azure-monitor-action-group-webhook-properties

Action-group webhook URIs can carry query tokens and expose Entra application identifiers.

azurecritical service: azure:monitor emits ContainsSecret

Where it sits

locationMicrosoft.Insights/actionGroups.properties.webhookReceivers[].{serviceUri,identifierUri,objectId,tenantId,useAadAuth}
location kindconfig_field
data kindscredential webhook_secret sensitive_data
emits edgeContainsSecret
serviceAzure Monitor / Activity Log (azure:monitor)

Collection recipe

access moderead_api
operationAction Groups - Get
response pathproperties.webhookReceivers[]
encodingjson
params{"resource_id": "\u003cazure-resource-id\u003e"}

Required permissions

Microsoft.Insights/actionGroups/read

References

move · open · esc close