Explanation (concise): To send a Microsoft Teams message when a suspicious sign-in is detected, create a playbook (Logic App) that posts to Teams ( A ) and associate the playbook so it runs when the corresponding alert/incident is created ( B )-typically via an automation rule or by attaching the playbook to the analytics rule/incident. Entity behavior analytics, workbooks, or Fusion aren't required for sending Teams notifications.