services / Azure / Microsoft Sentinel data connector
A Microsoft Sentinel data connector that ingests telemetry from a source (Azure services, endpoints, third-party products) into the workspace, feeding all downstream detection.
Connectors are the telemetry supply for the whole SIEM; cutting one stops the logs that every detection depends on, so the resource type is HIGH.
Microsoft.SecurityInsights/dataConnectors/delete
Deleting a data connector severs the telemetry pipeline entirely, cutting off the log source and blinding all detections that rely on it.
Risks
Scope: HIGH
This privilege may grant access to sensitive data from a single organizational function, or allow interruption of a service supporting a single organizational function.
Links
Contributed by P0 Security
© 2023–present P0 Security and contributors to the IAM Privilege Catalog