Configure Microsoft 365 in TEDI
This article is for the TEDI operator on the Vista workstation and covers only Settings > Microsoft 365. When you finish, TEDI polls a Teams channel and an Outlook folder, routes new messages into Control Panel chat, and can auto-reply. It also downloads files attached to Teams channel messages (see Teams file attachments).
The client's Microsoft 365 admin does the Microsoft side first, in Prepare a Microsoft 365 account for TEDI.
Before you start
- TEDI is installed and licensed, and the desktop app opens. See TEDI Initial Setup if License or Database is not ready.
- The TEDI Windows Service (display name TEDI Runner) is Running.
- You have the handoff values from Prepare, Step 7: the TEDI user's UPN and password, Client ID, Tenant ID and supported account type, Team and channel, and the people to add to TEDI Groups.
- For auto-replies (not just inbound capture), a chat model is configured under Settings > Assistant > Providers. See Configure LLM Providers in TEDI.
How it fits together
- One Entra public client app and one Microsoft account sign-in (by device code) serve both Teams and Outlook.
- The Microsoft 365 tab has four panels: Microsoft account, Teams, Outlook, and Outlook calendar sync. A Pending inbound panel appears at the top only when pending items exist.
- Save settings is on the Microsoft account panel and reloads runner config.
- Inbound polling runs in the TEDI Windows Service, not the desktop window, so closing the desktop window does not stop it. See Turn inbound off.
- The first-run setup wizard has an optional, skippable Microsoft 365 step, 4th in the flow (Welcome, License, Database, Microsoft 365, Email, LLM, Done). It embeds this same editor, so it has the same fields and saves the same settings. For plain SMTP email only, use Settings > Email instead.
Step 1: Enter Client id and Tenant id, then Save
- Launch the TEDI desktop app. In the collapsible left sidebar, under the Settings section, open Settings, then the Microsoft 365 tab.
- In the Microsoft account panel, set:
- Client id (required): the Application (client) ID from the handoff, in the form
xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx. - Tenant id (optional): the Directory (tenant) ID from the handoff. The field is optional in TEDI. Blank uses the
organizationsauthority, which accepts work or school accounts from any Entra directory. A filled value useshttps://login.microsoftonline.com/<tenant>. A single-tenant app registration, the usual kind, must enter its tenant ID, or sign-in fails with AADSTS50194. Only a multitenant app can leave it blank.
- Client id (required): the Application (client) ID from the handoff, in the form
- Select Save settings. Only Client id is required to save; if it is empty, TEDI shows Enter a Graph client id before saving. On success you see Microsoft 365 settings saved and runner config reloaded. If saving fails, you see Could not save Microsoft 365 settings.
Expected outcome: The status banner no longer shows the warning Microsoft client id required. (shown while no Graph client id is saved).
Step 2: Test connection and sign in
- Select Test connection. If Client id is empty, TEDI shows Enter a Graph client id before continuing. While it runs, the panel shows Testing Microsoft 365 connection…
- Sign-in uses a device-code prompt, shown in a toast:
Sign in required: open <verificationUri> and enter code <userCode>. Waiting…The address is normallyhttps://microsoft.com/devicelogin. Open it, enter the code, and sign in as the TEDI user from the handoff (not a personal account). - On success TEDI shows
Connected as <account>., or the fallback message Microsoft 365 connection verified.- On timeout: Microsoft sign-in timed out. Complete the device-code prompt, then click Test connection again.
- On other failures: Could not test Microsoft 365 connection.
Sign-in requests all 13 delegated permissions. The test fails if a core permission is missing. It still succeeds when only optional permissions are missing, because TEDI falls back to a core-only token; those permissions show red in Step 3.
Expected outcome: The Microsoft account is cached for Graph.
Step 3: Confirm all permissions are green
Under the Microsoft account buttons, TEDI lists all 13 delegated permissions, each marked Granted (green), Missing (red), or Unknown (gray, only when not signed in). The on-screen help reads: Green = present on the current token. Red = missing (add in Entra, grant admin consent, then Refresh permissions). Gray = not signed in.
