Skip to main content
Share / Export

Prepare a Microsoft 365 account for TEDI

This article is for the client's Microsoft 365 or Microsoft Entra admin. Every step happens in Microsoft portals. When you finish, hand the values in Step 7 to the TEDI operator, who completes Configure Microsoft 365 in TEDI.

What you'll set up and hand off​

  • A licensed work or school user that TEDI signs in as (for example tedi@yourcompany.com).
  • A Team and channel that user belongs to.
  • An Entra app registration configured as a public client, with no client secret.
  • 13 delegated Microsoft Graph permissions on that app, with tenant-wide admin consent.
  • A handoff table for the TEDI operator.

Who does this and needed roles​

  • User and license: User Administrator and License Administrator, or equivalent.
  • App registration and admin consent: Cloud Application Administrator. Microsoft names it as the least-privileged role for granting tenant-wide admin consent to delegated Microsoft Graph permissions ("sign in as at least a Cloud Application Administrator"), and it can also register apps. Privileged Role Administrator or Global Administrator is only needed for Graph application permissions, which TEDI does not use. Source: Grant tenant-wide admin consent to an application.

What TEDI needs from Microsoft 365​

TEDI signs in as one user through Microsoft Graph with a device code and uses that user's Teams membership and Exchange Online mailbox. No special SKU is needed.

  • A work or school account in your tenant. Personal accounts (@outlook.com, @hotmail.com, @live.com) are not supported.
  • One license seat that includes both Microsoft Teams and Exchange Online. Microsoft 365 Business Basic (with Teams) is the usual lowest-cost choice. Business Standard, Business Premium, E3, and E5 (with Teams) also work. E5 is not required: TEDI uses standard delegated Graph channel APIs, not the metered Teams export APIs. A spare seat is fine.
  • Membership in the Team TEDI will watch. A license does not add the user to a Team.

Poor fits: Apps-only licenses (no mailbox or Teams), a shared mailbox (not supported; TEDI always reads and sends as the signed-in user's own mailbox), a guest (B2B) user, or a staff member's everyday mailbox (TEDI's replies collide with that person's mail).

Step 1: Choose the identity​

  1. Pick a dedicated UPN and display name, for example tedi@yourcompany.com and TEDI. If the operator plans to give the assistant a personal name in TEDI (the TEDI username, set in TEDI under Settings > Assistant, default TEDI), you can match it, for example casey@yourcompany.com and Casey.
  2. Decide which Team and channel the account will join.

Step 2: Assign a license and create the user​

If a dedicated user with Teams and a mailbox already exists, confirm its license and go to Step 3.

  1. Open the Microsoft 365 admin center.
  2. Go to Billing > Licenses. Confirm a product with Exchange Online and Microsoft Teams has an unassigned seat. If not, buy one or free a seat.
  3. Go to Users > Active users > Add a user. In the Simplified view, select Add user instead.
  4. Enter the Display name and Username from Step 1. TEDI's channel posts show this display name.
  5. Set a password and record it securely.
  6. Under Assign product licenses, assign the Teams and Exchange Online license. Leave optional add-ons off unless your policy requires them.
  7. Finish the wizard and wait a few minutes for the mailbox and Teams to provision.

Microsoft 365 admin center Licenses page showing available Business Basic seats

Add a user wizard with display name tedi and license assignment including Teams

Expected outcome: The user appears under Active users with a licensed mailbox.

Step 3: Verify mailbox, Teams, MFA, and the Team and channel​

TEDI does not install a Teams app or create a Team or channel. Teams meetings started with Meet Now are joined from a Meet Now already posted in the watched channel; TEDI never creates them.

  1. Sign in as the TEDI user at outlook.office.com. Confirm the Inbox opens.
  2. If your tenant enforces MFA, complete enrollment for this account now so the operator's first sign-in does not stall.
  3. Sign in to teams.microsoft.com as the same user.
  4. Open or create the Team TEDI will watch, for example TEDI Assistant.
  5. Open or create a standard channel where people will post for TEDI, for example Ask TEDI. Private and shared channels are not verified for TEDI polling and replies.
  6. Confirm the TEDI user is a member of that Team.

Teams showing the dedicated TEDI user as a member of the TEDI Assistant team with the Ask TEDI channel

Expected outcome: The account opens Outlook and sees TEDI Assistant > Ask TEDI. The operator picks them from a list in TEDI, so nobody copies Graph IDs.

Step 4: Register the Entra app as a public client​

TEDI signs in with the device code flow, which requires a public client.

