Prepare a Microsoft 365 account for TEDI
Before you wire Graph in TEDI, you need a work or school Microsoft 365 user that can sign in, read a Teams channel, read and send Outlook mail, and stay signed in as the shared identity TEDI uses for inbound. This article covers which subscription or license that user needs and how to create (or reuse) the account. For Entra app registration, device-code sign-in, and Settings → Microsoft 365 fields, continue with Configure Microsoft 365 in TEDI .
Who should do this
A Microsoft 365 admin who can add users and assign licenses in the Microsoft 365 admin center .
Someone who knows which Team/channel and mailbox TEDI should use on the Vista workstation.
Before you start
Your organization already has a Microsoft 365 tenant (Entra ID directory), or you are ready to buy a Microsoft 365 business or enterprise subscription from Microsoft.
You can sign in as a Global admin, User admin, or License admin (or equivalent) for that tenant.
You know a display name and sign-in email for the dedicated TEDI identity (for example
tedi@yourcompany.com).
What TEDI needs from Microsoft 365
TEDI does not require a special “TEDI SKU” from Microsoft. It signs in as one user with Microsoft Graph (device code) and uses that user’s Teams membership and Exchange mailbox. That user must be a work or school account in your tenant—not a personal Microsoft account (
@outlook.com
,
@hotmail.com
,
@live.com
).
Required capabilities on the signed-in user
Capability Why TEDI needs it Typical Microsoft service Sign in to Microsoft Entra ID / Microsoft 365 Device-code Test connection and Refresh permissions in TEDI Any licensed Microsoft 365 work/school user in your tenant Microsoft Teams (join a team, read/post channel messages) Poll the configured channel and send auto-replies Microsoft Teams service plan on the user’s license Exchange Online mailbox Poll Inbox (or another folder) and send email replies via Graph
/me
Exchange Online (mailbox created when you assign a plan that includes it) Member of the target Team Load teams/channels and read that channel Teams membership (not a license by itself—add the user to the Team)
Recommended subscription / license
Assign one license seat that includes both Microsoft Teams and Exchange Online to the dedicated TEDI user. Common choices:
Microsoft 365 Business Basic (with Teams) — usual lowest-cost commercial option that includes web Outlook/Teams and an Exchange mailbox. Prefer this when you only need a dedicated service identity for TEDI.
Microsoft 365 Business Standard or Business Premium (with Teams) — fine if you already buy these for staff; desktop Office apps are not required for TEDI Graph inbound.
Microsoft 365 / Office 365 E3 or E5 (with Teams) — fine for enterprise tenants; TEDI does not require E5. Channel polling uses standard delegated Graph channel APIs, not the metered Teams message-export / compliance APIs that document E5 or Communications DLP requirements.
If your Microsoft price list offers plans with Teams and without Teams , choose a plan with Teams (or add a Teams license) for this user. A mailbox-only plan without Teams is not enough for Teams inbound. A Teams-only plan without Exchange Online is not enough for Outlook inbound.
Reuse vs buy: Many sites already have spare Business Basic / Standard seats. You can assign an unused seat to a new
tedi@…
user instead of purchasing a second subscription product.
What does not work (or is a poor fit)
Personal Microsoft accounts — TEDI’s Microsoft 365 path expects work/school Graph authority, not consumer Outlook.com.
Microsoft 365 Apps–only licenses (desktop Word/Excel without Exchange/Teams services) — no mailbox / Teams cloud services for Graph inbound.
Signing in as a shared mailbox — Shared mailboxes are not interactive sign-in identities. Create a licensed user mailbox for TEDI’s device-code sign-in. (You can still have humans email that address.)
Guest / external B2B users as the TEDI identity — Prefer a member user in your tenant with a clear mailbox UPN.
Using a day-to-day personal staff mailbox — Technically possible, but replies and Inbox polling collide with that person’s mail. Prefer a dedicated account.
Step 1: Decide the identity
The local name is yours to choose. Many sites use
tedi@yourcompany.com
with Microsoft display name TEDI . You can also personalize both: in TEDI, the TEDI username (under Models / assistant settings; default
TEDI
) can be changed to something like Casey or Ops Bot . If you want the mailbox and channel posts to match that persona up front, create the Microsoft user with the same display name and a matching UPN (for example
casey@yourcompany.com
).
