services / Azure / Security alert suppression rules
Rules in Microsoft Defender for Cloud that automatically dismiss or suppress security alerts matching defined criteria, preventing matching future alerts from surfacing to responders.
These rules govern which detections reach responders; they affect threat-detection visibility rather than production data directly.
Microsoft.Security/alertsSuppressionRules/write
Pre-creating a suppression rule matching the attacker's own activity ensures future alerts on that activity are auto-dismissed, silently evading detection and preventing those alerts from being recorded/actioned.
Risks
Scope: MEDIUM
This privilege may grant access to confidential data, or its exploit can incur operational cost.
Links
Contributed by P0 Security
© 2023–present P0 Security and contributors to the IAM Privilege Catalog