Integration with Microsoft Teams

Sending Report Summary to Teams Channel

You can configure CloudGuard to send summaries to Teams with a HTTP webhook.

Teams Configuration

  1. In Teams, create a new channel.

  2. From the Channel menu , select Connectors.

  3. From the list of connectors, select Incoming Webhook and click Add.

  4. In the new window, click Add again.

  5. Enter the webhook name, for example, "webhook" and click Create.

  6. From the URL field, copy the URL address of the webhook and click Close.

    The Teams channel informs you that you have a connection to the Incoming Webhook.

CloudGuard Configuration

  1. In CloudGuard, navigate to Settings > Configure > Notifications and click Add Notification.

  2. Enter the applicable options as described in Notifications.

  3. In the Immediate Notification section, select Send report summary to Teams channel. The field for the Teams webhook URL opens.

  4. Paste the URL address from Teams to the field.

  5. Click SAVE.

  6. From the Posture Management menu, navigate to the Continuous Posture and add a new Policy with the Notification created in the previous steps.

  7. To make sure that CloudGuard sends notifications to the channel, from the menu of the newly created policy, select Send all alerts.

  8. In the Send All Alerts box that opens, below Notification Type, select Teams Channel and click Send.

  9. You can see that CloudGuard sends the notification to your Teams channel. It includes the summary and a maximum of seven of the most critical alerts.

Sending Notifications to Teams Channel through SNS

Caution - Depending on the size of your environment and the number of notifications that you receive from CloudGuard, Teams may flag the notification traffic as a DDoS event and block the traffic. For large environments, it is recommended to use Sending Report Summary to Teams Channel instead.

Best Practices:

  • Depending on the size of your environment you may want to filter the notifications sent to Teams. You can add a filter in Step 4 when you configure the notification. It is recommended to filter notifications by severity (Critical & High).

  • It is recommended to utilize the built-in summary report functionality for Teams (Sending Report Summary to Teams Channel) if you do not need immediate Teams notifications for individual events.