Enable sending alert notifications about attack paths to the security contact email address defined in the Microsoft Defender for Cloud settings. The contact information provided will be used by Microsoft Defender for Cloud to contact the subscription owners and/or administrators when potential attack paths are found within their cloud environment.
Microsoft Defender for Cloud's attack path analysis helps you prioritize security remediation by identifying exploitable attack sequences within your multicloud environment. It provides actionable recommendations to close these security gaps. Enabling attack path email notifications ensures the right people are notified when potential attack paths are identified in your Azure cloud account, in order to be able to mitigate the risks in a timely fashion.
Audit
To determine if sending alert notifications for attack paths is enabled within Microsoft Defender for Cloud, perform the following operations:
Remediation / Resolution
To configure Microsoft Defender for Cloud to send alert notifications for attack paths identified within your Azure cloud account, perform the following operations:
References
- Azure Official Documentation
- Microsoft Defender for Cloud overview
- Configure email notifications for alerts and attack paths
- Identify and remediate attack paths
- Investigate risk with security explorer/attack paths
- Azure Command Line Interface (CLI) Documentation
- az account get-access-token