services / Azure / Microsoft Sentinel unregister
Unregisters the subscription from Microsoft Sentinel, tearing down the SIEM's registration at the subscription level.
Unregistering removes Sentinel from the subscription, the broadest single blinding action available; the EVASION-tier risks carry the severity while the asset scope is HIGH.
Microsoft.SecurityInsights/unregister/action
Unregistering the subscription from Sentinel offboards the SIEM entirely, disabling all detection and stopping security-telemetry aggregation across the subscription.
Risks
Scope: HIGH
This privilege may grant access to sensitive data from a single organizational function, or allow interruption of a service supporting a single organizational function.
Links
Contributed by P0 Security
© 2023–present P0 Security and contributors to the IAM Privilege Catalog