Jun 10 2022 08:16 AM
What are some of the best methods and strategies to start implementing an integration between Sentinel and TEAMS where when there are certain instances or alerts occurring, said alerts can be pinged to certain members on Microsoft TEAMS like through the use of playbooks, automations and setting up a API connection to integrate the two.
Jun 12 2022 09:57 AM - edited Jun 12 2022 10:01 AM
Hello @cronic1000 ,
You can find Teams connector under Office 365 connector.
After you have connected it, you will be able to create Analytic rules, Playbooks, etc. to get alerts.
Go to Sentinel -> Data connectors -> Search for Office 365 and open it. You will see 3 record types (Exchange, SharePoint, and Teams).
Under "Next steps" on the same connector page you can find 36 analytic rules to create for the mentioned record types.
Jun 13 2022 01:15 AM
Jun 13 2022 02:34 AM
Jun 16 2022 08:05 AM