Microsoft Defender ATP Trigger doesn't work

Shohei Morino 5 Reputation points
2024-09-20T06:56:35+00:00

Microsoft Defender ATP trigger does not work.

I am using Microsoft Defender ATP triggers for the Consumption plan Logic Apps.

We confirmed from the Defender Portal (security.microsoft.com) that the MDE alert was issued and checked the execution and trigger history of Logic Apps, but it was neither executed nor triggered.

What are the prerequisites, if any, for triggering?

When creating the connector for the Microsoft Defender ATP trigger, we used the Logic Apps system-assigned Managed ID and granted the following permissions to the Managed ID

"WindowsDefenderATP/Alert.Read.All/Read all alerts"

I created a connector with the OAuth option as a test, but the result was the same. In this case, the authenticated user was given the Entra Security Administrator role.

Translated with DeepL.com (free version)

Azure Logic Apps
Azure Logic Apps
An Azure service that automates the access and use of data across clouds without writing code.
3,162 questions
{count} vote

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.