services / Azure / Security contacts

The security contact configuration that defines which email addresses and phone numbers receive Microsoft Defender for Cloud alert notifications and severity thresholds for notifying.

Controls the human notification path for security alerts; tampering affects whether responders are told about detections, not production data.


Microsoft.​Security/​securityContacts/​delete

Deleting the security contact removes alert-email recipients so no one is notified of Defender detections, blinding responders.

Risks

Scope: MEDIUM

This privilege may grant access to confidential data, or its exploit can incur operational cost.

Links

  • https:​/​/​azure.​permissions.​cloud/​iam/​Microsoft.​Security
  • https:​/​/​learn.​microsoft.​com/​en-​us/​azure/​role-​based-​access-​control/​resource-​provider-​operations
  • Contributed by P0 Security

    © 2023–present P0 Security and contributors to the IAM Privilege Catalog