Pick a dedicated UPN (for example
tedi@yourcompany.com, or a personalized address that matches the assistant name you plan to use).Decide whether this mailbox is only for TEDI automation, or also an inbox humans read in Outlook. Either works; keep the Outlook allowlist in TEDI tight either way.
Confirm a Team and channel this account will join (you can create them after the user exists).
Expected outcome: You know the sign-in email TEDI operators will use during device-code sign-in, and whether the Microsoft display name should stay TEDI or match a personalized assistant name.
Step 2: Confirm you have an eligible license seat
Open the Microsoft 365 admin center .
Go to Billing → Licenses (or Billing → Your products ).
Find a product that includes Exchange Online and Microsoft Teams (for example Microsoft 365 Business Basic).
Confirm at least one seat is available to assign. If not, buy one additional license for that product (or free a seat from a departed user).
Expected outcome: At least one unused license seat that includes Teams + Exchange Online is ready to assign.
Step 3: Create the user (or choose an existing one)
Skip create if you already have a dedicated account with Teams + mailbox; go to Step 4 and verify the license.
In the Microsoft 365 admin center, go to Users → Active users → Add a user .
Enter:
Display name — for example
TEDI, or the same personalized name you will use in TEDI. Channel posts show this Microsoft display name; keep Skip replies from author names in Settings → Microsoft 365 aligned with it (defaultTEDI).Username — for example
tedi→tedi@yourcompany.com(or your personalized local part).
Set a password (or auto-generate). Record it securely for the first device-code sign-in and any MFA enrollment your tenant requires.
On the product licenses step, assign the Teams + Exchange Online license from Step 2. Leave other optional add-ons off unless your security policy requires them.
Finish the wizard. Wait a few minutes for the mailbox and Teams provisioning to finish.
Expected outcome: The user appears under Active users with a licensed mailbox UPN you can sign in with.
Step 4: Verify mailbox and Teams access
Sign in once as the new user at outlook.office.com (or the Outlook desktop app). Confirm Inbox opens.
Sign in to teams.microsoft.com as the same user.
Join or create the Team/channel TEDI will watch (for example Team TEDI Runner , channel Ask TEDI ). The account must be a member of that Team.
If your tenant enforces MFA, complete enrollment for this account now so device-code sign-in on the Vista PC does not stall later.
Expected outcome: The same work/school account can open Outlook mail and see the target Team/channel in Teams.
Step 5: Hand off to Graph configuration in TEDI
Give the Vista workstation operator:
The account UPN (for example
tedi@yourcompany.com).How to complete MFA / password for first sign-in.
Which Team and channel to select after Load teams from Microsoft .
An Entra admin still needs to register the public-client app and grant Graph admin consent (covered in the next article)—creating the user alone is not enough.
Open Configure Microsoft 365 in TEDI and complete Entra registration, Client id / Tenant id, Test connection (sign in as this user), Teams, and Outlook panels.
Expected outcome: Operators know which Microsoft account to use for device-code sign-in and which Team/channel/mailbox it owns.
Setup checklist
[ ] Work/school tenant available (not a personal Microsoft account)
[ ] One license seat with Microsoft Teams + Exchange Online (Business Basic with Teams or higher is typical)
[ ] Dedicated user created (recommended) and license assigned
[ ] Outlook Inbox opens for that user
[ ] User is a member of the Team/channel TEDI will poll
[ ] MFA enrolled if required by tenant policy
[ ] Ready for Configure Microsoft 365 in TEDI (Entra app + Settings → Microsoft 365)
Common mistakes
Buying Apps-only or Teams-without-mailbox — TEDI Outlook inbound needs Exchange Online on the signed-in user.
Buying mailbox-only without Teams — Teams inbound needs a Teams-enabled user who can join the channel.
Expecting E5 — Not required for TEDI’s delegated channel and mail polling.
Using a shared mailbox as the Graph identity — Use a licensed user for device-code sign-in.
Skipping Team membership — License alone does not put the user in your Ask TEDI channel.
Signing in with a personal @outlook.com account during Test connection — Use the work/school UPN you created here.
Next steps
Configure Microsoft 365 in TEDI — Register the Entra public client, grant Graph permissions, and complete Settings → Microsoft 365 (device code, Teams, Outlook).
TEDI Initial Setup — License, Vista SQL catalog, and Windows Service if the workstation is not ready yet.
Monitoring and Troubleshooting TEDI — When inbound is quiet after configuration.