services / Azure / Microsoft Sentinel export connection
A Microsoft Sentinel export connection that routes security data out of the workspace to an external destination.
Export connections move aggregated security data (spanning many org functions) out of the workspace; configuring one is an exfiltration channel, so the resource type is HIGH.
Microsoft.SecurityInsights/ExportConnections/delete
Deleting an export connection cuts a configured security-data export, which can sever a downstream retention or monitoring pipeline that depends on the exported telemetry.
Risks
Scope: HIGH
This privilege may grant access to sensitive data from a single organizational function, or allow interruption of a service supporting a single organizational function.
Links
Contributed by P0 Security
© 2023–present P0 Security and contributors to the IAM Privilege Catalog