web
You’re offline. This is a read only version of the page.
close
Skip to main content

Notifications

Announcements

Community site session details

Community site session details

Session Id :
Power Platform Community / Forums / Power Automate / Auto resolve Informati...
Power Automate
Unanswered

Auto resolve Informational-severity alert: Creation of forwarding/redirect rule for internal redirections.

(0) ShareShare
ReportReport
Posted on by 7

Good day,

I've been asked to automate the following process we have in place in my org:

  1. A User creates a forwarding rule
  2. A mail is sent to a certain DL containing the link of the Alert so we can process it manually

Luminaire_0-1656494563433.png

  1. If the forward/redirect is internal (xxx@myorg.com) then the alert is set to "Resolved" and "Internal" as a comment
  2. If the forward/redirect is external (xxx@gmail.com) then we have to remove this auto-forward / rule (manual process)

I pretty sure there are many ways to overlook this but what I have so far is:

 

Luminaire_1-1656494704798.png

It seems that this kind of Informational Alerts does not reside in the Defender for Cloud App but more in the Security Center.
I'm also receiving a 403 error code when testing the flow whereas I have activated all appropriate PIM Role (Security Operator):

Luminaire_2-1656494918108.png

So the main point here would be to have that if the redirection is done internally, the Alert closes automatically with the "Resolved" status and "Internal" as a comment. External ones will always be done manually.
I'm kind of stuck here and spent few hours looking everywhere but without any real success.

I don't know if this helps but I already have an Azure Sentinel query that lists all the existing alerts showing the forwarded email address that is allowing us to select all Alerts from the "Compliance" center and bulk solve them by filtering on the correct policy.

 

 

Luminaire_3-1656495244194.png

I was also thinking to extract the link from the mails we receive to have the alert ID but this one is encoded with the Safe Link feature.

Is there's someone that could point me in the right direction or giving me a few tips to have this achieved?
FYI, it seems I don't have access to the Microsoft Graph Security connector which might be the key here. Correct?

Many thanks in advance.

 

Categories:
I have the same question (0)

Under review

Thank you for your reply! To ensure a great experience for everyone, your content is awaiting approval by our Community Managers. Please check back later.

Helpful resources

Quick Links

Forum hierarchy changes are complete!

In our never-ending quest to improve we are simplifying the forum hierarchy…

Ajay Kumar Gannamaneni – Community Spotlight

We are honored to recognize Ajay Kumar Gannamaneni as our Community Spotlight for December…

Leaderboard > Power Automate

#1
Michael E. Gernaey Profile Picture

Michael E. Gernaey 525 Super User 2025 Season 2

#2
Tomac Profile Picture

Tomac 324 Moderator

#3
abm abm Profile Picture

abm abm 232 Most Valuable Professional

Last 30 days Overall leaderboard