services / Azure / Defender for Cloud workflow automations

Automation configurations that route Microsoft Defender for Cloud alerts, recommendations, and assessment events to targets such as Logic Apps, Event Hubs, or Log Analytics for automated SOAR-style response and export.

These drive automated response and downstream export of security events; tampering affects response/telemetry flow rather than production data.


Microsoft.​Security/​automations/​write

Editing an automation can disable automated response to the attacker's activity, or repoint the export target to an attacker-controlled Event Hub/endpoint to siphon off security alert and event data.

Risks

Scope: MEDIUM

This privilege may grant access to confidential data, or its exploit can incur operational cost.

Links

  • https:​/​/​azure.​permissions.​cloud/​iam/​Microsoft.​Security
  • https:​/​/​learn.​microsoft.​com/​en-​us/​azure/​role-​based-​access-​control/​resource-​provider-​operations
  • Contributed by P0 Security

    © 2023–present P0 Security and contributors to the IAM Privilege Catalog