UiPath Documentation
activities
latest
false

Integration Service activities

Last updated May 22, 2026

Azure Defender for Cloud how-to guides

This page includes guides and resources that can help you learn how to create automations using Azure Defender for Cloud activities.

Workflow examples

End-to-end automation solutions that demonstrate how Azure Defender for Cloud activities are used as the malware scanning engine in a broader security response workflow.

Workflow exampleDescriptionActivities
SOAR – File Threat Detection and ResponseEnd-to-end SOAR solution that scans supplier files from email, OneDrive, and SharePoint using Azure Defender and AI Agent, then automatically quarantines threats and triggers full security response.Request Defender Scan, Retrieve Defender Scan Results

Studio Web templates

Reusable Studio Web templates built around Azure Defender for Cloud as the malware scanning layer. Files are sourced from a variety of locations, uploaded to Azure Blob Storage to trigger Defender for Storage scanning, and then retrieved via Defender for Cloud activities for further processing.

TemplateFile sourceDescriptionActivities
SOAR Threat Analysis – Scan Local FilesLocal file systemUpload a local file to Azure Blob Storage, trigger malware scanning with Microsoft Defender for Cloud, enrich findings with Microsoft Sentinel Threat Intelligence, and support incident response in Microsoft Azure Sentinel.Request Defender Scan, Retrieve Defender Scan Results
SOAR Threat Analysis – Scan Files from Google DriveGoogle DriveRetrieve files from Google Drive, upload them to Azure Blob Storage, trigger malware scanning with Microsoft Defender for Cloud, enrich findings with Microsoft Sentinel Threat Intelligence, and support incident response in Microsoft Azure Sentinel.Request Defender Scan, Retrieve Defender Scan Results
SOAR Threat Analysis – Scan Files from Gmail AttachmentsGmailDownload Gmail attachments, upload them to Azure Blob Storage, trigger malware scanning with Microsoft Defender for Cloud, enrich findings with Microsoft Sentinel Threat Intelligence, and support incident response in Microsoft Azure Sentinel.Request Defender Scan, Retrieve Defender Scan Results
SOAR Threat Analysis – Scan Files from OneDriveMicrosoft OneDriveRetrieve files from OneDrive, upload them to Azure Blob Storage, trigger malware scanning with Microsoft Defender for Cloud, enrich findings with Microsoft Sentinel Threat Intelligence, and support incident response in Microsoft Azure Sentinel.Request Defender Scan, Retrieve Defender Scan Results
SOAR Threat Analysis – Scan Files from Outlook AttachmentsMicrosoft OutlookDownload Outlook email attachments, upload them to Azure Blob Storage, trigger malware scanning with Microsoft Defender for Cloud, enrich findings with Microsoft Sentinel Threat Intelligence, and support incident response in Microsoft Azure Sentinel.Request Defender Scan, Retrieve Defender Scan Results
  • Workflow examples
  • Studio Web templates

Was this page helpful?

Connect

Need help? Support

Want to learn? UiPath Academy

Have questions? UiPath Forum

Stay updated