Operations
Notification channels setup
Configure Slack, Microsoft Teams, or PagerDuty delivery for ITDR alerts, incidents, connector health, and response-action outcomes.
Updated May 6, 2026 | 13 min
Who can configure notifications
- Partner admins can configure notification channels while operating in a managed customer tenant.
- Tenant admins can configure notification channels for their own tenant.
- Super admins can configure notification channels after switching into the target tenant.
- Analysts and read-only users can use alert and incident workflows, but they do not configure notification integrations.
Setup order
- Choose the destination. Decide whether this tenant needs Slack, Teams, PagerDuty, or separate channels for different event types.
- Create the destination credential. Create the Slack incoming webhook, Teams workflow webhook, or PagerDuty routing key in the customer-approved workspace or service.
- Open ITDR Settings. Sign in as partner admin, tenant admin, or super admin, switch to the target tenant if needed, then open Settings -> Notification channels.
- Add the channel. Enter a channel name, choose Slack, Teams, or PagerDuty, set the minimum severity, paste the webhook URL or routing key, and select event types.
- Send a test. Use Test to confirm the destination accepts ITDR notifications before relying on the integration during an incident.
- Review delivery history. Use Recent notification deliveries to confirm events were queued, sent, retried, or failed.
What to create before opening ITDR
| Destination | Create first | Paste into ITDR | Best use |
|---|---|---|---|
| Slack | Incoming webhook for the destination Slack channel | Webhook URL that starts with https://hooks.slack.com/services/... | SOC triage channels, customer success handoff channels, or partner operations channels |
| Microsoft Teams | Teams workflow or incoming webhook that accepts a JSON card payload | Webhook URL generated by the Teams workflow or connector | Customer IT or security operations teams already working in Teams |
| PagerDuty | Events API v2 integration on the target PagerDuty service | Integration routing key | Critical incident paging and escalation workflows |
Provider-side setup steps
Before you start
- Slack workspace permission to create or manage apps.
- A destination channel selected by the customer or MSP, such as #security-alerts or #itdr-incidents.
Create the value to paste into ITDR
- Open api.slack.com/apps and choose Create New App.
- Choose From scratch, enter an app name such as ITDR Notifications, and select the customer workspace.
- Open Incoming Webhooks from the app settings menu.
- Turn Activate Incoming Webhooks on.
- Select Add New Webhook to Workspace.
- Choose the Slack channel that should receive ITDR notifications and approve access.
- Copy the generated webhook URL. It normally starts with https://hooks.slack.com/services/.
- Paste that URL into ITDR Settings -> Notification channels with channel type Slack.
Operational notes
- Create separate Slack webhooks if different ITDR event types should go to different Slack channels.
- Treat the webhook URL like a secret because anyone with it can post to that Slack channel.
Microsoft Teams
Microsoft Teams workflow webhook docsBefore you start
- Permission to create workflows in the target Microsoft Teams tenant.
- A target team and channel or chat approved for ITDR notifications.
Create the value to paste into ITDR
- Open Microsoft Teams and go to the channel or chat that should receive ITDR notifications.
- Select More options next to the channel or chat, then choose Workflows.
- Search for webhook workflow templates and choose the template for posting to a channel when a webhook request is received.
- Name the workflow clearly, such as ITDR Critical Notifications.
- Confirm or choose the target team and channel.
- Save the workflow.
- Open the workflow trigger details and copy the HTTP POST URL.
- Paste that URL into ITDR Settings -> Notification channels with channel type Teams.
Operational notes
- Microsoft is moving Teams webhook setup toward Workflows. Older incoming webhook connectors may not be available in every tenant.
- Teams workflows are owned by a user account. Use a durable service or operations owner where the customer policy allows it.
Before you start
- PagerDuty admin or manager access to the service that should receive ITDR incidents.
- A target service and escalation policy approved for security notifications.
Create the value to paste into ITDR
- Open PagerDuty and go to Services.
- Create a new service or open the existing service that should receive ITDR events.
- Open the Integrations tab for that service.
- Add an integration and choose Events API V2.
- Name the integration clearly, such as ITDR Notifications.
- Save the integration.
- Copy the Integration Key. PagerDuty also calls this the routing key for Events API v2.
- Paste that key into ITDR Settings -> Notification channels with channel type PagerDuty.
Operational notes
- Use PagerDuty for high-confidence incidents and severity changes, not every low-severity alert.
- If the customer uses Event Orchestration, confirm whether ITDR should use the service integration key or an orchestration routing key.
Event types
| ITDR event | What it means |
|---|---|
| New alerts | An ITDR detection created a new alert. |
| New incidents | A grouped incident was created from one or more related alerts. |
| Severity changes | An incident severity changed after triage or correlation. |
| Status changes | An incident moved through investigation, containment, resolution, or false-positive states. |
| Failed response actions | A containment or response action failed and needs operator review. |
| Successful response actions | A containment or response action completed. This is available but can be noisy. |
| Connector degraded | A Microsoft or platform connector has degraded telemetry, authorization, or sync health. |
Recommended routing patterns
- Critical incidents to PagerDuty with minimum severity Critical or High.
- Connector degraded events to a partner operations Slack or Teams channel.
- Failed response actions to the SOC channel so operators can retry or investigate.
- New alerts to Slack only for High and Critical severity to avoid notification fatigue.
Validation checklist
- Test notification reaches the expected Slack channel, Teams channel, or PagerDuty service.
- The ITDR channel list shows the webhook masked, not exposed in full.
- Delivery history shows `sent` after a test or real routed event.
- If delivery fails, the failed row shows the provider error so the admin can fix the destination.
- The selected event types match the customer operating model and escalation expectations.
Handoff template
Tenant: Configured by: Destination type: Slack / Teams / PagerDuty Destination owner: Channel or service name: Minimum severity: Enabled event types: Test notification result: Delivery history checked: Open follow-up: