NotificationsMicrosoft Teams

Microsoft Teams

Connect Microsoft Teams to RAD Security for workflow notifications and alerts.

This guide walks you through connecting Microsoft Teams to RAD Security, enabling automated notifications from workflows directly to your Teams channels and users. The setup requires administrative access to configure a service account and grant organization-wide consent.

Important: Microsoft Teams is currently designed for workflow notifications and is not integrated with RADBot.

Prerequisites

Before you begin, ensure you have:

Microsoft 365 Business or Enterprise subscription
Global Administrator or Application Administrator role in Microsoft Entra ID
Access to create users in your Microsoft 365 tenant
Access to RAD Security workspace with integration permissions

This integration requires one-time administrative setup including creating a service account and granting admin consent. Plan for approximately 10-15 minutes for the complete setup process.


The first step is to grant organization-wide consent for the RAD Security application. This allows the service account (created in Step 2) to send notifications without requiring individual user consent.

Time Required: 2-3 minutes Required Role: Global Administrator or Application Administrator

Access the Admin Consent URL

Open the following admin consent URL in your browser:

https://login.microsoftonline.com/common/adminconsent?client_id=7f4e5217-6d0a-4fa2-97d8-a55ab5a67ec4&redirect_uri=https://api.rad.security/integrations/admin-consent/callback

This will grant consent for your organization and redirect you to a confirmation page.

Log in as Administrator

You'll be redirected to Microsoft's login page. Log in using your Microsoft 365 administrator account (Global Administrator or Application Administrator role).

Review Permissions

Review the permissions that RAD Security is requesting:

  • Read team names and descriptions - To identify available Teams
  • Read channel names and descriptions - To target specific channels
  • Send messages to channels - To deliver workflow notifications
  • Send and read direct messages - To send notifications to individual users
  • Read user profiles - To identify users for direct messaging
  • Maintain offline access - To refresh tokens automatically

Grant Consent

Click Accept to grant organization-wide consent for the RAD Security application.

You'll be redirected to a confirmation page showing "Admin Consent Granted" when successful.

Admin consent is now granted! This step only needs to be completed once for your entire organization. Regular users and the service account won't see permission prompts after this.


Step 2: Create Service Account

The Microsoft Teams integration uses a dedicated service account to send notifications on behalf of RAD Security. This ensures notifications come from a consistent, identifiable source.

Time Required: 5 minutes Required Role: User Administrator or Global Administrator

Navigate to Microsoft 365 Admin Center

Go to Microsoft 365 Admin Center and sign in with your administrator account.

Navigate to UsersActive users

Create New User

Click Add a user to begin creating the service account.

Enter the following details:

  • Username: Choose a descriptive name (e.g., rad-bot, rad-security, security-notifications)
  • Display name: "RAD Security" or "RAD Security Bot"
  • Domain: Use your organization's primary domain

Example: rad-bot@yourcompany.com

Assign License

Select a license that includes Microsoft Teams access:

  • Microsoft 365 Business Basic (minimum)
  • Microsoft 365 Business Standard
  • Microsoft 365 E3 or E5

A license is required for the service account to send Teams messages using delegated permissions. The account cannot send messages without a license that includes Teams functionality.

Configure Password

Set a strong password for the service account:

  • Uncheck "Require this user to change their password when they first sign in"
  • Generate a secure password (20+ characters recommended)
  • Save these credentials securely in your organization's password manager or secrets vault

Store the username and password securely! You'll need these credentials in Step 4 to complete the OAuth flow.

Complete User Creation

Review the settings and click Finish adding to create the service account.

Verify the account appears in your Active Users list with an active license.

Your service account is now ready! Make sure the credentials are stored securely before proceeding.


Step 3: Configure Integration in RAD Security

Now that admin consent is granted and the service account is created, you can configure the integration in RAD Security.

Time Required: 2 minutes Required Role: RAD Security tenant administrator

Navigate to Integrations

Log in to RAD Security and navigate to Data SourcesIntegrations.

Select Microsoft Teams

Find and click on Microsoft Teams from the list of available notification integrations.

Enter Integration Details

Provide a descriptive name for this integration:

  • Integration Name: e.g., Microsoft Teams - Production

Click Connect to begin the OAuth authorization flow.


Step 4: Complete OAuth Authorization

You'll now complete the OAuth flow using the service account credentials you created in Step 2.

Time Required: 2 minutes Required Credentials: Service account username and password from Step 2

Sign In as Service Account

After clicking Connect, you'll be redirected to Microsoft's login page.

