The add-on uses Microsoft Entra ID app-only authentication, stores credentials in Splunk password storage, and supports common alert fields such as To, CC, Subject, and Message. Alert messages can include Splunk tokens such as $name$, $results_link$, and result fields.