Post Message Teams

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Content Index


This playbook will post a message in a Microsoft Teams channel when an Incident is created in Microsoft Sentinel.

Attribute Value
Type Playbook
Solution SentinelSOARessentials
Source View on GitHub

Additional Documentation

📄 Source: Post-Message-Teams/incident-trigger/readme.md

Post-Message-Teams (Incident Trigger)

author: Yaniv Shasha

Summary

This playbook posts a message in a Microsoft Teams channel when an incident is created in Microsoft Sentinel. The message includes key incident details such as severity, title, status, ID, and URL.

Prerequisites

Deployment instructions

  1. To deploy the playbook, click the Deploy to Azure button below. This will launch the ARM Template deployment wizard.
  2. Fill in the required parameters:
    • Playbook Name
    • Teams Group ID
    • Teams Channel ID

Deploy to Azure Deploy to Azure Gov

Post-deployment Instructions

a. Authorize connections

Once deployment is complete, authorize each connection.

  1. Open the Logic App in the Azure portal.
  2. Click the Teams connector resource.
  3. Click Edit API connection.
  4. Click Authorize.
  5. Sign in.
  6. Click Save.
  7. Repeat steps for other connections as needed.

Note: The message will be sent from the user who creates the connection.

b. Attach the playbook

  1. In Microsoft Sentinel, configure an automation rule to trigger this playbook when an incident is created. - Learn more about automation rules

    Note: Enable the playbook if it is disabled before assigning it to the automation rule.

Screenshots

Playbook
Playbook

Teams Message Example
Teams Message Light Teams Message Dark


Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Playbooks · Back to SentinelSOARessentials