MS Teams
Send BigPanda incidents to an MS Teams channel for team investigation.
Supported Versions | Type | Authentication Type |
|---|---|---|
SaaS Deployments | Webhook | User API Key |
The MS Teams integration allows you to easily share BigPanda incidents in a customized message to a channel within Teams.
The integration shares incidents from BigPanda to Teams via a webhook. When an incident triggers an AutoShare or is manually shared, it is normalized and sent to the Teams API where it triggers an automated workflow.
Biggy
For information about installing Biggy with MS Teams, see the Install Biggy documentation.
Standard AutoShare Rules
The MS Teams integration follows standard AutoShare rules. See the Sharing Rules documentation for more information.
MS Teams Workflow Integration
Microsoft has retired the Office 365 connectors feature from Microsoft Teams, replacing it with Automate Workflows. All new MS Teams integrations should use the MS Teams Workflow instructions to configure sending MS Teams messages from BigPanda incident shares.
All existing MS Teams integrations will be migrated to the new workflow integration before the connectors are fully retired in December 2024. As part of this transition, all AutoShares will need to move to MS Teams Workflows.
Key Features
Incident updates: Updates to ongoing incidents will be sent to your MS Teams channel in real time.
Streamline workflows Invite your team members to the MS Teams channel(s) specifically pertaining to them, clearly designating responsibilities and saving time.
Communication optimization: Team members can collaborate together, capitalizing on a diverse knowledge base of expertise to tackle each issue.
Customizable messages: Configure what data is included in MS Teams messages for each AutoShare rule, selecting from alert tags, incident metadata, and incident tags.
Preview: Sample message content helps you visualize how your teams will see incidents within MS Teams.
Install the Integration
Install the integration by following these steps:
Create an app key
Create an app key in BigPanda.
Integration specific
You'll need a separate app key for each integrated system.

App key configuration in BigPanda
Add the Workflow URL to BigPanda
On the workflow confirmation page in Teams, copy the workflow url and enter it in the Incoming Webhook URL field. You can also retrieve the workflow URL from the workflow editor.
You must create an App Key before configuring the webhook.

After entering the URL, click Configure incoming webhook url.
Add Sharing Channels
The Teams integration leverages webhook URLs to send incident details. To start sending incident details to a specific channel or workflow, add the webhook URL for that workflow during the Add the Workflow URL to BigPanda step in integration installation.
By default, a Teams incident share includes a link to the incident in the BigPanda console, information on the incident status, and the check tag value.
The default tags can be adjusted or additional Incident Data or Primary Alert Tags can be added. Any tags added during integration configuration will be included in all shares for this integration. If a tag does not have a value, it will be sent with an N/A value.
Primary Alert
The Primary Alert for an incident is the oldest most severe alert in the Incident. If a more severe alert comes in it will be the new primary alert.
Sharing to MS Teams
Once configured, the Teams workflow can be selected as a destination for AutoShare and Manual sharing of incidents.
To send incident information to a Teams channel:
1. Select the Teams integration name from the Share via field when configuring an AutoShare rule, or Sharing an incident.
2. Select the Teams workflow from the available options. All workflows added to this integration will appear in the list.
Adjust Sharing Rules
All BigPanda shares include a link to the triggering incident in BigPanda.
Some mandatory incident and primary alert data fields may have been configured during integration configuration. These fields will be included by default in all autoshare rules or manual shares for that integration.
Additional customization can be added when configuring an AutoShare rule or as part of a Manual share.
Customize the Message
![]() |
Each AutoShare rule and manual share can be customized for the destination channel. The Message Preview pane shows a sample built from a real incident in the sharing environment, so you can see the result before you save.
Option | What it does |
|---|---|
Link type | Chooses which link recipients receive. The BigPanda app link opens the full incident and requires a login. The preview page link does not require a login, which suits channels that include people without BigPanda accounts. |
Incident Data | Adds incident properties and incident tags to the message. |
Primary Alert Data | Adds tag values from the primary alert, which is the oldest and most severe alert correlated into the incident. Use this when responders need to see the specific host, service, or check that triggered the incident rather than the incident summary alone. |
Additional Message | Adds your own text to the share. The text also appears in the incident's activity feed. |
AutoShare Delay | Changes how long BigPanda waits before the first share. Incidents resolved within the delay period are not shared at all. |
Mandatory fields cannot be removed per share
Fields marked as mandatory during integration configuration are included in every share for that integration, and cannot be removed from an individual AutoShare rule. To change them, update the Teams integration settings.
Troubleshooting
Symptom | Likely Cause | Solution |
|---|---|---|
The Primary Alert Data list shows no results when configuring an AutoShare rule. | The tag list did not load in time. This is more likely in organizations with a large number of alert tags. | Close and reopen the dropdown. If it still does not load, contact BigPanda Support and include your organization name and the time you tried. |
Test AutoShare returns a red error message. | The destination channel webhook is misconfigured. | Review the Teams integration configuration for missing or mismatched values, then test again. |
Uninstall the Integration
Deleting an integration requires that you remove the integration in both the integrated system and BigPanda. We recommend that you first uninstall the integration on the integrated system to prevent traffic from being sent and rejected by BigPanda, since the app_key will not exist once you delete the integration in BigPanda.
Caution during replacement
When replacing an existing integration with a new tool or system, we recommend configuring the new integration first to ensure no data is lost.
Stop sending data from BigPanda
In BigPanda, disable any settings that send data to the integrated system. This includes modifying or removing AutoShare rules or Environments that are tied to the integration.
Delete the integration in BigPanda
Take the following steps to delete the integration from BigPanda:
In BigPanda, navigate to the Integrations tab and select the desired integration from the list.
In the integration details on the right of the page, click the trash icon, then confirm you want to delete the integration. The integration will be removed immediately.
️Data removal
This procedure does not remove any data from BigPanda or the integrated system. As needed, remove data from each system before deleting the integration.
Caution during replacement
When replacing an existing integration with a new tool or system, we recommend configuring the new integration first to ensure no data is lost.
Stop sending data from BigPanda
In BigPanda, disable any settings that send data to the integrated system. This includes modifying or removing AutoShare rules or Environments that are tied to the integration.
Delete the integration in BigPanda
Take the following steps to delete the integration from BigPanda:
In BigPanda, navigate to the Integrations tab and select the desired integration from the list.
In the integration details on the right of the page, click the trash icon, then confirm you want to delete the integration. The integration will be removed immediately.
