Forum Discussion

cronic1000's avatar
cronic1000
Copper Contributor
Jun 10, 2022

Integration of Microsoft Sentinel & Microsoft TEAMS for integration of alerts

What are some of the best methods and strategies to start implementing an integration between Sentinel and TEAMS where when there are certain instances or alerts occurring, said alerts can be pinged to certain members on Microsoft TEAMS like through the use of playbooks, automations and setting up a API connection to integrate the two.

  • mikhailf's avatar
    mikhailf
    Steel Contributor

    Hello cronic1000 ,

     

    You can find Teams connector under Office 365 connector. 

    After you have connected it, you will be able to create Analytic rules, Playbooks, etc. to get alerts.

     

    Go to Sentinel -> Data connectors -> Search for Office 365 and open it. You will see 3 record types (Exchange, SharePoint, and Teams). 

     

    Under "Next steps" on the same connector page you can find 36 analytic rules to create for the mentioned record types.

     

     

Resources