services / Azure / Security contacts
The security contact configuration that defines which email addresses and phone numbers receive Microsoft Defender for Cloud alert notifications and severity thresholds for notifying.
Controls the human notification path for security alerts; tampering affects whether responders are told about detections, not production data.
Microsoft.Security/securityContacts/write
Overwriting the security contact can remove responder recipients or raise the notification severity threshold so alerts on the attacker's activity are never emailed, cutting off the notification path.
Risks
Scope: MEDIUM
This privilege may grant access to confidential data, or its exploit can incur operational cost.
Links
Contributed by P0 Security
© 2023–present P0 Security and contributors to the IAM Privilege Catalog