Defender for Cloud Apps 與 Microsoft Power Automate 整合,提供自訂的警示自動化與協調手冊。 透過使用 Power Automate 中的 Power Automate 連接器,當 Defender for Cloud Apps 產生警報時,你可以自動化觸發 Playbook。 例如,使用 ServiceNow 連接器自動在工單系統中建立問題,或在 Defender for Cloud Apps 觸發警報時發送批准郵件以執行自訂治理行動。 在開始之前,請確保你符合 先決條件。
必要條件
在製作戰術手冊之前,請確保你符合以下先決條件:
- 您必須擁有有效的 Microsoft Power Automate 方案
- 在 Defender for Cloud Apps 建立 API 令牌。
運作方式
單獨而言,Defender for Cloud Apps 提供預先定義的治理選項,例如在定義政策時暫停使用者或將檔案設為私人。 透過使用 Defender for Cloud Apps 連接器在 Power Automate 建立工作手冊,您可以建立工作流程,啟用自訂的政策治理選項。 在 Power Automate 建立好操作手冊後,會自動同步到 Defender for Cloud Apps。 然後將操作手冊與 Defender for Cloud Apps 中的政策關聯,將警報發送給 Power Automate。 Microsoft Power Automate 提供多種連接器與條件,幫助您打造客製化的工作流程。
Power Automate 中的 Defender for Cloud Apps 連接器支援自動觸發與動作。 當 Defender for Cloud Apps 產生警報時,Power Automate 會自動觸發。 操作包括更改 Defender for Cloud Apps 中的警示狀態。
為適用於雲端應用程式的 Defender 建立 Power Automate 教戰手冊
請執行以下步驟,為 Defender for Cloud Apps 建立 Power Automate 手冊:
在 Defender for Cloud Apps 建立 API 令牌。
前往 Power Automate 入口網站,選擇 「我的流程」,選擇 「新流程」,然後在下拉選單中,在 「從空白中建立你自己的流程」中,選擇 自動化雲端流程。
提供流程名稱,在選擇你的流程觸發器中輸入 Defender for Cloud Apps,並選擇「當警報產生時」。
在認證設定中,貼上你在步驟 1 建立的 Defender for Cloud Apps API 令牌。 給你的連結取個名字,然後選擇 「建立」。
現在根據你的需求建立戰術手冊。 選取 +新增步驟,以定義當 Defender for Cloud Apps 中的原則產生警示時應觸發的工作流程。 你可以新增動作、邏輯條件、切換情況條件或循環,並儲存遊戲手冊。 在這個範例中,我們將新增一個 ServiceNow 連接器。
繼續設定你的操作手冊。 該操作手冊將自動與 Defender for Cloud Apps 同步。 欲了解更多關於在 Power Automate 中建立雲端流程的資訊,請參閱「在 Power Automate 中建立雲端流程」。
在 Microsoft Defender 入口網站的雲端應用程式中,請前往政策 ->政策管理。 在您想要將其警示轉送至 Power Automate 的原則資料列中,選取三個點圖示,然後選取 「編輯原則」。
在「警示」中,選擇「發送警示至Power Automate」,並從下拉選單選擇你的 Power Automate 手本名稱。
您所撰寫或獲得存取權的 Defender for Cloud Apps 劇本,可在 Microsoft Defender 入口網站中檢視:前往 Settings,然後選擇 Cloud Apps,並在 System 底下選取 Playbooks。
注意事項
Power Platform 環境的最大支援數量為 80 個,但每個環境內可用的 playbook 數量沒有限制。
後續步驟
如果你遇到任何問題,我們隨時準備協助。 若要獲得產品問題的協助或支援,請 開啟客服單。
相關內容
請使用以下資源了解更多關於警報自動化的資訊: