services / Azure / Defender for Cloud workflow automations

Automation configurations that route Microsoft Defender for Cloud alerts, recommendations, and assessment events to targets such as Logic Apps, Event Hubs, or Log Analytics for automated SOAR-style response and export.

These drive automated response and downstream export of security events; tampering affects response/telemetry flow rather than production data.


Microsoft.​Security/​automations/​delete

Deleting an automation removes the automated response/export workflow, so detections no longer trigger their configured containment or notification actions.

Risks

Scope: MEDIUM

This privilege may grant access to confidential data, or its exploit can incur operational cost.

Links

  • https:​/​/​azure.​permissions.​cloud/​iam/​Microsoft.​Security
  • https:​/​/​learn.​microsoft.​com/​en-​us/​azure/​role-​based-​access-​control/​resource-​provider-​operations
  • Contributed by P0 Security

    © 2023–present P0 Security and contributors to the IAM Privilege Catalog