A company uses Microsoft Defender for Cloud to monitor its security posture. The compliance team wants to receive email notifications immediately when a control in the ISO 27001 regulatory compliance standard fails. They want to be alerted only when specific controls change from 'compliant' to 'non-compliant'. Which feature should they configure?
Workflow automation in Microsoft Defender for Cloud is the native mechanism to react to changes in regulatory compliance assessments. You configure an automation rule to watch for a specific assessment status change (e.g., a control failing) and then invoke a Logic App or Power Automate flow to send an email, post to Teams, or create a ticket. This provides the proactive notification (e.g., email) required by the scenario. It is the only built-in way to directly trigger external actions based on compliance assessment changes.
Why this answer
Workflow automation in Microsoft Defender for Cloud can be configured to trigger based on regulatory compliance assessment changes, specifically when a control transitions from 'compliant' to 'non-compliant'. This allows the compliance team to receive immediate email notifications for ISO 27001 control failures without manual polling or dashboard monitoring.
Exam trap
The trap here is that candidates often confuse Security Alerts (which are threat-focused) with compliance state change notifications, or assume the Regulatory Compliance dashboard's continuous export can directly send real-time email alerts, but it only exports data to external sinks without built-in notification logic.
How to eliminate wrong answers
Option A is wrong because Security Alerts in Defender for Cloud are triggered by threat detection events (e.g., suspicious activities, vulnerabilities), not by regulatory compliance control state changes. Option B is wrong because the Regulatory Compliance dashboard with continuous export sends data to Log Analytics or Event Hubs for archival and analysis, but it does not natively support immediate email notifications based on specific control state transitions. Option D is wrong because custom recommendations are used to define additional security best practices or policies, not to trigger notifications on compliance control changes.