services / Azure / Defender for Cloud workspace settings

The workspace settings that determine which Log Analytics workspace Microsoft Defender for Cloud exports its security data, alerts, and agent telemetry to for the scope.

Defines the telemetry/alert destination for the whole subscription; redirecting or removing it can sever the flow of security data to where it is retained and analyzed.


Microsoft.​Security/​workspaceSettings/​write

Repointing the workspace export to an attacker-chosen or dead workspace diverts security telemetry and alerts away from the monitored/retained location, destroying the responders' log stream and blinding detection.

Risks

Scope: HIGH

This privilege may grant access to sensitive data from a single organizational function, or allow interruption of a service supporting a single organizational function.

Links

  • https:​/​/​azure.​permissions.​cloud/​iam/​Microsoft.​Security
  • https:​/​/​learn.​microsoft.​com/​en-​us/​azure/​role-​based-​access-​control/​resource-​provider-​operations
  • Contributed by P0 Security

    © 2023–present P0 Security and contributors to the IAM Privilege Catalog