Skip to main content
Triggers a workflow on every new alert. The alerts are aggregated from various security products within the Microsoft Defender suite. Sources of Alerts in Microsoft Defender XDR:
  • Microsoft Defender for Endpoint (MDE)
  • Microsoft Defender for Identity (MDI)
  • Microsoft Defender for Office 365 (MDO)
  • Microsoft Defender for Cloud Apps (MDCA)
  • Microsoft Defender for Cloud (MDC)
  • Azure Active Directory Identity Protection
  • Microsoft Defender Antivirus (MDA)
  • Microsoft Sentinel (formerly Azure Sentinel)
The least required permission is SecurityAlert.Read.All. Endpoint: https://graph.microsoft.com/v1.0/security/alerts_v2
Workflows with this trigger check for new events every 5 minutes by default. You can adjust this interval in the Trigger settings.

Sample Event