Troubleshooting Threat Detector (TD)
Written by
Updated at July 17, 2026
Service account does not have sufficient permissions for resources in scope
The service account lacks permissions for resources within the collection scope. The error description will include the service account ID and the resource it was unable to access. Make sure the service account has the threat-detector.worker role for the resources scanned by the module.
Alert delivery for this rule is restricted
The user received over 100 alerts triggered by a single rule within five minutes. In the error description, you will see the number of alerts and the timestamp of the last alert. Try to identify the root cause of mass alerts or mute alerts for this rule.