Security alert emails are disabled

Check notification settings and delivery so the responsible team receives required security alert emails.

Description

Turning off email notifications for a Defender for Cloud security contact can delay awareness of security events because alerts no longer arrive through that route. This setting is separate from alert detection and other notification channels.

Alerts need a delivery process that lets the responsible team see them in time.

Potential impact

  • Important detection results may be seen late.
  • Incident response may start later.
  • Alerts may be missed if no alternative notification channel exists.

Remediation

  • Set alert_notifications = true for contacts that need email notifications.
  • Maintain an address monitored by the responsible team, review recipient settings and verify actual delivery.
  • Operate an additional route such as a SIEM or ticketing system and plan for delivery failures.

Examples

These excerpts compare the email notification option only. Other contact settings, including name and alerts_to_admins required by AzureRM 4.50.0, are omitted.

Before

hcl
resource "azurerm_security_center_contact" "example" {
  email               = "contact@example.com"
  phone               = "+1-555-555-5555"
  alert_notifications = false
}

After

hcl
resource "azurerm_security_center_contact" "example" {
  email               = "contact@example.com"
  phone               = "+1-555-555-5555"
  alert_notifications = true
}

Explanation:

  • Before: Security alert emails to the contact are disabled.
  • After: Email notifications are enabled. Actual delivery and acknowledgement still need to be checked.

References