services / Azure / Microsoft Sentinel analytics rule action
A response action attached to a Microsoft Sentinel analytics rule, binding the rule to an automation/playbook that fires when the rule triggers.
These bindings drive automated response; removing or altering them silently breaks the reaction to a detection even while the rule itself still fires, so they inherit the detection backbone's HIGH scope.
Microsoft.SecurityInsights/alertRules/actions/write
Repointing or altering a rule's response action can suppress the automated reaction (notification, playbook) to a triggered detection, letting an alert fire into a void.
Risks
Scope: HIGH
This privilege may grant access to sensitive data from a single organizational function, or allow interruption of a service supporting a single organizational function.
Links
Contributed by P0 Security
© 2023–present P0 Security and contributors to the IAM Privilege Catalog