How to make Defender for cloud workflow automation gets alerts or vulnerability from all subscription and send automatic emails?

Ro_009 0 Reputation points
2025-06-20T02:25:18.8966667+00:00

I'm trying to achieve sending an automatic email in case of any vulnerability detected by Defender for Cloud using its "workflow automation".

I referred to this: https://learn.microsoft.com/en-us/azure/defender-for-cloud/workflow-automation to build the workflow automation. Which is not working as expected. I have a few questions:

  1. Is Defender for Cloud can be used for vulnerability detection? or should I use other Defender suites? If other suites, what is that?
  2. How do I know if my workflow automation ran successfully or not?
  3. From the logic app "activity log", I see "Operation name" > "List Trigger callback URL" status "Succeeded". However, when I see "Development tools" -> "run history," there is no status logged. How is it possible? When the activity log says success, and there is no run history?
  4. How can I make sure that the workflow I'm creating ( in one of the subscriptions) can provide me all the vulnerabilities from the entire Azure resources/subscriptions?
  5. How can this vulnerability scanning be extended to other cloud provider assets/resources?

It would be really appreciated if I can get the answers for my above questions. Thanks.

Microsoft Security Microsoft Defender Microsoft Defender for Cloud
0 comments No comments
{count} votes

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.