Ensure that the Notify about attack paths with the following risk level (or higher) setting is enabled within the Email notifications configuration of Microsoft Defender for Cloud for each Azure subscription. When enabled, Microsoft Defender for Cloud sends email notifications about detected attack paths to the subscription owner or other designated security contacts, based on the configured minimum risk level threshold.
Microsoft Defender for Cloud's attack path analysis identifies exploitable sequences of steps that an attacker could use to reach critical assets in your environment. Enabling attack path email notifications ensures that the appropriate security personnel are alerted promptly when such attack paths are detected, enabling them to investigate and remediate potential threats before they can be exploited. Without this configuration, security teams may miss critical signals and be unable to respond to high-risk attack paths in a timely manner.
Note: Enabling attack path email notifications may cause alert fatigue if the risk level threshold is set too low. Select an appropriate minimum risk level (Low, Medium, High, or Critical) to balance security coverage with notification volume. Microsoft Defender for Cloud limits outgoing email volume per risk level to reduce alert fatigue.
Audit
To determine if sending email notifications for attack paths is enabled within Microsoft Defender for Cloud, perform the following operations:
Remediation / Resolution
To configure Microsoft Defender for Cloud to send email notifications for attack paths identified within your Azure cloud account, perform the following operations:
References
- Azure Official Documentation
- Configure email notifications for alerts and attack paths - Microsoft Defender for Cloud | Microsoft Learn
- Identify and remediate attack paths - Microsoft Defender for Cloud | Microsoft Learn
- Security explorer and attack paths in Microsoft Defender for Cloud - Microsoft Defender for Cloud | Microsoft Learn
- Azure Command Line Interface (CLI) Documentation
- az account | Microsoft Learn
- az account get-access-token | Microsoft Learn