Setting up email alerts or automatic workflows for Connection errors (For both MCAS & DFI)

Copper Contributor

Hi,

 

I am trying to set up alerts as a minimum if a connected app in Cloud App Security goes from status "Connected" to status "Connection Error". I would like the same for Defender for Identity if the sensors fail.

Anybody have any experience on how can this be achieved?  

 

Would be great if such an alert could trigger an automatic workflow, that eg. creates a ticket in an ITSM system & assigns the responsible team depending on the app, which connection has failed.

Really hope someone can help - I have been looking in MS Docu with no luck.

Thanks :)

 

 

2 Replies

@Lassekatten 

 

MDI is the easy one. It will generate a Health Alert if your Sensor goes down. You can configure alerts in the UI on the portal. 

 

Tech.png

 

In MCAS, I'm not sure there's any alerting for an app connector going down. You might be able to configure a Power Automate Flow for this. Power Automate | Microsoft Power Platform

@jurowley Thanks for the reply :) I found the Health Alert from in the MDI portal. 

 

In Power Automate, I can only find one MCAS trigger, which is 'alert generation', so I do not think PA supports the use case. 

Could it be possible to leverage Microsoft Graph to set this up?

I cannot figure out, what parameter to look for though.

 

Best Regards