Receive updates in Microsoft Teams
:::info Learn how to set up an integration between Cobalt and Microsoft Teams. The availability of this feature depends on your PTaaS tier.
:::
Integrate with Microsoft Teams to seamlessly collaborate with Cobalt pentesters and other pentest team members directly from Teams.
:::info Note: If you have an EU account, install the "Cobalt Offensive Security EU" app instead
:::
Please be aware of the following considerations when using this integration. We are working to improve the integration and address these limitations.
Connect your Microsoft Teams workspace to your Cobalt Organization in order to sync Cobalt pentests chat with Teams channels, allowing your team to collaborate on a test directly from your Teams instance.
The Cobalt Offensive Security app requires specific Microsoft Graph API permissions to function properly. These are not configured in the Teams app manifest, but must be granted by your Teams administrator through the Azure portal:
Navigate to: Azure Portal → App registrations → Cobalt Offensive Security → API permissions → Add a permission → Microsoft Graph → Application permissions
Add the following Microsoft Graph Application Permissions:
After adding these permissions, an administrator must click "Grant admin consent" to activate them.
Security Note: The Cobalt Offensive Security app only accesses Teams channels where it is explicitly added. While ChannelMessage.Read.All and file permissions have organization-wide scope at the API level, the app's functionality is limited to channels where it's installed and only processes messages directed to the bot. Chat.Read.WhereInstalled uses Resource Specific Consent (RSC) to restrict access exclusively to chats where the app is present.
As an administrator for your Microsoft Teams instance, you can add the Cobalt Offensive Security app to your environment by:
To remove the Cobalt Offensive Security app from your Microsoft Teams instance:
Here’s what to expect once you’ve removed the Cobalt Offensive Security app:
Once you’ve installed the Cobalt Offensive Security app in your Microsoft Teams instance, you can connect a Teams channel to a pentest, so your teams and pentesters can seamlessly collaborate directly from the Teams channel or through the Cobalt platform.
To communicate with the Cobalt pentest team through Microsoft Teams, you must connect a Teams channel to a specific Cobalt pentest. The person who sets up the Teams channel connection must have a Cobalt account which has access to the Cobalt pentest.
Once you’ve connected your Microsoft Teams instance, you can view all pentests connected to Teams channels.
You may also disconnect directly from Teams, by going to the desired channel, and using the bot command “@Cobalt Offensive Security disconnect”.
Once a Teams channel has been connected to a Cobalt pentest, you can send messages to the pentest chat directly from Teams.
You can also use the bot command “@Cobalt Offensive Security chat” then type your message. Once sent, the message will appear in the Cobalt Chat for the associated pentest, and will be syndicated to your Teams channel for visibility to the other channel members.
You can also use the bot command “@Cobalt Offensive Security help” to view a list of the available commands and what they are used for.
If a Teams channel has been connected to a Cobalt pentest, during the course of the pentest, updates posted by pentesters will be sent as messages to the connected channel(s).
If you have issues or need support, contact support@cobalt.io.
Q: Do all messages in my Teams channel get synced to the Cobalt pentest?
A: No. Only messages or replies sent using the Cobalt Offensive Security bot will be synced to Cobalt. Any other communication within the channel, using the standard Teams messaging features, will remain private to that channel, and are not visible to Cobalt.
Q: Do I need to provide pentesters and Cobalt staff with access to Microsoft Teams?
A: No. Pentesters and Cobalt staff can see and respond to messages posted via the Microsoft Teams integration using the Pentest Chat within the Cobalt platform.
Q: Do all members of my Teams channel need to have access to the Cobalt platform?
A: No. You can invite anybody you wish from your organization to the Teams channel, even those without a Cobalt account. All members of the channel will be able to post, respond and view communications from the associated pentest.
Q: Can Cobalt access data in my Microsoft Teams instance when I use this integration?
A: No. Cobalt has no visibility or access to your Teams system, except for messages posted using the Cobalt Offensive Security bot.
Q: Where do messages sent from Teams appear in the Cobalt platform?
A: Messages are synchronized to the Cobalt Chat for the pentest or engagement that they are associated with.
Q: Who can see the messages sent using the integration?
A: Messages sent to Cobalt from the Teams bot will be visible to Cobalt users who have been granted access to the associated pentest (including your Cobalt Staff members, Pentesters, and any team members that you have invited to the pentest in the Cobalt platform). After you’ve connected a Teams channel to a pentest, messages posted using the Cobalt Offensive Security bot will be syndicated to the connected pentest’s InApp chat on the Cobalt platform, and vice versa. Users with access to the Teams channel will be able to see the messages originating from the Cobalt InApp chat on the connected pentest.
Q: How do I control who sees the Cobalt discussions in Teams?
A: Anybody you add to a Teams channel that is connected to a Cobalt pentest will be able to see the discussion. Cobalt has no visibility or control over the membership of your Teams channels. As such, it is the customer’s responsibility to manage access in Teams.
Q: Can I subscribe to multiple Cobalt pentests from the same Teams channel?
A: No, a Teams channel can only be connected to one Cobalt pentest. To connect another pentest, you may remove the original connection, then connect the new test. Otherwise, you must create a new channel.
Q: Can I discuss a specific Cobalt finding using the integration?
A: Currently the integration supports Cobalt’s Pentest Chat only, not Finding chat. You may reference a finding ID when sending a message, but the message will remain in the Pentest Chat, and will not be directly associated to the specific finding.
Q: Does the integration support threading?
A: No, threaded messaging is not currently supported, but will be in a future release.
Q: Does the integration support file attachments?
A: Yes. When you send a message to the Cobalt bot in Teams, attachments are included with the message in Cobalt's in-app chat. For messages sent from in-app chat, attachments are displayed in the Teams channel as links that users can click to securely download the files.
Q: Does the integration support reactions?
A: No, emoji reactions are not currently supported, but will be in a future release.