services / Azure / Microsoft Sentinel incident relation
A relation linking a Microsoft Sentinel incident to related resources such as bookmarks, alerts, and entities that constitute its investigation evidence.
Relations are the evidence links of an incident rather than the incident itself; removing them degrades but does not delete the case, so this override is MEDIUM.
Microsoft.SecurityInsights/incidents/relations/delete
Deleting incident relations severs the links between an incident and its supporting evidence (bookmarks, alerts, entities), degrading the investigation record.
Risks
Scope: MEDIUM
This privilege may grant access to confidential data, or its exploit can incur operational cost.
Links
Contributed by P0 Security
© 2023–present P0 Security and contributors to the IAM Privilege Catalog