Prepare a Microsoft 365 account for TEDI
This article is for the client's Microsoft 365 or Microsoft Entra admin. Every step happens in Microsoft portals. When you finish, hand the values in Step 7 to the TEDI operator, who completes Configure Microsoft 365 in TEDI.
What you'll set up and hand off
- A licensed work or school user that TEDI signs in as (for example
tedi@yourcompany.com). - A Team and channel that user belongs to.
- An Entra app registration configured as a public client, with no client secret.
- 13 delegated Microsoft Graph permissions on that app, with tenant-wide admin consent.
- A handoff table for the TEDI operator.
Who does this and needed roles
- User and license: User Administrator and License Administrator, or equivalent.
- App registration and admin consent: Cloud Application Administrator. Microsoft names it as the least-privileged role for granting tenant-wide admin consent to delegated Microsoft Graph permissions ("sign in as at least a Cloud Application Administrator"), and it can also register apps. Privileged Role Administrator or Global Administrator is only needed for Graph application permissions, which TEDI does not use. Source: Grant tenant-wide admin consent to an application.
What TEDI needs from Microsoft 365
TEDI signs in as one user through Microsoft Graph with a device code and uses that user's Teams membership and Exchange Online mailbox. No special SKU is needed.
- A work or school account in your tenant. Personal accounts (
@outlook.com,@hotmail.com,@live.com) are not supported. - One license seat that includes both Microsoft Teams and Exchange Online. Microsoft 365 Business Basic (with Teams) is the usual lowest-cost choice. Business Standard, Business Premium, E3, and E5 (with Teams) also work. E5 is not required: TEDI uses standard delegated Graph channel APIs, not the metered Teams export APIs. A spare seat is fine.
- Membership in the Team TEDI will watch. A license does not add the user to a Team.
Poor fits: Apps-only licenses (no mailbox or Teams), a shared mailbox (not supported; TEDI always reads and sends as the signed-in user's own mailbox), a guest (B2B) user, or a staff member's everyday mailbox (TEDI's replies collide with that person's mail).
Step 1: Choose the identity
- Pick a dedicated UPN and display name, for example
tedi@yourcompany.comand TEDI. If the operator plans to give the assistant a personal name in TEDI (the TEDI username, set in TEDI under Settings > Assistant, defaultTEDI), you can match it, for examplecasey@yourcompany.comand Casey. - Decide which Team and channel the account will join.
Step 2: Assign a license and create the user
If a dedicated user with Teams and a mailbox already exists, confirm its license and go to Step 3.
- Open the Microsoft 365 admin center.
- Go to Billing > Licenses. Confirm a product with Exchange Online and Microsoft Teams has an unassigned seat. If not, buy one or free a seat.
- Go to Users > Active users > Add a user. In the Simplified view, select Add user instead.
- Enter the Display name and Username from Step 1. TEDI's channel posts show this display name.
- Set a password and record it securely.
- Under Assign product licenses, assign the Teams and Exchange Online license. Leave optional add-ons off unless your policy requires them.
- Finish the wizard and wait a few minutes for the mailbox and Teams to provision.
Expected outcome: The user appears under Active users with a licensed mailbox.
Step 3: Verify mailbox, Teams, MFA, and the Team and channel
TEDI does not install a Teams app or create a Team or channel. Teams meetings started with Meet Now are joined from a Meet Now already posted in the watched channel; TEDI never creates them.
- Sign in as the TEDI user at outlook.office.com. Confirm the Inbox opens.
- If your tenant enforces MFA, complete enrollment for this account now so the operator's first sign-in does not stall.
- Sign in to teams.microsoft.com as the same user.
- Open or create the Team TEDI will watch, for example TEDI Assistant.
- Open or create a standard channel where people will post for TEDI, for example Ask TEDI. Private and shared channels are not verified for TEDI polling and replies.
- Confirm the TEDI user is a member of that Team.
Expected outcome: The account opens Outlook and sees TEDI Assistant > Ask TEDI. The operator picks them from a list in TEDI, so nobody copies Graph IDs.
Step 4: Register the Entra app as a public client
TEDI signs in with the device code flow, which requires a public client.
- Open the Microsoft Entra admin center.
- Go to Entra ID > App registrations > New registration.
- Set:
- Name: for example
TEDI Graph. - Supported account types: Single tenant only (Microsoft's recommendation for most apps) or Multiple Entra ID tenants, per your policy. Older portal versions label these Accounts in this organizational directory only and Accounts in any organizational directory. Record which one you chose.
