services / Azure / Microsoft Sentinel analytics rule action
A response action attached to a Microsoft Sentinel analytics rule, binding the rule to an automation/playbook that fires when the rule triggers.
These bindings drive automated response; removing or altering them silently breaks the reaction to a detection even while the rule itself still fires, so they inherit the detection backbone's HIGH scope.
Microsoft.SecurityInsights/alertRules/actions/delete
Deleting the response action decouples the rule from its automated response, so detections no longer drive any reaction.
Risks
Scope: HIGH
This privilege may grant access to sensitive data from a single organizational function, or allow interruption of a service supporting a single organizational function.
Links
Contributed by P0 Security
© 2023–present P0 Security and contributors to the IAM Privilege Catalog