Microsoft Sentinel
Cloud and workloads

Collaborate In Microsoft Teams

In brief

The page metadata was updated, Microsoft Sentinel role names were expanded in links, and screenshot descriptions were made more specific.

What Defender admins need to know

Administrators can more easily identify applicable roles and follow the documented Teams collaboration steps.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Use an incident team to investigate

  1. At the bottom of the incident pane that appears on the right, select Actions > Create team (Preview).

    Screenshot of the incident page with the option to create a Microsoft Teams team.

    The Incident team pane opens on the right. Define the following settings for your incident team:

  1. When you're done adding users and groups, select Create team to create your incident team.

    The incident pane refreshes, with a link to your new incident team under the Team name title.

    Screenshot of an incident showing the added link to the related Microsoft Teams team.

  2. Select your Teams integration link to switch into Microsoft Teams, where all of the data about your incident is listed on the Incident page tab.

    Screenshot of incident details and conversation thread available in Microsoft Teams.

Continue the conversation about the investigation in Teams for as long as needed. You have the full incident details directly in Microsoft Teams.