Microsoft Teams Integration with DefectDojo
Microsoft Teams Integration with DefectDojo
Microsoft Teams is Microsoft's chat and collaboration app, part of Microsoft 365, where work is organized into teams, channels, and chats. External systems post into a channel through incoming webhooks, which Microsoft now provides through Workflows built on Power Automate after retiring the older Office 365 connector webhooks. DefectDojo uses one of those workflow URLs to post messages. The integration is one-way: DefectDojo sends to Teams and does not read replies.
Microsoft Teams Integration with DefectDojo
Our organization runs on Microsoft 365, so the security channel in Teams is where people actually look. We pointed DefectDojo's system notifications at that channel, which gives the AppSec team a running record of scans added, Engagements created, and other events without anyone opening DefectDojo. In DefectDojo Pro we added Messaging Connector alerts on top, so a team's own channel gets a card only when an import brings in new High or Critical findings for its Assets. The setup needs no app registration and no tenant admin consent. Someone with rights to the channel creates a workflow and pastes its URL into DefectDojo.
Why Microsoft Teams Matters
Security events that wait in an inbox wait too long, and Teams is where many companies coordinate day-to-day work.
- A post in the channel the team already watches gets seen faster than a notification email.
- Everyone in the channel sees the same event at the same time, which helps when several people share triage duty.
- Power Automate workflows let the owner of a channel set up the webhook without involving a Microsoft 365 administrator.
- A channel that receives every event from a busy instance turns into noise. What you choose to send decides whether the channel stays useful.
Advantages of This Integration
What we gained by sending DefectDojo events to Teams:
- System notifications in both editions. Community Edition and DefectDojo Pro can post system-wide notifications to a Teams channel, and a superuser chooses which notification types go there.
- No app to register. The connection is a Power Automate workflow URL. There is no bot, app manifest, or tenant consent step.
- Rule-based alerts in DefectDojo Pro. Messaging Connectors route alerts through Triage Engine rules, so a card can be limited by severity, scope, tags, status, or any other rule condition.
- One card per import. Imports are batched, so a rule on newly created Findings posts one card summarizing the batch rather than one per Finding, unless you switch to per-Finding messages.
- Simulate first. Pro alerts can run in Simulate mode, which records what would have been sent without posting anything.
- Connector health in the channel. In DefectDojo Pro, the Connector Health Warning notification can be delivered to Teams, so a failing Upstream Connector is noticed when it breaks.
- Failure handling. If the workflow is deleted, DefectDojo stops sending to that destination after a few consecutive credential failures and reports which destination was disabled.
How This Integration Works
There are two ways to post DefectDojo messages to Teams. Both start with a Power Automate workflow in the target channel.
Option 1: System notifications (Community Edition and DefectDojo Pro). You need Superuser access.
- Create an incoming webhook with Workflows, following Microsoft's guide for creating incoming webhooks with Workflows for Microsoft Teams. The webhook can target a channel or a specific chat. Keep the
logic.azure.comURL the workflow returns. - In DefectDojo, open System Settings (Configuration > System Settings in the Classic UI, or Settings > System > System Settings in the Pro UI).
- Check Enable Microsoft Teams notifications. A hidden field labeled Msteams url appears. Paste the workflow URL there and save.
- Select which events go to Teams on the System Notifications page.
Option 2: Messaging Connectors (DefectDojo Pro, beta). Enable Messaging Connectors on the Feature Flags page, along with Triage Engine, which routes the alerts.
- In Teams, open the channel, select the ... menu next to its name, then Workflows. Choose the Post to a channel when a webhook request is received template, confirm the team and channel, and select Add workflow. Copy the URL it gives you.
- In DefectDojo, open Connect > Downstream, find Microsoft Teams in the Messaging section, and select Add Configuration. Enter a Location (your Teams or Microsoft 365 URL, used for display and links only), an Instance Label naming the channel, and the Workflow URL.
- Save. DefectDojo checks that the URL uses
https://and a Microsoft workflow host, but does not post to it. Use Send test message when you are ready to confirm it works. - Create an alert from Messaging Alerts: choose New findings from an import, the Teams connection, an optional channel label, a severity floor, and Simulate or Live mode. For anything more specific, build a Triage Engine rule with a Send a Microsoft Teams Message node.
One connection reaches one channel, because the workflow URL decides where messages go. A second channel needs a second connection.
Data Granularity: What Gets Sent
| What | System notifications | Messaging Connectors (Pro) |
|---|---|---|
| Triggering events | Selected system notification types, such as scans added, upcoming Engagements, SLA expiry | Rule triggers; the alerts page offers new findings from an import |
| Destination | One channel or chat, set by the Msteams url | One channel per connection, set by the workflow URL |
| Filtering | Choice of notification types only; no RBAC filtering | Severity, scope, tags, status, and other rule conditions |
| Message format | DefectDojo's built-in notification text | A card in DefectDojo's built-in wording; batch digest lists 10 Findings by default |
| Volume control | Per notification type | One card per batch by default; per-Finding sending capped at 1,000 per run by default |
| Personal messages | Not supported for Teams | Not supported |
| Direction | One-way | One-way, no buttons, threads, or message edits |
Because the Teams channel is not tied to a DefectDojo user, system notifications sent there are not filtered by Organization, Asset, or Engagement. Everyone who can read the channel sees every selected event.
Use Cases
An AppSec activity feed: System notifications for scans added and Engagements created post to a private Teams channel for the security team, giving them a log of activity across the instance.
Team-specific alerts in DefectDojo Pro: Each product team has its own channel and its own Teams connection. A Messaging Connector rule scoped to that team's Assets posts a card only when an import brings in new High or Critical findings.
Watching connector health: The Connector Health Warning notification goes to the platform team's channel, so an expired scanner credential is reported the first time a sync fails.
Trying a rule safely: A new alert runs in Simulate mode for a week. The team reviews the recorded deliveries, adjusts the severity floor, then switches the alert to Live.
Operational Tips
- Treat the workflow URL like a password. Anyone who has it can post to that channel.
- Keep the system notification channel private. It receives every selected system notification for every Organization, with no RBAC filtering.
- Teams cannot receive personal notifications, and it cannot be chosen for per-Asset notifications. Use email or Slack for those, or a Pro Messaging Connector rule scoped to specific Assets.
- Do not point a Messaging Connector alert at the channel that system notifications already use, or that channel receives both messages.
- Older Triage Engine Teams nodes no longer fall back to the System Settings webhook. Open each such rule, choose a connection and destination, and save it.
- If a workflow is deleted or recreated, paste the new URL into the connection and send a test message. A successful test re-enables a destination that was disabled for credential failures.