Important: Log in using the service account credentials (e.g., rad-bot@yourcompany.com), not your personal administrator account.

Complete Authentication

Enter the service account password.

Since admin consent was already granted in Step 1, you should not see a permissions consent screen. The authentication will complete automatically.

Verify Success

You'll be redirected back to RAD Security with the integration configured.

Verify that:

  • Integration status shows Connected
  • Tenant name is displayed correctly
  • Scopes are listed properly

OAuth authorization is complete! The integration is now active and ready to send notifications.


Step 5: Add Bot to Teams Channels

For the RAD Security bot to send messages to Teams channels, the service account must be added as a member of those channels. This is required because we use delegated permissions where the authenticated user (service account) must be a channel member to post messages.

This step is performed by Teams users, not administrators. Each channel owner or member can add the bot to their channels as needed.

Open Microsoft Teams

Launch Microsoft Teams (desktop app or web version).

Navigate to Target Channel

Go to the Team and channel where you want to receive notifications.

Add the Bot as a Member

Click the three dots (⋯) next to the channel name and select Manage channel.

  1. Go to the Members tab
  2. Click Add members
  3. Search for your service account name (e.g., "RAD Security Bot" or "rad-bot@yourcompany.com")
  4. Click Add and set the role to Member

You can also add the bot by typing /add in the channel followed by the bot's name or email address.

Repeat for Other Channels

Repeat this process for each channel that should receive workflow notifications.

Note: The bot does not need to be added to send direct messages to users. DMs work automatically once the integration is configured.


Verify Integration

After completing the setup, verify that the integration is working properly:

Check Integration Status

Go to Data SourcesIntegrations in RAD Security and locate your Microsoft Teams integration.

Verify that:

  • Status shows Connected
  • Tenant name matches your organization
  • User information is displayed correctly

Send Test Notification to Channel

Configure a test workflow to send a notification to a Teams channel:

  • Target format: "Team Name/Channel Name"
  • Example: "Security Operations/Alerts"

Verify the message appears in the specified Teams channel.

Send Test Direct Message

Configure a test workflow to send a notification to a user:

  • Target format: User's email address
  • Example: "user@yourcompany.com"

Verify the user receives a direct message from the RAD Security bot in Teams Chat.

Your Microsoft Teams integration is now fully configured! You can now receive workflow notifications and alerts in Teams channels and direct messages.


Configuring Notification Destinations

When setting up workflow notifications, you can specify where messages should be delivered in Microsoft Teams:

Send to a Channel

To send notifications to a specific Teams channel, use the format "Team Name/Channel Name":

Security Operations/Critical Alerts
  • Team and channel names are case-sensitive
  • Use the exact names as they appear in Microsoft Teams
  • The service account must be added as a member of the channel (see Step 5)
  • Works with both standard and private channels

Example targets:

  • "Engineering/Deployments"
  • "Security Team/Incident Response"
  • "Operations/Monitoring Alerts"

Send Direct Messages to Users

To send notifications directly to a specific user, provide their email address:

user@yourcompany.com
  • Use the email address associated with the user's Microsoft 365 account
  • The user will receive a direct message from the RAD Security bot
  • No additional setup required - DMs work once the integration is configured
  • The user must be in the same Microsoft 365 tenant

Example targets:

  • "john.doe@company.com"
  • "security-team@company.com"
  • "oncall@company.com"

What Notifications Are Sent


Use Cases

Workflow Monitoring Receive real-time updates when security workflows complete, keeping your team informed of automated actions.

Incident Response Get immediate alerts in dedicated incident response channels when critical security events are detected.

Team Collaboration Share security findings and workflow results with relevant teams in their existing Teams channels.

On-Call Notifications Send direct messages to on-call engineers for time-sensitive security issues requiring immediate action.


Troubleshooting


Security Best Practices

Secure Credential Storage Store the service account credentials in your organization's password manager or secrets vault. Multiple administrators should not share credentials directly.

Channel Access Control Only send sensitive security notifications to private channels with restricted membership to prevent information disclosure.

Service Account Monitoring Monitor the service account for unusual activity and treat it as a privileged account in your security policies.

Least Privilege The service account only has the minimum required permissions to send messages and read basic user/team information.

Regular Access Reviews Periodically review which Teams channels receive RAD Security notifications and adjust as team membership changes.

Message Content Configure workflow notifications to avoid including sensitive data like credentials or PII in Teams messages.


Next Steps