services / Azure / Security contacts
The security contact configuration that defines which email addresses and phone numbers receive Microsoft Defender for Cloud alert notifications and severity thresholds for notifying.
Controls the human notification path for security alerts; tampering affects whether responders are told about detections, not production data.
Microsoft.Security/securityContacts/delete
Deleting the security contact removes alert-email recipients so no one is notified of Defender detections, blinding responders.
Risks
Scope: MEDIUM
This privilege may grant access to confidential data, or its exploit can incur operational cost.
Links
Contributed by P0 Security
© 2023–present P0 Security and contributors to the IAM Privilege Catalog