services / Azure / Microsoft Sentinel analytics rule on-demand run

Triggers an on-demand run of an existing Microsoft Sentinel analytics rule.

This only re-executes an existing rule as already configured; it cannot disable or alter detection (that is alertRules/write) and has no destructive effect, so scope is LOW.


Microsoft.​SecurityInsights/​alertRules/​triggerRuleRun/​action

On-demand rule execution consumes analytics query capacity; repeated triggering could burn quota, but it neither alters nor disables detection.

Risks

Scope: LOW

This privilege allows access to data that are not meant to be public, but are otherwise not sensitive.

Links

  • https:​/​/​azure.​permissions.​cloud/​iam/​Microsoft.​SecurityInsights
  • https:​/​/​learn.​microsoft.​com/​en-​us/​azure/​role-​based-​access-​control/​resource-​provider-​operations
  • Contributed by P0 Security

    © 2023–present P0 Security and contributors to the IAM Privilege Catalog