← Help

Integrations Guide

Connect Microsoft Entra, and set up Slack, Microsoft Teams, or a custom webhook for scan alerts.

What this does

Microsoft Entra ID stores your app-registration credentials, verifies them against Microsoft Graph, and on Refresh pulls the directory (users, MFA registered, admin/guest counts, and whether Conditional Access exists). That inventory is shown on Integrations and as a read-only snapshot on mapped GRC identity controls. Manual Evidence / notes are never written or overwritten.

Webhook alerts are a Pro feature. Every webhook you add gets a message any time a scan discovers a new finding at medium severity or above (medium, high, or critical). Findings at low or info severity, like a routine subdomain-discovery result, don't trigger a notification, to keep the channel focused on things worth acting on.

Microsoft Entra ID setup

  1. Open the Azure portal and go to Microsoft Entra ID → App registrations → New registration.
  2. Name the app (e.g. CyberEnforced), choose Accounts in this organizational directory only, and register it. You do not need a redirect URI.
  3. On the app's Overview page, copy the Directory (tenant) ID and the Application (client) ID.
  4. Open Certificates & secrets, click New client secret, set an expiry, and copy the Value immediately. Azure only shows it once. The Secret ID is not the secret.
  5. Open API permissions → Add a permission → Microsoft Graph → Application permissions, add Organization.Read.All, User.Read.All, Reports.Read.All, and Policy.Read.All, then click Grant admin consent for your tenant. If the app is already connected, add the new permissions and grant admin consent again before Refresh will succeed.
  6. On CyberEnforced's Integrations page, paste the three values and click Connect Entra. CyberEnforced requests a token, reads the tenant name, then pulls the directory. Use Refresh later to replace the inventory.

If Microsoft accepts the secret but Graph returns a permission error, the usual cause is a missing admin consent. Refresh still saves the user list if only the MFA report or Conditional Access call is denied; those fields stay unknown until the matching permission is consented. GRC notes stay manual.

Slack setup

  1. Go to api.slack.com/apps and create a new app (or pick an existing one) for your workspace.
  2. Open Incoming Webhooks in the app's settings and switch it on.
  3. Click Add New Webhook to Workspace, choose the channel that should receive alerts, and allow it.
  4. Copy the Webhook URL Slack gives you (it looks like https://hooks.slack.com/services/...).
  5. On CyberEnforced's Integrations page (under your organization's sidebar), choose Slack, give it a label (e.g. the channel name), and paste the URL in.

Microsoft Teams setup

  1. Open the Teams channel that should receive alerts, then choose Connectors (or Workflows on newer Teams, using the "When a webhook request is received" template) from the channel's menu.
  2. Configure an Incoming Webhook, give it a name, and create it.
  3. Copy the webhook URL it gives you.
  4. On CyberEnforced's Integrations page, choose Microsoft Teams, give it a label, and paste the URL in.

Microsoft has been migrating Teams from classic Connectors to Workflows-based webhooks on some tenants. If Connectors isn't available in your channel menu, use the Workflows option instead; the resulting URL works the same way here.

Generic webhook

For anything else (Discord, Zapier, a custom internal system), add a Generic webhook integration with any HTTPS (or HTTP, for an internal-only endpoint) URL that accepts a POST body. CyberEnforced sends this JSON shape:

{
  "event": "finding.created",
  "organization_id": "…",
  "domain": "example.com",
  "finding": {
    "category": "missing_spf",
    "severity": "medium",
    "title": "Missing SPF record",
    "detail": "No SPF TXT record was found…"
  }
}

Testing a connection

After adding a webhook, click Test next to it on the Integrations page. This sends a real sample message immediately, so you can confirm the URL works without waiting for an actual finding. For Entra, Test asks Microsoft for a token again and refreshes the tenant name and status. Refresh pulls users, MFA, and Conditional Access existence and replaces the stored inventory.

Managing integrations

Disable pauses a webhook without deleting it (its URL is kept). Delete removes a webhook permanently. Disconnect removes an Entra connection, its stored secret, and the directory snapshot. Update credentials replaces the tenant ID, client ID, and optionally the client secret, then tests and refreshes the directory. Only organization owners, admins, and security managers can view, add, or manage integrations. Webhook URLs and Entra secrets can be used if they leak, so they're not shown to every member. Any member can still see the read-only Entra snapshot on mapped GRC controls.

Integrations Guide | CyberEnforced