Automated Microsoft 365 Alert Summarization and Slack Notification - n8n Workflow

Use this powerful n8n workflow to monitor Microsoft 365 service health emails, leverage OpenAI for concise summarization, and instantly push actionable alerts to Slack. Start automating IT notifications with this n8n template.

Workflow Preview

Ready to automate?

Download this n8n workflow template and start using it instantly.

Who is this best for?


  • IT System Administrators and DevOps teams needing immediate, non-cryptic M365 outage notifications.

  • Businesses looking to reduce email clutter and alert fatigue.

  • Users seeking pre-built n8n templates for complex AI-driven communication.

  • Anyone utilizing n8n for critical infrastructure monitoring and internal alerting.

Overview

Managing Microsoft 365 service alerts often means sifting through lengthy, technically dense emails from Microsoft. This process is time-consuming and prone to missing critical information, leading to slow response times during outages. This specific n8n workflow template solves this problem by automating the entire pipeline. It acts as an intelligent intermediary, transforming raw email data into concise, immediate, and actionable summaries. By using a specialized n8n node for OpenAI integration, the workflow ensures that business stakeholders receive updates tailored for urgency and clarity directly in a designated Slack channel. Furthermore, this n8n workflow manages cleanup, deleting the original email to keep your inbox tidy. Leveraging this n8n automation means your team can focus on remediation rather than interpretation.

How it Works

The entire process is initiated by an n8n trigger, specifically the Microsoft Outlook Trigger node.


  1. Trigger and Filtering: The n8n trigger is set to constantly check an Outlook mailbox, specifically filtering for new emails sent from [email protected] (Microsoft Service Health).

  2. Data Extraction (Code Node): Once a relevant email is found, the custom n8n node, 'Extract M365 Incident text & link', uses JavaScript and the Cheerio library to parse the HTML body of the email. It strips out unnecessary formatting and boilerplate, extracting the clean plain text of the alert and the direct incident link.

  3. AI Summarization: The 'Summarize service alert' n8n node (utilizing OpenAI/LangChain) receives the extracted text. It uses a detailed system prompt to summarize the M365 alert, incorporating an appropriate status emoji and determining the likely impact on users in key regions (US/Australia), finally outputting a strict JSON payload.

  4. Slack Block Generation (Code Node): A second custom n8n node, 'Generate Slack Block', takes the structured summary JSON from the AI step and converts it into the necessary Slack Block Kit JSON format. This includes the summarized text and a button linking directly to the M365 Service Health page.

  5. Notification: The Slack n8n node, 'Post outage to Slack', sends the formatted, actionable notification to the specified Slack channel.

  6. Cleanup: Finally, the Microsoft Outlook n8n node, 'Clear email alert from mailbox', uses the original email ID from the n8n trigger to delete the processed email, completing the seamless n8n workflow loop.

Installation Guide

To deploy this powerful n8n workflow, follow these steps:


  1. Import the n8n Workflow: Copy the provided JSON code and paste it directly into your n8n instance using the 'New' -> 'Import from JSON' option.

  2. Configure Credentials:

Microsoft Outlook: You must set up Microsoft Outlook credentials for the 'Check for 365 Service Alert' n8n trigger and the 'Clear email alert from mailbox' n8n node. This needs mailbox access (usually via OAuth 2.0).
OpenAI: Set up your OpenAI credentials for the 'Summarize service alert' n8n node, ensuring you have access to a reliable model like gpt-4o-mini.
* Slack: Configure your Slack API credentials (Bot Token) on the 'Post outage to Slack' n8n node. You will also need to specify the target channelId where alerts should be posted.

  1. Review Code Nodes: While the custom code is pre-written for this n8n template, it is essential to ensure the HTML selectors within the 'Extract M365 Incident text & link' n8n node are still valid, should Microsoft change their alert email format.

  2. Activate: Save the n8n workflow and toggle the activation switch to enable the n8n trigger.

Node Details

Check for 365 Service Alert (Microsoft Outlook Trigger): This critical n8n trigger continuously monitors the specified mailbox. Function: Initiates the n8n workflow upon receiving an email from the sender [email protected].
Extract M365 Incident text & link (Code Node): Function: Parses the complex HTML body of the Microsoft email using Cheerio to extract clean text (extractedText) and the incident hyperlink (incidentLink), preparing the data for the next n8n node.
Summarize service alert (OpenAI n8n Node): Function: Sends the extracted raw alert text to GPT-4o-mini with specific instructions (system prompt) to generate a concise, Slack-ready summary in a strict JSON format.
Generate Slack Block (Code Node): Function: Converts the JSON output from the AI into a valid Slack Block Kit message structure, including a button for quick access to the incident details. This transformation is key to the overall n8n workflow design.
Post outage to Slack (Slack n8n Node): Function: Sends the fully structured Block Kit payload to the designated Slack channel, delivering the final summarized alert.
Clear email alert from mailbox (Microsoft Outlook n8n Node): Function: Performs a cleanup action, using the message ID from the original n8n trigger to permanently delete the processed M365 alert email from the inbox.

Related n8n Workflows

Free

Nodes: 5 Nodes
Updated: December 26 2025
View all
Created by
Luke
Luke

Featured*