Microsoft Defender for Cloud Apps
Incidents and response

Integrate with Microsoft Power Automate for custom alert automation

In brief

The documentation now explicitly requires creating a Defender for Cloud Apps API token before creating playbooks and using that token in the connection’s authentication settings.

What Defender admins need to know

Administrators setting up the integration must create and provide the API token.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Integrate with Microsoft Power Automate for custom alert automation

Defender for Cloud Apps integrates with Microsoft Power Automate to provide custom alert automation and orchestration playbooks. By using the Power Automate connectors available in Power Automate, you can automate the triggering of playbooks when Defender for Cloud Apps generates alerts. For example, automatically create an issue in ticketing systems using ServiceNow connector or send an approval email to execute a custom governance action when an alert is triggered in Defender for Cloud Apps. Before you begin, make sure you meet the prerequisites.

Prerequisites

Before you create playbooks, make sure you meet the following prerequisite:prerequisites:

How it works

![Screenshot of the Power Automate trigger configuration selecting When an alert is generated for Defender for Cloud Apps.](media/flow-when-alert.png)
  1. Under Authentication settings, paste the Defender for Cloud Apps API token you created earlier.in step 1. Give your connection a name and select Create.

    Screenshot of the Power Automate authentication settings where the API token is pasted to create a connection.