web
You’re offline. This is a read only version of the page.
close
Skip to main content

Notifications

Announcements

Community site session details

Community site session details

Session Id :
Power Platform Community / Forums / Power Automate / CAS Policy automate - ...
Power Automate
Unanswered

CAS Policy automate - impossible travel activity.

(0) ShareShare
ReportReport
Posted on by

Hi,

I want to automate cloud app security policies to take specific action when an alert is generated.  For instance I want to create a policy and automate it to ask users to reset their passwords when their account is flagged for "impossible travel" activity" or multiple logins attempts from different geographical locations.

I have looked at using power automate but I cannot see it taking the above action, unless I'm missing something.  I can get it to send an email alert to admins.

 

I would welcome any suggestions or pointers.

Thank you.

Categories:
I have the same question (0)
  • alrezac Profile Picture
    on at

    Hi,

     

    The issue with this is that webhooks typically trigger with some kind of data update and unless we already have a trigger set up to monitor for that data change it will be hard to integrate this into flow if not impossible. It might be possible to set up an HTTP request to send when an account if flagged but I have no idea how that would work on the non-flow side. I would suggest opening a case with Microsoft Support to help take a look into this, I'll include a link below. Otherwise if any other communities members might have set this up before feel free to pitch in.

     

    Regards,

     

    Alex

     

    -------

     

    Community Support Team _ Alex Rezac
    If this post helps, then please consider Accept it as the solution to help the other members find it more quickly.

  • F1NN Profile Picture
    2 on at

    At Ignite on Tour Amsterdam last year i saw a demonstration connecting CASB to a Azure Runbook via a Flow to accomplish this.

    The case then was, when CASB has a impossible travel alert, start the flow.. kick of a Azure Runbook > check the mailbox of the specific user for an active Out of Office rule > Let Flow use the output of the job > if the rule was found, close the alert, if not found then post a message in teams.

     

    I remember the presenter saying that the demo would be available after, but i haven't been able to find it.

    Connecting flow to Azure Automation however is documented:
    https://danielchronlund.com/2018/11/18/start-your-azure-automation-powershell-runbook-with-a-microsoft-flow-button/
    https://docs.microsoft.com/en-us/azure/automation/start-runbooks

     

Under review

Thank you for your reply! To ensure a great experience for everyone, your content is awaiting approval by our Community Managers. Please check back later.

Helpful resources

Quick Links

Forum hierarchy changes are complete!

In our never-ending quest to improve we are simplifying the forum hierarchy…

Ajay Kumar Gannamaneni – Community Spotlight

We are honored to recognize Ajay Kumar Gannamaneni as our Community Spotlight for December…

Leaderboard > Power Automate

#1
Michael E. Gernaey Profile Picture

Michael E. Gernaey 522 Super User 2025 Season 2

#2
Tomac Profile Picture

Tomac 364 Moderator

#3
abm abm Profile Picture

abm abm 243 Most Valuable Professional

Last 30 days Overall leaderboard