services / Azure / Defender for Cloud workspace settings
The workspace settings that determine which Log Analytics workspace Microsoft Defender for Cloud exports its security data, alerts, and agent telemetry to for the scope.
Defines the telemetry/alert destination for the whole subscription; redirecting or removing it can sever the flow of security data to where it is retained and analyzed.
Microsoft.Security/workspaceSettings/delete
Deleting the workspace settings stops export of Defender security data to Log Analytics, cutting off telemetry retention and analysis.
Risks
Scope: HIGH
This privilege may grant access to sensitive data from a single organizational function, or allow interruption of a service supporting a single organizational function.
Links
Contributed by P0 Security
© 2023–present P0 Security and contributors to the IAM Privilege Catalog