Configure email notifications for security incidents, Gamebook activity, and system alerts. Customize by severity and workspace.
ContraForce keeps your team informed with configurable email notifications. Receive alerts when new incidents are detected, Gamebooks complete, or when issues require attention—all customizable by severity and workspace.
Notification capabilities vary by module. The XDR + SIEM module offers full customization, while the XDR-only module has limited notification options.
Notification features depend on which ContraForce module you’ve deployed:
Feature
Defender Module
XDR + SIEM Module
Sentinel incident notifications
—
✓
Defender for Endpoint incident notifications
—
—
Gamebook completion notifications
✓
✓
Severity-based filtering
—
✓
Per-workspace customization
—
✓
Distribution group support
—
✓
Defender Module Users: ContraForce does not generate email notifications for new Defender for Endpoint incidents. Use Microsoft Defender’s built-in notification settings for Defender alerts. ContraForce notifications are sent only for Gamebook activity.
Deploying ContraForce does not interrupt or override your existing Microsoft Defender notification configuration.
Configure different notification preferences for each customer workspace:
Navigate to Settings > Notifications
Select the Workspace you want to configure
Enable or disable severity levels for that workspace
Save changes
Use per-workspace configuration to match notification settings to each customer’s SLA. High-priority customers might need all severities enabled, while others might only need High alerts.
Begin with High severity notifications enabled for all workspaces. Add Medium and Low severities gradually based on team capacity to avoid alert fatigue.
Use distribution groups for team visibility
Route notifications to a shared mailbox so the entire SOC team has visibility. This prevents missed alerts when individuals are unavailable.
Create email rules for organization
Set up email folder rules to automatically categorize ContraForce notifications by workspace or severity for easier triage.
Integrate with ticketing systems
Route notifications to an email address that creates tickets in your ITSM (ServiceNow, Jira, etc.) for automatic tracking and SLA management.
Review and adjust periodically
Regularly review notification settings. If you’re experiencing alert fatigue, consider disabling lower severity levels or refining detection rules.
Allowlist the sender address
Add noreply@notifications.contraforce.com to your email allowlist to prevent notifications from being caught by spam filters.
What email address sends ContraForce notifications?
All notifications are sent from noreply@notifications.contraforce.com
Can I get notifications for Defender for Endpoint incidents?
ContraForce does not send email notifications for Defender for Endpoint incidents directly. Use Microsoft Defender’s built-in notification settings for those alerts. ContraForce sends notifications for Sentinel incidents (XDR + SIEM module) and Gamebook activity (all modules).
How do I add a distribution group?
Contact support@contraforce.com with the email address you want to use. The ContraForce Engineering team will configure it for your account.
Can I customize the email template?
Email templates are standardized and cannot be customized. For custom notification formatting, consider routing emails to a ticketing system that can reformat them.
Is there a notification delay?
Notifications are sent in near real-time when incidents are detected and processed by ContraForce. Typical delay is under 5 minutes.
Can I get SMS or push notifications?
ContraForce currently supports email notifications only. For SMS or push, route email notifications to a service like PagerDuty or Opsgenie.