Azure security contact email is missing

Check the contact and delivery path for Microsoft Defender for Cloud security notifications.

Description

The security contact identifies who should receive Microsoft Defender for Cloud alerts. Without an email address monitored by the responsible team, important contact notifications may be missed or handled late.

Specifying an address does not guarantee delivery of every alert. Manage notification options, recipients and other monitoring paths together.

Potential impact

  • The responsible team may see security alerts too late to respond promptly.
  • Contact responsibilities can become unclear during handovers or incident response.

Remediation

  • Set email in azurerm_security_center_contact to an address the responsible team regularly monitors.
  • Configure contact and administrator notifications for the intended recipients and test actual delivery.
  • Update the address when responsibilities change and maintain supplementary response paths, such as a SIEM.

Examples

The shared name setting is omitted. AzureRM 4.50.0 requires email, so the before excerpt is not a complete deployable configuration. Replace the example address with the real team address.

Before

hcl
resource "azurerm_security_center_contact" "example" {
  phone = "+1-555-555-5555"

  alert_notifications = true
  alerts_to_admins    = true
}

The contact email is missing. A phone number does not replace an email-notification address.

After

hcl
resource "azurerm_security_center_contact" "example" {
  email = "security-team@example.com"
  phone = "+1-555-555-5555"

  alert_notifications = true
  alerts_to_admins    = true
}

The team address and notification options are specified. Verify actual receipt as well as the stored settings.

References