Review Azure security contact phone details

Maintain the contact details and delivery paths required by the incident-response process.

Description

A missing security contact phone number can leave an organization without information needed for its telephone escalation process. The phone field is contact information; setting it does not guarantee automatic calls or SMS delivery for Defender for Cloud alerts. Email notifications and a separate escalation process also need management.

Potential impact

  • Outdated or missing contact details can delay incident handoffs and response.
  • Registering a number without testing actual notification paths can leave important alerts unnoticed.

Remediation

  • If telephone escalation is required, set phone on Microsoft.Security/securityContacts to the responsible contact’s actual number and keep it current.
  • Review email addresses, notification options and the organization’s escalation process together, and test delivery. Do not treat a stored phone number as an automatic calling service.

Examples

These contact settings are excerpts for a subscription-scope template. Replace the illustrative name, email and phone number with the organization’s actual details.

Before

bicep
resource securityContact 'Microsoft.Security/securityContacts@2020-01-01-preview' = {
  name: 'default1'
  properties: {
    emails: 'security@example.com'
    alertNotifications: {
      state: 'On'
      minimalSeverity: 'High'
    }
  }
}

No phone number is specified, but email and High-severity email notifications are configured.

After

bicep
resource securityContact 'Microsoft.Security/securityContacts@2020-01-01-preview' = {
  name: 'default1'
  properties: {
    emails: 'security@example.com'
    phone: '+82-2-555-1234'
    alertNotifications: {
      state: 'On'
      minimalSeverity: 'High'
    }
  }
}

A phone number is added as contact information. This does not enable automatic voice or SMS alerts.

References