last sync: 2025-Apr-30 18:25:25 UTC
this is the development/test site - data is not accurate. Go to prod

Deploy Workflow Automation for Microsoft Defender for Cloud alerts

Azure BuiltIn Policy definition

Source Azure Portal
Display name Deploy Workflow Automation for Microsoft Defender for Cloud alerts
Id f1525828-9a90-4fcf-be48-268cdd02361e
Version 5.0.1
Details on versioning
Versioning Versions supported for Versioning: 1
5.0.1
Built-in Versioning [Preview]
Category Security Center
Microsoft Learn
Description Enable automation of Microsoft Defender for Cloud alerts. This policy deploys a workflow automation with your conditions and triggers on the assigned scope. To deploy this policy on newly created subscriptions, open the Compliance tab, select the relevant non-compliant assignment and create a remediation task.
Cloud environments AzureCloud = true
AzureUSGovernment = true
AzureChinaCloud = unknown
Available in AzUSGov The Policy is available in AzureUSGovernment cloud. Version: '5.0.1'
Repository: Azure-Policy f1525828-9a90-4fcf-be48-268cdd02361e
Mode All
Type BuiltIn
Preview False
Deprecated False
Effect Fixed
deployIfNotExists
RBAC role(s)
Role Name Role Id
Contributor b24988ac-6180-42a0-ab88-20f7382dd24c
Rule aliases THEN-ExistenceCondition (4)
Alias Namespace ResourceType Path PathIsDefault DefaultPath Modifiable
Microsoft.Security/automations/isEnabled Microsoft.Security automations properties.isEnabled True False
Microsoft.Security/automations/sources[*].ruleSets[*].rules[*] Microsoft.Security automations properties.sources[*].ruleSets[*].rules[*] True False
Microsoft.Security/automations/sources[*].ruleSets[*].rules[*].expectedValue Microsoft.Security automations properties.sources[*].ruleSets[*].rules[*].expectedValue True False
Microsoft.Security/automations/sources[*].ruleSets[*].rules[*].propertyJPath Microsoft.Security automations properties.sources[*].ruleSets[*].rules[*].propertyJPath True False
Rule resource types IF (1)
THEN-Deployment (3)
Compliance Not a Compliance control
Initiatives usage none
History
Date/Time (UTC ymd) (i) Change type Change detail
2023-05-26 17:43:09 change Patch (5.0.0 > 5.0.1)
2022-06-24 19:15:47 change Major (4.0.0 > 5.0.0)
2021-07-30 15:17:20 change Major (3.0.0 > 4.0.0)
2021-02-17 14:28:42 change Major (2.0.0 > 3.0.0)
2021-02-03 15:09:01 change Major (1.0.0 > 2.0.0)
2020-05-29 15:39:09 add f1525828-9a90-4fcf-be48-268cdd02361e
JSON compare
compare mode: version left: version right:
JSON
api-version=2021-06-01
EPAC