat-detection visibility rather than production data directly.


Microsoft.​Security/​alertsSuppressionRules/​write

Pre-creating a suppression rule matching the attacker's own activity ensures future alerts on that activity are auto-dismissed, silently evading detection and preventing those alerts from being recorded/actioned.

Risks

Scope: MEDIUM

This privilege may grant access to confidential data, or its exploit can incur operational cost.

Links

  • https:​/​/​azure.​permissions.​cloud/​iam/​Microsoft.​Security
  • https:​/​/​learn.​microsoft.​com/​en-​us/​azure/​role-​based-​access-​control/​resource-​provider-​operations
  • Contributed by P0 Security

    © 2023–present P0 Security and contributors to the IAM Privilege Catalog