Description
An Azure Security Contact uses alertNotifications for new security alert emails and notificationsByRole for recipients with specified subscription RBAC roles. A disabled required email path or missing recipient can delay awareness of an alert.
Email notification is separate from threat detection itself. If email is not used, verify that another monitoring and notification path reaches the responsible responders.
Potential impact
- Missed or late alerts can delay response.
- Incorrect recipients or severity thresholds can omit needed alerts or generate unnecessary email.
Remediation
- If email is a response channel, set
alertNotifications.state: Onand choose the requiredminimalSeverity. - For role-based recipients, set
notificationsByRole.state: Onand select appropriate roles. Regularly verify actual addresses, current role holders and delivery results.
Examples
These resource excerpts belong in a subscription-scope Bicep template. Supply targetScope = 'subscription' in the containing template and use actual contact details. High does not select every alert severity for email.
Before
resource security_contact 'Microsoft.Security/securityContacts@2020-01-01-preview' = {
name: 'security contact'
properties: {
emails: 'sample@email.com'
phone: '9999999'
alertNotifications: {
state: 'Off'
minimalSeverity: 'High'
}
notificationsByRole: {
state: 'On'
roles: ['Owner']
}
}
}
New alert emails are disabled. Do not assume the role-recipient setting alone ensures required delivery; verify the actual response path.
After
resource security_contact 'Microsoft.Security/securityContacts@2020-01-01-preview' = {
name: 'security contact'
properties: {
emails: 'sample@email.com'
phone: '9999999'
alertNotifications: {
state: 'On'
minimalSeverity: 'High'
}
notificationsByRole: {
state: 'On'
roles: ['Owner']
}
}
}
Email notifications are enabled with a High severity threshold. Verify delivery to the configured recipients.