QuestionQ12

Manage and monitor security posture

You have an Azure subscription named Sub1 that includes a storage account named storage1.

Sub1 has Microsoft Defender for Storage enabled, with on-upload malware scanning enabled for Defender for Storage.

Your company's security team requires all malicious files to be processed automatically by a serverless workflow for quarantine and notification.

You need to ensure that malware scan results initiate an automated response while minimizing operational effort.

What should you configure?

Explanation

Microsoft Defender for Storage can deliver malware scan results through Event Grid for near-real-time, event-driven automation. An Event Grid subscription can route scan-result events to a serverless workflow endpoint, enabling automated quarantine and notifications for malicious blobs.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!