Skip to main content
Get a list of alert resources created to track suspicious activities in an organization. This operation lets you filter and sort through alerts to create an informed cyber security response. It exposes a collection of alerts that were flagged in your network, within the time range you specified in your environment retention policy. The most recent alerts are displayed at the top of the list.
  • Least privileged Microsoft Graph permission to access the action via application: SecurityAlert.Read.All.
  • Higher privileged Microsoft Graph permission to access the action via application: SecurityAlert.ReadWrite.All.
External DocumentationTo learn more, visit the Microsoft Entra ID documentation.

Basic Parameters

Advanced Parameters

Example Output

Workflow Library Example

List Alerts with Microsoft Entra Id and Send Results Via Email
Workflow LibraryPreview this Workflow on desktop