services / Azure / Microsoft Sentinel onboarding state
The onboarding state marking a Log Analytics workspace as enabled for Microsoft Sentinel, gating whether the SIEM is active for that workspace.
The onboarding state controls whether Sentinel runs on a workspace at all; removing it offboards the SIEM, so the resource type is HIGH.
Microsoft.SecurityInsights/onboardingStates/delete
Deleting the onboarding state offboards Sentinel from the workspace, tearing down detections and halting security-telemetry aggregation for it.
Risks
Scope: HIGH
This privilege may grant access to sensitive data from a single organizational function, or allow interruption of a service supporting a single organizational function.
Links
Contributed by P0 Security
© 2023–present P0 Security and contributors to the IAM Privilege Catalog