services / Azure / Microsoft Sentinel export connection
A Microsoft Sentinel export connection that routes security data out of the workspace to an external destination.
Export connections move aggregated security data (spanning many org functions) out of the workspace; configuring one is an exfiltration channel, so the resource type is HIGH.
Microsoft.SecurityInsights/ExportConnections/write
Creating or updating an export connection can route the workspace's aggregated security data and logs to an attacker-controlled destination, bulk-exfiltrating sensitive telemetry.
Risks
Scope: HIGH
This privilege may grant access to sensitive data from a single organizational function, or allow interruption of a service supporting a single organizational function.
Links
Contributed by P0 Security
© 2023–present P0 Security and contributors to the IAM Privilege Catalog