Microsoft Teams

The Microsoft Teams integration enables ARMO users to receive security alerts directly in Microsoft Teams channels.

ARMO supports Microsoft Teams alert delivery using Teams Workflows webhook URLs. After creating a Teams Workflows webhook in Microsoft Teams, configure the generated webhook URL in ARMO and use it as an alert channel in supported ARMO alerting flows.

Alerts can be filtered and routed based on the alerting flow configuration, allowing you to control which ARMO alerts are sent to Microsoft Teams.

Prerequisites

Before configuring the Microsoft Teams integration, make sure you have:

  • Access to the Microsoft Teams channel where ARMO alerts should be posted
  • Permission to create Teams Workflows in Microsoft Teams
  • An ARMO user with an Admin or Manager role

Microsoft has retired Office 365 Connectors / Incoming Webhooks in Microsoft Teams. Existing connector-based webhook configurations may continue to work as long as they are supported by Microsoft, but new Microsoft Teams alerting integrations should be configured using Teams Workflows webhook URLs.

For more details, see Microsoft’s Office 365 Connectors retirement announcement:
https://devblogs.microsoft.com/microsoft365dev/retirement-of-office-365-connectors-within-microsoft-teams/


Create a Teams Workflows webhook

To send ARMO alerts to Microsoft Teams, first create a Teams Workflow that exposes an incoming webhook URL.

  1. In Microsoft Teams, go to the channel where you want ARMO alerts to appear.

  2. Select More options (...) next to the channel name, then select Workflows.

  3. In the Workflows window, search for Send webhook alerts to a channel.

  4. Select the Send webhook alerts to a channel template.

  5. Select the relevant Team and Channel, then select Save.

  6. After the workflow is created, select Copy webhook link.

  7. Keep the copied webhook URL available. You will need it when configuring the Microsoft Teams alerting integration in ARMO.

Configure Microsoft Teams in ARMO

After creating the Teams Workflows webhook URL, configure it in ARMO.

  1. In ARMO, go to Settings --> Integrations.

  2. Under Alerting, locate Microsoft Teams and select Connect.

  3. Select Add webhook.

  4. Enter a name for the Microsoft Teams alert channel.

    For example: Security Alerts

    The alert channel name is used in ARMO when selecting where notifications should be sent. Choose a clear name that identifies the target Teams channel or alert purpose.

  5. Paste the Teams Workflows webhook URL you copied from Microsoft Teams.

  1. Select Save.

  2. After the configuration is saved, ARMO automatically sends a test notification to the Microsoft Teams channel.

Use the Microsoft Teams alert channel

After configuring the Microsoft Teams alert channel, you can use it to send ARMO notifications to the selected Microsoft Teams channel.

Microsoft Teams alert channels can be used in supported alerting flows, including:

When configuring one of these alerting flows, select the Microsoft Teams alert channel as the notification channel. Once enabled, matching alerts will be sent to the configured Microsoft Teams channel.



Did this page help you?