Description
Turning off email notifications for a Defender for Cloud security contact can delay awareness of security events because alerts no longer arrive through that route. This setting is separate from alert detection and other notification channels.
Alerts need a delivery process that lets the responsible team see them in time.
Potential impact
- Important detection results may be seen late.
- Incident response may start later.
- Alerts may be missed if no alternative notification channel exists.
Remediation
- Set
alert_notifications = truefor contacts that need email notifications. - Maintain an address monitored by the responsible team, review recipient settings and verify actual delivery.
- Operate an additional route such as a SIEM or ticketing system and plan for delivery failures.
Examples
These excerpts compare the email notification option only. Other contact settings, including name and alerts_to_admins required by AzureRM 4.50.0, are omitted.
Before
hcl
resource "azurerm_security_center_contact" "example" {
email = "contact@example.com"
phone = "+1-555-555-5555"
alert_notifications = false
}
After
hcl
resource "azurerm_security_center_contact" "example" {
email = "contact@example.com"
phone = "+1-555-555-5555"
alert_notifications = true
}
Explanation:
- Before: Security alert emails to the contact are disabled.
- After: Email notifications are enabled. Actual delivery and acknowledgement still need to be checked.