Book Image

Microsoft Defender for Cloud Cookbook

By : Sasha Kranjac
Book Image

Microsoft Defender for Cloud Cookbook

By: Sasha Kranjac

Overview of this book

Microsoft Defender for Cloud is a multi-cloud and hybrid cloud security posture management solution that enables security administrators to build cyber defense for their Azure and non-Azure resources by providing both recommendations and security protection capabilities. This book will start with a foundational overview of Microsoft Defender for Cloud and its core capabilities. Then, the reader is taken on a journey from enabling the service, selecting the correct tier, and configuring the data collection, to working on remediation. Next, we will continue with hands-on guidance on how to implement several security features of Microsoft Defender for Cloud, finishing with monitoring and maintenance-related topics, gaining visibility in advanced threat protection in distributed infrastructure and preventing security failures through automation. By the end of this book, you will know how to get a view of your security posture and where to optimize security protection in your environment as well as the ins and outs of Microsoft Defender for Cloud.
Table of Contents (12 chapters)

Creating logic apps for use in Microsoft Defender for Cloud

Azure Logic Apps is an important part of automating various actions in Microsoft Defender for Cloud. Logic Apps has a much broader application than just being a part of Microsoft Defender for Cloud automation scenarios, but then, it is important to know how to create a logic app that can be used with Microsoft Defender for Cloud.

This recipe will introduce you to creating a simple Logic App that can be used in Microsoft Defender for Cloud automation. The Logic App will send an email using Office 365 when an Microsoft Defender for Cloud alert is triggered.

Getting ready

Open a web browser and navigate to https://portal.azure.com.

How to do it…

To create a Logic App that will send an email when an Microsoft Defender for Cloud alert is triggered, complete the following steps:

  1. In the Azure portal, open Logic Apps.
  2. From the top-left menu, click + Add.
  3. On the Basics tab, under Project Details...