LOW
Source
CloudSploit
ID
security-contact-additional-email

Security Contact Additional Email

Ensure Additional email addresses are configured with security contact email.

Microsoft Defender for Cloud emails the Subscription Owner to notify them about security alerts. Adding your Security Contact's email address to the Additional email addresses field ensures that your organization's Security Team is included in these alerts. This ensures that the proper people are aware of any potential compromise in order to mitigate the risk in a timely fashion.

Follow the appropriate remediation steps below to resolve the issue.

  1. Log in to the Microsoft Azure Management Console.

  2. Select the “Search resources, services, and docs” option at the top and search for “Microsoft Defender for Cloud”. Step

  3. On the “Microsoft Defender for Cloud” page, scroll down the left navigation panel and choose “Environment Settings”. Step

  4. On the “Environment Settings” page, select the “Subscription” by clicking on the “Name”. Step

  5. Under the “Settings | Defender plans " page, click on the “Email Notifications”. Step

  6. On the “Settings | Email notifications” page under “Email recipients” if the “Additional email addresses (separated by commas)” is empty then the security contacts additional are not configured to be sent to the admins. Step

  7. On the “Additional email addresses (separated by commas) section add the additional email addresses. Step

  8. Under “Notification types” select “High” from the dropdown next to “Notify about alerts with the following severity (or higher). Click on the “Save” button to make the changes. Step

  9. Repeat step number 3 - 8 to ensure to ensure that email notifications are configured to be sent to subscription owners.