services / Azure / Security alert dismissal
The action that sets a Microsoft Defender for Cloud security alert's state to dismissed, removing it from the active alert queue that responders triage.
Changes the state of an already-fired detection to hide it from responders; affects incident visibility rather than production data.
Microsoft.Security/locations/alerts/dismiss/action
Dismissing an active alert hides an already-fired detection of the attacker's activity from responders and manipulates the alert's state to a benign disposition, evading incident response.
Risks
Scope: MEDIUM
This privilege may grant access to confidential data, or its exploit can incur operational cost.
Links
Contributed by P0 Security
© 2023–present P0 Security and contributors to the IAM Privilege Catalog