Description
A missing security contact phone number can leave an organization without information needed for its telephone escalation process. The phone field is contact information; setting it does not guarantee automatic calls or SMS delivery for Defender for Cloud alerts. Email notifications and a separate escalation process also need management.
Potential impact
- Outdated or missing contact details can delay incident handoffs and response.
- Registering a number without testing actual notification paths can leave important alerts unnoticed.
Remediation
- If telephone escalation is required, set phone on Microsoft.Security/securityContacts to the responsible contact’s actual number and keep it current.
- Review email addresses, notification options and the organization’s escalation process together, and test delivery. Do not treat a stored phone number as an automatic calling service.
Examples
These contact settings are excerpts for a subscription-scope template. Replace the illustrative name, email and phone number with the organization’s actual details.
Before
resource securityContact 'Microsoft.Security/securityContacts@2020-01-01-preview' = {
name: 'default1'
properties: {
emails: 'security@example.com'
alertNotifications: {
state: 'On'
minimalSeverity: 'High'
}
}
}
No phone number is specified, but email and High-severity email notifications are configured.
After
resource securityContact 'Microsoft.Security/securityContacts@2020-01-01-preview' = {
name: 'default1'
properties: {
emails: 'security@example.com'
phone: '+82-2-555-1234'
alertNotifications: {
state: 'On'
minimalSeverity: 'High'
}
}
}
A phone number is added as contact information. This does not enable automatic voice or SMS alerts.