- Redirect URI: if the form shows it, leave it blank.
- Name: for example
- Select Register.
- On Overview, copy the Application (client) ID and Directory (tenant) ID.
- Open Authentication and select the Settings tab. Turn on Allow public client flows (the default is Disabled) and save the change.
- Do not add anything under Certificates & secrets.
Step 5: Add delegated Microsoft Graph permissions
- In the app, open API permissions > Add a permission > Microsoft Graph > Delegated permissions. Do not use Application permissions.
- Add all 13 permissions below. TEDI requests all 13 at sign-in and checks every one. The 7 core permissions are required for sign-in to pass. Without an optional group, text inbound still works but that feature does not.
| Permission | What TEDI uses it for | Admin consent required (per Microsoft) | Core or optional (group) |
|---|---|---|---|
User.Read | Signed-in identity | No | Core |
Team.ReadBasic.All | List teams | No | Core |
Channel.ReadBasic.All | List channels | No | Core |
ChannelMessage.Read.All | Poll channel messages | Yes | Core |
ChannelMessage.Send | Post channel replies and the start-gate alert thread | No | Core |
Mail.Read | Poll the inbox | No | Core |
Mail.Send | Send email replies and the start-gate alert emails | No | Core |
ChannelMember.Read.All | Look up channel members' email addresses (channel roster emails) | Yes | Optional (proof) |
User.ReadBasic.All | Resolve the asker's email address | No | Optional (proof) |
Calendars.Read | Read meeting details, including calendar events and channel Meet Now join URLs | No | Optional (calendar) |
Calendars.ReadWrite | Outlook calendar sync: push Schedules, Monitors, and Bot due items to a dedicated Outlook calendar named TEDI | No | Optional (calendar) |
Files.Read.All | Download files shared from SharePoint or OneDrive that are attached to Teams channel messages | No | Optional (files) |
Sites.Read.All | Download files attached to Teams channel messages when they are stored in SharePoint | No | Optional (files) |
Consent values are from the delegated column of the Microsoft Graph permissions reference.
Step 6: Grant admin consent
Admin consent is always required for TEDI, because ChannelMessage.Read.All and ChannelMember.Read.All need it.
- On API permissions, select Grant admin consent and confirm.
- Confirm every row shows Granted in the Status column.
If you add or change a permission later, grant consent again and tell the operator so they can refresh permissions in TEDI.
Step 7: Hand off to the TEDI operator
Send these values through a secure channel. Send the password separately from the UPN.
| Item | Value |
|---|---|
| TEDI user UPN | For example tedi@yourcompany.com |
| First sign-in and MFA | Confirmation that first sign-in and MFA enrollment are done, and how the operator gets the password |
| Client ID | Application (client) ID from Step 4 |
| Tenant ID and supported account type | Directory (tenant) ID from Step 4, and whether the app is single tenant or multitenant. The TEDI field is optional, and blank uses the organizations authority. A single-tenant app, the usual kind, requires the tenant ID in practice, or sign-in fails with AADSTS50194. |
| Team and channel | For example TEDI Assistant > Ask TEDI |
| TEDI users | The people who should be TEDI super users (the All skills group) and any individual users, so the operator can set up Groups in TEDI |
Checklist
- Work or school user created with a Teams and Exchange Online license
- Outlook opens and MFA is enrolled if required
- User is a member of the Team and channel
- App registered with Allow public client flows turned on and no client secret
- All 13 delegated permissions added, admin consent granted, every row Granted
- Handoff values sent to the TEDI operator
Common mistakes
- Public client flows left off. Device code sign-in fails until Allow public client flows is turned on (Authentication, Settings tab).
- Creating or pasting a client secret. TEDI has no secret field. Hand off the client ID only.
- Application permissions instead of Delegated. TEDI signs in as a user.
- Skipping admin consent.
ChannelMessage.Read.AllandChannelMember.Read.Allnever work without it. - Single-tenant app handed off without the tenant ID. TEDI then uses the
organizationsauthority, and sign-in fails with AADSTS50194. - Wrong license. Apps-only, mailbox-only, or Teams-only plans leave out a service TEDI needs.
- Skipping Team membership. A license does not add the user to the Team.
Next steps
- Configure Microsoft 365 in TEDI: the operator enters the handoff values.
- TEDI Initial Setup: license, Vista SQL catalog, and Windows Service.