Operations

Notification channels setup

Configure Slack, Microsoft Teams, or PagerDuty delivery for ITDR alerts, incidents, connector health, and response-action outcomes.

Updated May 6, 2026 | 13 min

Who can configure notifications

  • Partner admins can configure notification channels while operating in a managed customer tenant.
  • Tenant admins can configure notification channels for their own tenant.
  • Super admins can configure notification channels after switching into the target tenant.
  • Analysts and read-only users can use alert and incident workflows, but they do not configure notification integrations.

Setup order

  1. Choose the destination. Decide whether this tenant needs Slack, Teams, PagerDuty, or separate channels for different event types.
  2. Create the destination credential. Create the Slack incoming webhook, Teams workflow webhook, or PagerDuty routing key in the customer-approved workspace or service.
  3. Open ITDR Settings. Sign in as partner admin, tenant admin, or super admin, switch to the target tenant if needed, then open Settings -> Notification channels.
  4. Add the channel. Enter a channel name, choose Slack, Teams, or PagerDuty, set the minimum severity, paste the webhook URL or routing key, and select event types.
  5. Send a test. Use Test to confirm the destination accepts ITDR notifications before relying on the integration during an incident.
  6. Review delivery history. Use Recent notification deliveries to confirm events were queued, sent, retried, or failed.

What to create before opening ITDR

DestinationCreate firstPaste into ITDRBest use
SlackIncoming webhook for the destination Slack channelWebhook URL that starts with https://hooks.slack.com/services/...SOC triage channels, customer success handoff channels, or partner operations channels
Microsoft TeamsTeams workflow or incoming webhook that accepts a JSON card payloadWebhook URL generated by the Teams workflow or connectorCustomer IT or security operations teams already working in Teams
PagerDutyEvents API v2 integration on the target PagerDuty serviceIntegration routing keyCritical incident paging and escalation workflows

Provider-side setup steps

Before you start

  • Slack workspace permission to create or manage apps.
  • A destination channel selected by the customer or MSP, such as #security-alerts or #itdr-incidents.

Create the value to paste into ITDR

  1. Open api.slack.com/apps and choose Create New App.
  2. Choose From scratch, enter an app name such as ITDR Notifications, and select the customer workspace.
  3. Open Incoming Webhooks from the app settings menu.
  4. Turn Activate Incoming Webhooks on.
  5. Select Add New Webhook to Workspace.
  6. Choose the Slack channel that should receive ITDR notifications and approve access.
  7. Copy the generated webhook URL. It normally starts with https://hooks.slack.com/services/.
  8. Paste that URL into ITDR Settings -> Notification channels with channel type Slack.

Operational notes

  • Create separate Slack webhooks if different ITDR event types should go to different Slack channels.
  • Treat the webhook URL like a secret because anyone with it can post to that Slack channel.

Before you start

  • Permission to create workflows in the target Microsoft Teams tenant.
  • A target team and channel or chat approved for ITDR notifications.

Create the value to paste into ITDR

  1. Open Microsoft Teams and go to the channel or chat that should receive ITDR notifications.
  2. Select More options next to the channel or chat, then choose Workflows.
  3. Search for webhook workflow templates and choose the template for posting to a channel when a webhook request is received.
  4. Name the workflow clearly, such as ITDR Critical Notifications.
  5. Confirm or choose the target team and channel.
  6. Save the workflow.
  7. Open the workflow trigger details and copy the HTTP POST URL.
  8. Paste that URL into ITDR Settings -> Notification channels with channel type Teams.

Operational notes

  • Microsoft is moving Teams webhook setup toward Workflows. Older incoming webhook connectors may not be available in every tenant.
  • Teams workflows are owned by a user account. Use a durable service or operations owner where the customer policy allows it.

Before you start

  • PagerDuty admin or manager access to the service that should receive ITDR incidents.
  • A target service and escalation policy approved for security notifications.

Create the value to paste into ITDR

  1. Open PagerDuty and go to Services.
  2. Create a new service or open the existing service that should receive ITDR events.
  3. Open the Integrations tab for that service.
  4. Add an integration and choose Events API V2.
  5. Name the integration clearly, such as ITDR Notifications.
  6. Save the integration.
  7. Copy the Integration Key. PagerDuty also calls this the routing key for Events API v2.
  8. Paste that key into ITDR Settings -> Notification channels with channel type PagerDuty.

Operational notes

  • Use PagerDuty for high-confidence incidents and severity changes, not every low-severity alert.
  • If the customer uses Event Orchestration, confirm whether ITDR should use the service integration key or an orchestration routing key.

Event types

ITDR eventWhat it means
New alertsAn ITDR detection created a new alert.
New incidentsA grouped incident was created from one or more related alerts.
Severity changesAn incident severity changed after triage or correlation.
Status changesAn incident moved through investigation, containment, resolution, or false-positive states.
Failed response actionsA containment or response action failed and needs operator review.
Successful response actionsA containment or response action completed. This is available but can be noisy.
Connector degradedA Microsoft or platform connector has degraded telemetry, authorization, or sync health.

Recommended routing patterns

  • Critical incidents to PagerDuty with minimum severity Critical or High.
  • Connector degraded events to a partner operations Slack or Teams channel.
  • Failed response actions to the SOC channel so operators can retry or investigate.
  • New alerts to Slack only for High and Critical severity to avoid notification fatigue.

Validation checklist

  • Test notification reaches the expected Slack channel, Teams channel, or PagerDuty service.
  • The ITDR channel list shows the webhook masked, not exposed in full.
  • Delivery history shows `sent` after a test or real routed event.
  • If delivery fails, the failed row shows the provider error so the admin can fix the destination.
  • The selected event types match the customer operating model and escalation expectations.

Handoff template

Tenant:
Configured by:
Destination type: Slack / Teams / PagerDuty
Destination owner:
Channel or service name:
Minimum severity:
Enabled event types:
Test notification result:
Delivery history checked:
Open follow-up: