services / Azure / Defender for Cloud workflow automations
Automation configurations that route Microsoft Defender for Cloud alerts, recommendations, and assessment events to targets such as Logic Apps, Event Hubs, or Log Analytics for automated SOAR-style response and export.
These drive automated response and downstream export of security events; tampering affects response/telemetry flow rather than production data.
Microsoft.Security/automations/write
Editing an automation can disable automated response to the attacker's activity, or repoint the export target to an attacker-controlled Event Hub/endpoint to siphon off security alert and event data.
Risks
Scope: MEDIUM
This privilege may grant access to confidential data, or its exploit can incur operational cost.
Links
Contributed by P0 Security
© 2023–present P0 Security and contributors to the IAM Privilege Catalog