Microsoft Defender for Endpoint
Developer and API

Use the Microsoft Defender for Endpoint Power Automate connector to create event-triggered flows

In brief

The article now describes creating Power Automate flows with the Microsoft Defender for Endpoint connector, including workflows triggered by events or alerts. Wording and metadata were also refreshed.

What Defender admins need to know

Administrators following this guide will see updated Power Automate terminology and clearer event- and alert-triggered workflow guidance.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Use the Power Automate connector to create an event flow

Automating security procedures is a standard requirement for every modern Security Operations Center (SOC). For SOC teams to operate in the most efficient way, automation is a must. Use Microsoft Power Automate to help you create automated workflows and build an end-to-end procedure automation within a few minutes. Microsoft Power Automate supports different connectors that were built exactly for automating security workflows.

Use this articleguide to guide youcreate event-triggered automations in creating automationsPower Automate, such as workflows that are triggered by an event, such asrun when a new alert is created in your tenant. Microsoft Defender API has an official Power Automate Connector with many capabilities.

:::image type="content" source="media/api-flow-0.png" alt-text="The Actions page in the Microsoft Defender 365 portal" lightbox="media/api-flow-0.png" :::

Example: Create an event-triggered flow

The followingThis example demonstrates how to create a Flowflow that is triggered anytimewhenever a new Alertalert occurs on your tenant. You'll define what event starts the flow and which follow-up action the flow takes when the trigger occurs.

  1. Log in to Microsoft Power Automate.

Related content

For more information, see the following resource: