services / Azure / Security policies
The Defender for Cloud security policy (the set of security assessment/compliance rules evaluated against resources) governing which misconfigurations and threats are checked for at the scope.
This is security-scanning policy, not IAM/access policy; weakening it reduces which findings are detected, affecting detection posture rather than access control.
Microsoft.Security/policies/write
Editing the security policy can disable assessment rules so the attacker's misconfigurations go undetected, weakening the detection posture and manipulating what the security scan reports.
Risks
Scope: MEDIUM
This privilege may grant access to confidential data, or its exploit can incur operational cost.
Links
Contributed by P0 Security
© 2023–present P0 Security and contributors to the IAM Privilege Catalog