More Info:

Security solution changes have been detected within your Microsoft Azure cloud account.

Risk Level

High

Address

Security

Compliance Standards

HIPAA, CISAZURE, CBP, ISO27001

Triage and Remediation

Remediation

Sure, here are the step-by-step instructions to remediate the misconfiguration of creating an alert for “Delete Security Solution” events in Azure using the Azure console:

  1. Open the Azure portal and navigate to the Security Center.

  2. Click on “Security policy” from the left-hand menu.

  3. Select the policy that you want to update.

  4. Scroll down to the “Alerts” section and click on “Add alert”.

  5. In the “Create alert rule” window, select the “Activity log” option.

  6. Under “Event types”, select “Service Health” and then select “Service health status changes”.

  7. In the “Service health status changes” section, select “Resolved” and “Dismissed” as the status changes to be alerted for.

  8. Under “Actions”, select “Email/SMS/Push/Voice” and add the email addresses of the people who should be alerted.

  9. Click on “Create alert rule” to save the configuration.

Once you have followed these steps, you should receive an alert whenever a “Delete Security Solution” event is detected in Azure. This will help you to take immediate action to remediate any potential security risks.