services / Azure / Microsoft Sentinel incident relation

A relation linking a Microsoft Sentinel incident to related resources such as bookmarks, alerts, and entities that constitute its investigation evidence.

Relations are the evidence links of an incident rather than the incident itself; removing them degrades but does not delete the case, so this override is MEDIUM.


Microsoft.​SecurityInsights/​incidents/​relations/​delete

Deleting incident relations severs the links between an incident and its supporting evidence (bookmarks, alerts, entities), degrading the investigation record.

Risks

Scope: MEDIUM

This privilege may grant access to confidential data, or its exploit can incur operational cost.

Links

  • https:​/​/​azure.​permissions.​cloud/​iam/​Microsoft.​SecurityInsights
  • https:​/​/​learn.​microsoft.​com/​en-​us/​azure/​role-​based-​access-​control/​resource-​provider-​operations
  • Contributed by P0 Security

    © 2023–present P0 Security and contributors to the IAM Privilege Catalog