services / Azure / Microsoft Sentinel incident comment
An analyst comment on a Microsoft Sentinel incident, capturing investigation notes and response context on the case record.
Comments are a narrower part of the incident record than the incident itself; deleting them erases investigation notes but not the whole case, so this override is MEDIUM rather than the incident-level HIGH.
Microsoft.SecurityInsights/incidents/comments/delete
Deleting incident comments removes analyst investigation notes from the case record, degrading the response audit trail.
Risks
Scope: MEDIUM
This privilege may grant access to confidential data, or its exploit can incur operational cost.
Links
Contributed by P0 Security
© 2023–present P0 Security and contributors to the IAM Privilege Catalog