StudyToCert

All certifications / SC-200 / Lessons

Microsoft Certified: Security Operations Analyst Associate SC-200 · Domain 2: Respond to security incidents

Defender for Cloud security alerts: alert details, the Take action tab, triggering automation

▶ Watch the overview video

Last reviewed September 30, 2026 · Leer en español

When a Microsoft Defender for Cloud workload plan detects a threat, such as suspicious process execution on a virtual machine (VM), access to a storage account from a suspicious IP address, a SQL injection attempt or a suspicious Azure Resource Manager operation, it raises a security alert. Alerts appear on Defender for Cloud's Security alerts page and, through the integration with Defender XDR, in the Defender portal incident queue. They can also flow to Microsoft Sentinel through its Defender for Cloud connector. Remember that alerts come only from paid workload plans, not from posture management.

Free account

Keep reading for free

Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 6 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.

Sign up free Log in

Study SC-200 for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the SC-200 study plan