Customize email notifications for Microsoft Sentinel incidents by severity and workspace. Configure alerts for your SOC team with per-customer granularity.
ContraForce provides customizable email notifications for Microsoft Sentinel incidents, allowing you to configure alerts by severity level for each workspace. Keep your team informed about critical security events while filtering out noise.
Module Requirement: Full notification customization is available with the XDR + SIEM module. The XDR-only module has limited notification capabilities (Gamebook notifications only).
Defender Module Users: ContraForce does not generate email notifications for Defender for Endpoint incidents. Use Microsoft Defender’s built-in notification settings for Defender alerts. Deploying ContraForce will not interrupt your existing Defender notification configuration.
Continue for all workspaces requiring custom settings
Document your notification configuration for each customer. This helps maintain consistency and simplifies troubleshooting when customers report notification issues.
Gamebook notifications help track automated response actions across your customer base, providing audit trails for compliance and visibility into response activity.
Begin with High severity only, monitor for a week, then gradually enable Medium and Low based on team capacity and incident quality.
Match notifications to SLAs
Configure severity settings to match your SLA with each customer. Premium customers might get all severities; standard customers might only get High and Medium.
Use distribution groups for team visibility
Individual email notifications risk being missed. Distribution groups ensure the entire team has visibility into alerts.
Integrate with ticketing for tracking
Route notifications to your ITSM for automatic ticket creation, SLA tracking, and audit trails.
Allowlist the sender address
Add noreply@notifications.contraforce.com to email allowlists for your organization and your customers.
Review and tune periodically
Monthly review notification settings. If a severity level generates too much noise, consider disabling it while you tune detection rules.
All notifications are sent from noreply@notifications.contraforce.com
Can I get notifications for Defender for Endpoint incidents?
No, ContraForce does not send notifications for Defender for Endpoint incidents. Use Microsoft Defender’s built-in notification settings. ContraForce notifications are for Sentinel incidents (XDR + SIEM module) and Gamebook activity.
How do I add a distribution group?
Contact support@contraforce.com with the email address. The ContraForce Engineering team will configure it for your account.
Can I customize the email template?
Email templates are standardized and cannot be customized. For custom formatting, route emails to a ticketing system that can transform them.
Is there a notification delay?
Notifications are sent in near real-time when Sentinel incidents are processed. Typical delay is under 5 minutes from incident creation.
Can different users get different notifications?
Currently, notifications are configured at the workspace level, not per-user. All recipients for a workspace receive the same notifications based on severity settings.
Can I get SMS or push notifications?
ContraForce currently supports email only. For SMS or push, route email notifications to PagerDuty, Opsgenie, or similar services.