SETUP GUIDE

Connect Microsoft Teams

Get Strix critical alerts in the Teams channel your team already lives in. Create an incoming webhook, paste it into Strix, and send a test — that's the whole setup.

~5 min One-way notifications Incoming webhook

How it works

Teams is a notification destination, not an alert source. The flow runs one way.

Strix → Teams

When a critical alert fires, Strix POSTs a card to your Teams incoming webhook, and it appears in the channel that webhook targets.

Critical alerts only

Only critical alerts notify — the same bar that auto-opens a case — so the channel stays a stream of things worth reacting to, not every event.

Set it up

Three steps from an empty channel to live alerts.

Before you start

  • A Microsoft Teams channel where you can add an incoming webhook.
  • Admin access in Strix (only admins can save the webhook).
  • Permission to add connectors / create a Workflows flow in your tenant.

Two ways to make a Teams webhook

Microsoft is retiring the classic Incoming Webhook connector. If your tenant still has it, use it (step 1 below). If not, create a Power Automate “Workflows” flow with the “When a Teams webhook request is received” trigger — it gives you an incoming webhook URL too. Either URL goes into the same Strix field.

  1. 1
    Create an incoming webhook in Teams

    In Microsoft Teams, open the channel that should receive alerts → ⋯ (More options) → Manage channel → Connectors (or Edit → Connectors). Find Incoming Webhook → Configure, name it “Strix”, optionally upload an icon, and Create. Teams generates a webhook URL — copy it.

    https://<tenant>.webhook.office.com/webhookb2/00000000-0000-0000-0000-000000000000@.../IncomingWebhook/.../...
  2. 2
    Paste it into Strix

    In Strix, open Integrations → Microsoft Teams → Configure. Paste the webhook URL into the Webhook URL field and Save. Only an admin can set this; other members see it as managed by an admin.

  3. 3
    Send a test

    Click Test. Strix posts a sample card to the channel so you can confirm it lands before real alerts flow. The panel also shows delivery health — how many notifications are pending and how many have failed.

What lands in Teams

When
In Teams
A critical alert fires
A card is posted to your channel with the alert title, severity, and source
A non-critical alert
Stays in the Strix inbox — only critical alerts notify, to keep the channel signal-heavy
Delivery fails
Strix retries; persistent failures show in the panel's failed count

You're connected when…

  • Integrations → Microsoft Teams shows your saved webhook URL.
  • Clicking Test posts a sample card into the chosen Teams channel.
  • The delivery panel shows 0 failed deliveries after a successful test.
  • The next critical alert appears in the channel automatically.

Troubleshooting

There's no “Incoming Webhook” connector option
Microsoft is retiring classic Office 365 connectors, so some tenants hide them. Create the webhook via a Power Automate “Workflows” incoming-webhook flow instead, and paste that URL — the Strix side is identical.
Test says it worked but nothing appears in Teams
The webhook targets a different channel than you're watching, or the connector was removed. Recreate the incoming webhook on the correct channel and paste the new URL.
Test fails with a 404 / 410
The webhook was deleted or expired in Teams. Create a fresh incoming webhook and save the new URL in Strix.
The field is greyed out / “managed by an admin”
Teams notifications are admin-configured. Ask an org admin to paste the webhook, or have your role elevated to Admin.
Alerts arrive in the inbox but never in Teams
Only critical alerts notify (Wazuh rule level ≥ 12, or High/critical severity from Splunk/Sentinel). Lower-severity alerts stay in the inbox by design.

Keep the webhook safe

The incoming webhook URL is a secret — anyone with it can post into your channel. Store it only in Strix. If it leaks, remove it in Teams (that invalidates it), create a new one, and update it in Integrations → Microsoft Teams.

Frequently asked

Critical alerts only — the same bar that auto-opens a case. Each card carries the alert's title, severity, and source. Lower-severity alerts stay in the Strix inbox so the channel doesn't fill with noise.

Want critical alerts in Teams? We'll help you wire the webhook.

Book Demo