services / Azure / Defender for Cloud workflow automations
Automation configurations that route Microsoft Defender for Cloud alerts, recommendations, and assessment events to targets such as Logic Apps, Event Hubs, or Log Analytics for automated SOAR-style response and export.
These drive automated response and downstream export of security events; tampering affects response/telemetry flow rather than production data.
Microsoft.Security/automations/delete
Deleting an automation removes the automated response/export workflow, so detections no longer trigger their configured containment or notification actions.
Risks
Scope: MEDIUM
This privilege may grant access to confidential data, or its exploit can incur operational cost.
Links
Contributed by P0 Security
© 2023–present P0 Security and contributors to the IAM Privilege Catalog