Microsoft Defender for Cloud
Cloud and workloads

Alerts Azure Storage

In brief

Seven Azure Storage alert entries now list their severity as Informational instead of High, Medium, or Low variants.

What Defender admins need to know

Administrators should use the updated severity labels when reviewing and prioritizing these documented alerts.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

MITRE tactics: Initial Access

Severity: High/LowInformational

Potential malware uploaded to a storage account

MITRE tactics: Discovery

Severity: Medium/LowInformational

Unusual amount of data extracted from a storage account

MITRE tactics: Execution

Severity: Medium/LowInformational

Unusual deletion in a storage account

MITRE tactics: Exfiltration

Severity: Medium/LowInformational

Unusual unauthenticated public access to a sensitive blob container

MITRE tactics: Exfiltration / Resource Development / Impact

Severity: MediumInformational

Suspicious external operation to an Azure storage account with overly permissive SAS token

MITRE tactics: Exfiltration / Resource Development / Impact

Severity: MediumInformational

Unusual SAS token was used to access an Azure storage account from a public IP address

MITRE tactics: Exfiltration / Resource Development / Impact

Severity: LowInformational

Malicious blob uploaded to storage account