Skip to main content

Microsoft Teams Integration

Get real-time security alerts directly in your Teams channels.

Where Your Team Works

Integrate CastellanAI with Microsoft Teams to receive instant security alerts where your team already collaborates.


Why Teams Integration?

FeatureDescription
Instant AlertsNotified within seconds of critical threats
CustomizableFilter by severity, event type, or specific agents
Rich FormattingColor-coded cards with actionable details

Setup Steps

Step 1: Create an Incoming Webhook in Teams

  1. Go to your Teams channel → Click ⋯ (More options) → Select Connectors
  2. Search for "Incoming Webhook" and click Add
  3. Name it "CastellanAI Security Alerts" and optionally upload a logo
  4. Click Create and copy the generated webhook URL
Keep URL Secure

Anyone with this URL can post messages to your Teams channel. Store it securely.


Alert Format

Teams alerts include rich formatting:

Alert Components

ComponentDescription
Severity BadgeColor-coded (Red=Critical, Orange=High, Yellow=Medium)
Event SummaryAI-generated description
Affected HostHostname and platform
MITRE ATT&CKMapped tactics and techniques
Quick ActionsDirect links to investigate

Advanced Configuration

Multiple Webhook Setup

Configure different channels for different alert types:

ChannelPurposeSeverity
#security-criticalOn-call teamCritical only
#security-allSOC teamHigh and above
#security-dailyDaily digestSummary

Troubleshooting

Test Alert Not Received

CheckSolution
Webhook URLVerify correct and active
Connector statusEnsure connector still installed
Channel permissionsVerify you can post to channel

Best Practices

PracticeDescription
Use dedicated channelsSeparate critical from informational
Set channel notificationsEnable for critical channels
Pin ongoing incidentsUse Teams pin feature
Create workflowsAutomate with Power Automate
📝 Teams Integration Checklist
  • Create incoming webhook in Teams
  • Add webhook to CastellanAI portal
  • Configure severity filters
  • Test webhook delivery
  • Set up channel notifications
  • Train team on alert response
  • Document escalation procedures

What's Next?

GuideDescription
Slack IntegrationAlso use Slack? Set up parallel alerting
Taking ActionRespond to alerts and execute actions
Advanced WebhooksCustom webhook configurations