Skip to content

Microsoft.Security/alertsSuppressionRules/write

Azure

Microsoft.Security/alertsSuppressionRules/write

service: Azure - Microsoft Defender for Cloud
techniques:

Event

An active matching suppression rule automatically dismisses Defender for Cloud alerts. Dismissed alerts remain available in the alert list; suppression does not delete the underlying event or uninstall protection. Inspect exact alert types, entity conditions, state, and expiry to determine coverage.

Security Context

Unauthorized broad suppression can impair defenses (T1685). Approved false-positive tuning is common. A comment claiming a change ticket is not approval evidence, and creating a rule does not prove that any alert matched it.

Log Source

Azure Activity Log, Administrative category, with operationName.value: Microsoft.Security/alertsSuppressionRules/write. Correlate status, subStatus, and final resource state; accepted asynchronous requests may still fail. Request bodies and HTTP details are optional and export-dependent.

Key Fields

FieldInvestigation value
caller, claims, authorizationRecorded actor and authorization context; verify effective permissions.
resourceId, correlationIdExact target and related operations.
status, subStatusOutcome, including acceptance versus final completion.
properties.requestbody, httpRequestSubmitted configuration or request URL where available; secret material may be omitted.

What to Investigate

  1. Confirm the recorded outcome and compare actor, target, and timing with the approved workflow.
  2. Verify the change independently and compare previous/new type, scope conditions, enabled state, and expiration.
  3. Confirm alert-type and entity-field values against actual alerts and inspect which alerts were dismissed.
  4. Review coverage gaps and overlapping controls; do not infer a subsequent RDP attack or assume all alerts vanished.

Sample Event

Synthetic scenario. The sample uses the documented wildcard alert type with a specific source-IP condition and an illustrative expiry. It does not suppress every source or show a matched alert; this replaces the unverified RDPBruteForce type and host-field combination.

Exact field presence, payload nesting, identity/session details, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not prove intent or downstream activity.

{
"authorization": {
"action": "Microsoft.Security/alertsSuppressionRules/write",
"scope": "/subscriptions/20000000-0000-4000-8000-000000000001/providers/Microsoft.Security/alertsSuppressionRules/suppress-test-source"
},
"caller": "draco@fantasticlogs.cloud",
"channels": "Operation",
"claims": {
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"ipaddr": "203.0.113.66",
"name": "Draco Malfoy",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "30000000-0000-4000-8000-001010011010",
"puid": "1003200000000666",
"http://schemas.microsoft.com/identity/claims/tenantid": "10000000-0000-4000-8000-000000000001",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "draco@fantasticlogs.cloud",
"http://schemas.microsoft.com/identity/claims/wids": "e8611ab8-c189-46e8-94e1-60213ab1f814",
"uti": "alSup213ExampleUtid01",
"ver": "1.0"
},
"correlationId": "90000000-0000-4000-8000-000100100100",
"description": "",
"eventDataId": "90000000-0000-4000-8000-000100100101",
"eventName": {
"value": "EndRequest",
"localizedValue": "End request"
},
"category": {
"value": "Administrative",
"localizedValue": "Administrative"
},
"eventTimestamp": "2026-04-15T18:32:01.7421005Z",
"level": "Informational",
"operationId": "90000000-0000-4000-8000-000100100110",
"operationName": {
"value": "Microsoft.Security/alertsSuppressionRules/write",
"localizedValue": "Create or update Alert Suppression Rule"
},
"resourceGroupName": "",
"resourceProviderName": {
"value": "Microsoft.Security",
"localizedValue": "Microsoft.Security"
},
"resourceType": {
"value": "Microsoft.Security/alertsSuppressionRules",
"localizedValue": "Microsoft.Security/alertsSuppressionRules"
},
"resourceId": "/subscriptions/20000000-0000-4000-8000-000000000001/providers/Microsoft.Security/alertsSuppressionRules/suppress-test-source",
"status": {
"value": "Succeeded",
"localizedValue": "Succeeded"
},
"subStatus": {
"value": "Created",
"localizedValue": "Created (HTTP Status Code: 201)"
},
"submissionTimestamp": "2026-04-15T18:32:02.2128443Z",
"subscriptionId": "20000000-0000-4000-8000-000000000001",
"tenantId": "10000000-0000-4000-8000-000000000001",
"properties": {
"statusCode": "Created",
"serviceRequestId": null,
"eventCategory": "Administrative",
"entity": "/subscriptions/20000000-0000-4000-8000-000000000001/providers/Microsoft.Security/alertsSuppressionRules/suppress-test-source",
"message": "Microsoft.Security/alertsSuppressionRules/write",
"hierarchy": "10000000-0000-4000-8000-000000000001/20000000-0000-4000-8000-000000000001",
"requestbody": "{\"properties\":{\"reason\":\"FalsePositive\",\"alertType\":\"*\",\"state\":\"Enabled\",\"expirationDateUtc\":\"2027-04-15T00:00:00Z\",\"comment\":\"Illustrative testing exception; approval must be verified independently\",\"suppressionAlertsScope\":{\"allOf\":[{\"field\":\"entities.ip.address\",\"in\":[\"203.0.113.66\"]}]}}}"
},
"relatedEvents": []
}

Sources

MITRE ATT&CK Mapping

Tactics: Defense Impairment

Techniques:
  • T1685 — Disable or Modify Tools — Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities. This may include stopping spec...
Documentation reviewed: October 5, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.