
This article has not been completed yet. However, it may already contain helpful Information and therefore it has been published at this stage.
Customer request / need:
The customer would like to be notified when a new recommendation appears in the Windows Defender for Cloud panel.

Initial situation:



We can see that no resources are monitored and therefore there are no recommendations.
Logic App:










At this point it seems that there exists a bug
You first need to build an empty Logic app, where you then add the Microsoft Defender for Cloud trigger manually to be able to use the template afterwards.





Azure Security Center Workflow Automation






Activating the Microsoft Defender for Cloud Assessment


Now, after some time, recommendations should appear and we should be informed about them by mail.
References:
Azure Security - Easy Wins - Part 1
Azure Security - Easy Wins - Part 1
