A Defender for Cloud workflow automation is creating ticket storms from Low recommendations across the canal subscriptions. How should the Azure security engineer scope the automation?
Select an answer to reveal the explanation.
Short Explanation
If Low recommendations are flooding the help desk, tighten the trigger. Scope the workflow to High severity, the right Defender plan, or a named recommendation so automation stays useful.
Full Explanation
Workflow automation remains usable when conditions filter on alert severity, Defender plan, or a specific recommendation name rather than firing on every Low posture item. Over-broad triggers create ticket storms. Disabling Defender for Cloud removes protection, and timer-only Logic Apps without alert or recommendation conditions are not Defender for Cloud workflow automation.