Information
Enables emailing security alerts to the subscription owner or other designated security contact.
Enabling security alert emails ensures that security alert emails are sent by Microsoft. This ensures that the right people are aware of any potential security issues and can mitigate the risk.
Solution
Remediate from Azure Portal
- From Azure Home select the Portal Menu.
- Select Microsoft Defender for Cloud
- Under Management select Environment settings
- Click on the appropriate Subscription.
- Click on Email notifications
- Under Notification types check box next to Notify about alerts with the following severity (or higher) and select an appropriate severity level from the drop-down menu.
- Click Save
- Repeat steps 1-7 for each Subscription requiring remediation.
Remediate from Azure CLI
Use the below command to enable Send email notification for high severity alerts :
az account get-access-token --query "{subscription:subscription,accessToken:accessToken}" --out tsv | xargs -L1 bash -c 'curl -X PUT -H "Authorization: Bearer $1" -H "Content-Type: application/json" https://management.azure.com/subscriptions/<$0>/providers/Microsoft.Security/securityContacts/default1?api-version=2017-08-01-preview -d@"input.json"'
Where input.json contains the data below, replacing validEmailAddress with a single email address or multiple comma-separated email addresses:
{
"id": "/subscriptions/<subscriptionId>/providers/Microsoft.Security/securityContacts/default",
"name": "default",
"type": "Microsoft.Security/securityContacts",
"properties": {
"email": "<validEmailAddress>",
"alertNotifications": "On",
"alertsToAdmins": "On"
}
}
Impact:
Enabling security alert emails can cause alert fatigue, increasing the risk of missing important alerts. Select an appropriate severity level to manage notifications. Azure aims to reduce alert fatigue by limiting the daily email volume per severity level. Learn more:
https://learn.microsoft.com/en-us/azure/defender-for-cloud/configure-email-notifications#email-frequency
.