services / Azure / Microsoft Sentinel analytics rule on-demand run
Triggers an on-demand run of an existing Microsoft Sentinel analytics rule.
This only re-executes an existing rule as already configured; it cannot disable or alter detection (that is alertRules/write) and has no destructive effect, so scope is LOW.
Microsoft.SecurityInsights/alertRules/triggerRuleRun/action
On-demand rule execution consumes analytics query capacity; repeated triggering could burn quota, but it neither alters nor disables detection.
Risks
Scope: LOW
This privilege allows access to data that are not meant to be public, but are otherwise not sensitive.
Links
Contributed by P0 Security
© 2023–present P0 Security and contributors to the IAM Privilege Catalog