  1. Open the Microsoft Entra admin center.
  2. Go to Entra ID > App registrations > New registration.
  3. Set:
    • Name: for example TEDI Graph.
    • Supported account types: Single tenant only (Microsoft's recommendation for most apps) or Multiple Entra ID tenants, per your policy. Older portal versions label these Accounts in this organizational directory only and Accounts in any organizational directory. Record which one you chose.
    • Redirect URI: if the form shows it, leave it blank.
  4. Select Register.
  5. On Overview, copy the Application (client) ID and Directory (tenant) ID.
  6. Open Authentication and select the Settings tab. Turn on Allow public client flows (the default is Disabled) and save the change.
  7. Do not add anything under Certificates & secrets.

Entra app Overview showing the Application (client) ID and Directory (tenant) ID

Step 5: Add delegated Microsoft Graph permissions​

  1. In the app, open API permissions > Add a permission > Microsoft Graph > Delegated permissions. Do not use Application permissions.
  2. Add all 13 permissions below. TEDI requests all 13 at sign-in and checks every one. The 7 core permissions are required for sign-in to pass. Without an optional group, text inbound still works but that feature does not.
PermissionWhat TEDI uses it forAdmin consent required (per Microsoft)Core or optional (group)
User.ReadSigned-in identityNoCore
Team.ReadBasic.AllList teamsNoCore
Channel.ReadBasic.AllList channelsNoCore
ChannelMessage.Read.AllPoll channel messagesYesCore
ChannelMessage.SendPost channel replies and the start-gate alert threadNoCore
Mail.ReadPoll the inboxNoCore
Mail.SendSend email replies and the start-gate alert emailsNoCore
ChannelMember.Read.AllLook up channel members' email addresses (channel roster emails)YesOptional (proof)
User.ReadBasic.AllResolve the asker's email addressNoOptional (proof)
Calendars.ReadRead meeting details, including calendar events and channel Meet Now join URLsNoOptional (calendar)
Calendars.ReadWriteOutlook calendar sync: push Schedules, Monitors, and Bot due items to a dedicated Outlook calendar named TEDINoOptional (calendar)
Files.Read.AllDownload files shared from SharePoint or OneDrive that are attached to Teams channel messagesNoOptional (files)
Sites.Read.AllDownload files attached to Teams channel messages when they are stored in SharePointNoOptional (files)

Consent values are from the delegated column of the Microsoft Graph permissions reference.

Entra API permissions list showing the 13 delegated Microsoft Graph permissions with Granted status

Admin consent is always required for TEDI, because ChannelMessage.Read.All and ChannelMember.Read.All need it.

  1. On API permissions, select Grant admin consent and confirm.
  2. Confirm every row shows Granted in the Status column.

If you add or change a permission later, grant consent again and tell the operator so they can refresh permissions in TEDI.

Step 7: Hand off to the TEDI operator​

Send these values through a secure channel. Send the password separately from the UPN.

ItemValue
TEDI user UPNFor example tedi@yourcompany.com
First sign-in and MFAConfirmation that first sign-in and MFA enrollment are done, and how the operator gets the password
Client IDApplication (client) ID from Step 4
Tenant ID and supported account typeDirectory (tenant) ID from Step 4, and whether the app is single tenant or multitenant. The TEDI field is optional, and blank uses the organizations authority. A single-tenant app, the usual kind, requires the tenant ID in practice, or sign-in fails with AADSTS50194.
Team and channelFor example TEDI Assistant > Ask TEDI
TEDI usersThe people who should be TEDI super users (the All skills group) and any individual users, so the operator can set up Groups in TEDI

Checklist​

  • Work or school user created with a Teams and Exchange Online license
  • Outlook opens and MFA is enrolled if required
  • User is a member of the Team and channel
  • App registered with Allow public client flows turned on and no client secret
  • All 13 delegated permissions added, admin consent granted, every row Granted
  • Handoff values sent to the TEDI operator

Common mistakes​

  • Public client flows left off. Device code sign-in fails until Allow public client flows is turned on (Authentication, Settings tab).
  • Creating or pasting a client secret. TEDI has no secret field. Hand off the client ID only.
  • Application permissions instead of Delegated. TEDI signs in as a user.
  • Skipping admin consent. ChannelMessage.Read.All and ChannelMember.Read.All never work without it.
  • Single-tenant app handed off without the tenant ID. TEDI then uses the organizations authority, and sign-in fails with AADSTS50194.
  • Wrong license. Apps-only, mailbox-only, or Teams-only plans leave out a service TEDI needs.
  • Skipping Team membership. A license does not add the user to the Team.

Next steps​