Skip to main content

Microsoft Teams

The Microsoft Teams channel puts your agent in Teams as a bot your employees message directly — they chat with it in a one-to-one conversation and it replies in-thread, with streaming where Teams supports it.
Looking for the agent to use Teams as a tool (message a teammate, spin up a meeting) rather than host the conversation? That’s the separate Microsoft Teams integration.
The bot works in one-to-one personal chat — each employee messages the agent directly. It doesn’t join team channels or group chats. People are recognized on their first message — Cobalt knows who is talking from their Microsoft Entra identity, with nothing to set up beyond the directory permission your admin grants during setup. Guests and external users are told the agent is not available to them.

Before you start

You’ll need a Microsoft Azure / Entra admin to register an Azure Bot and to grant it one directory permission, and a Teams admin (or permission to upload custom apps) to install the app in your organization. Cobalt generates the Teams app package for you and walks you through each step in an install wizard, so there’s little to configure by hand.

Install it

The channel’s install wizard is a five-step flow. Each step shows its own status, and you finish once the credentials verify and a test message round-trips.
1

Brand the bot

Set the bot’s display name and upload its two icons (a full-color icon and an outline icon Teams uses in different places). Defaults are fine to start.
2

Create the Azure Bot

In the Azure portal, create an Azure Bot — for “Type of App” choose Single Tenant. Cobalt shows you the values to copy in — the bot handle, the app type, and the per-channel messaging endpoint URL — with a deep link to the right Azure screen. Set the messaging endpoint to the URL Cobalt shows, then under Channels enable Microsoft Teams.
Do not choose User-Assigned Managed Identity. Managed-identity bots have no client secret, so Cobalt — which authenticates from outside your Azure tenant — can never connect to one. If you already created a managed-identity bot, delete it and create a Single Tenant bot instead.
Azure no longer offers Multi-tenant bot creation (removed after July 2025). Existing Multi-tenant installs keep working unchanged — Cobalt detects your bot’s app type automatically when it verifies the credentials.
3

Create a client secret

On the bot’s Configuration page, note the Application (client) ID and Directory (tenant) ID (the tenant ID appears as App Tenant ID, right below the app ID) and paste them into Cobalt. Then click Manage beside Microsoft App ID to open the app registration behind the bot, go to Certificates & secrets, and add a client secret. Azure shows the value once — paste it into Cobalt before you click away. Cobalt needs all three before it can check the directory permission in the next step.
4

Let the agent read your directory

Still in the app registration behind the bot, under API permissions, add Microsoft Graph → Application permissions → User.Read.All, then click Grant admin consent. Back in Cobalt, press Check permission — Cobalt asks Microsoft directly, and the wizard continues only once Microsoft confirms the grant.Teams tells Cobalt which account sent a message, not who it belongs to. This permission lets the agent read a person’s name and email — only for people who message it, and never writing anything back. See Directory access for Teams for what is read, the four causes of a failed check, and a copyable request for when someone else has to grant the consent.
There is no “continue anyway”. If your organization routes consent through an approval workflow, or blocks it by policy, see Consent policies & workflows. Your setup progress is saved while you wait.
5

Verify the credentials

With the app ID, the secret, and the tenant ID in place, run Verify — Cobalt makes a live call to confirm the credentials work.
6

Install in Teams and test

Download the Teams app package (.zip) Cobalt builds for this agent — it contains your branding, the manifest with your verified App ID, and the messaging endpoint. Then choose how to distribute the app — upload to your org’s app catalog (recommended; available to everyone) or sideload the package directly (works only if your org allows custom app uploads). Install it, then send a test direct message to confirm the bot responds.
The download becomes available after the credentials verify, so every package you download already has your real Microsoft App ID baked in.

Settings

On the channel’s settings you can configure:
  • Bot display name and icons — how the bot appears in Teams.
  • AI disclaimer — the text (up to 200 characters) and how often it shows (off, once per conversation, or always).
  • Directory access — the User.Read.All grant as Microsoft last reported it, when it was last checked, and how many people couldn’t be identified if it is missing. Grant directory access opens the right Azure page; Check again asks Microsoft afresh. Channels installed before this permission was part of setup keep working and are remediated here.

Keep the connection healthy

  • Client secrets expire. Azure client secrets have an expiry date; Cobalt shows a countdown and reminds you before one lapses. Rotate the secret from the channel — create a new secret in Azure and paste it in — before it expires, so the bot keeps responding.
  • Directory access can be revoked. If an administrator removes the User.Read.All consent, the next Teams message flips the channel’s Directory access section to Not granted so you see it, rather than conversations silently arriving from strangers.
  • Activity. The channel’s activity view shows recent inbound traffic, so you can confirm messages are reaching the agent.
  • Disconnect removes the credentials and takes the channel offline.

Teams as an integration

Connecting Teams as a channel (so employees chat with the agent there) is separate from connecting Teams as an integration (so the agent can search, message, and act in Teams on a user’s behalf). You can use either or both.