A passing Test connection does not mean every row is green, so always check this list.
Refresh permissions always starts an interactive device-code sign-in for all 13 permissions, using the same toast as Test connection. Unlike Test connection, it never succeeds silently from the cached token. It does not clear the token cache. Use it whenever the Microsoft admin adds or changes permissions. On success it shows Permissions refreshed for <account>. On timeout it shows Microsoft sign-in timed out. Complete the device-code prompt, then click Refresh permissions again.
- Confirm every row is green.
- If any row is red, ask the Microsoft admin to confirm the permission is added and admin consent is granted (Prepare, Steps 5 and 6). Consent in Entra must succeed first.
- Select Refresh permissions, complete the device-code prompt with the same account, and confirm the rows turn green.
Missing optional permissions do not block text inbound. For example, without Files.Read.All and Sites.Read.All, Teams channel attachments are skipped.
Step 4: Choose the Team and channel
- At the bottom of the Teams panel, select Load teams from Microsoft. Teams do not load automatically after sign-in. The button uses the existing sign-in from Step 2 and never starts a device-code prompt. While it runs you see Loading teams from Microsoft…. Without a sign-in it shows Microsoft sign-in required. Click Test connection first, then load teams again. On failure it shows Could not load teams from Microsoft.
- Choose Team (placeholder Select a team), for example TEDI Assistant. Then choose Channel (placeholder Select a channel), for example Ask TEDI. There are no free-text Graph ID fields.
- Optional: Team display name (optional) and Channel display name (optional) override the names TEDI shows for the selected Team and channel.
- Set Inbound poll interval (seconds). Default
30, minimum5. - Review Skip replies from author names (comma-separated). Default
TEDI. TEDI skips a Teams message when its author display name matches one of these names exactly (case-insensitive). This is not how TEDI avoids replying to itself: its own posts appear under the signed-in account, and TEDI suppresses them by recorded message ids and echo matching. The setting only catches authors whose display name equals a listed name, such as a separate account named TEDI. Outlook ignores it. - Check Enable inbound polling (Teams channel → Control Panel chat → auto-reply).
- Optional: under Start-gate alert emails (optional), enter an Email address and select Add Email for each person to alert. See Pending inbound after a start.
- Select Save settings again. Teams inbound is ready only after a Team and Channel are chosen and saved. Until then the status banner shows Teams: select a team and channel.
The Team list shows only Teams the signed-in account is a member of. If a Team is missing, make sure the account is a member of it. The Channel list includes standard, private, and shared channels, but only standard channels are verified for polling and replies, so choose a standard channel.
Step 5: Set up Outlook inbound
- In the Outlook panel, set:
- Default folder path: default
Inbox. - Default account (optional) (placeholder
user@company.com): an account label only. TEDI always reads and sends as the signed-in mailbox; this field does not select another mailbox. The value is added to TEDI's own addresses, so mail from it is skipped. Blank is fine. - Inbound poll interval (seconds): default
30, minimum5.
- Default folder path: default
- Check Enable inbound polling (Inbox mail → Control Panel chat → auto email reply).
- Select Save settings. Without a folder path, the status banner shows Outlook: set folder path.
The Outlook panel has no sender field. Its help text reads: Who may email TEDI is managed under Settings → Groups. The signed-in Microsoft 365 mailbox is always skipped to prevent reply loops. Outlook inbound is deny by default: a sender must be a member of at least one Group. In Settings > Groups, the All skills group holds super users, and admins can create other groups for individual users.
Each poll reads the top 15 messages in the Default folder path and skips messages already processed. It then skips, in order, mail sent by the signed-in mailbox, senders not in any Group, and calendar invites and RSVPs.
Step 6: Save and smoke test
If you changed anything since the last save, select Save settings.
When you first enable Teams or Outlook inbound, TEDI takes a baseline: existing messages are marked seen and nothing older is replied to. For Outlook that is the 15 most recent messages in the folder, because each poll reads the top 15. Test only with posts and mail sent after you enable inbound.
- Read the status banner. Healthy inbound shows Teams inbound active · every 30s and Outlook inbound active · every 30s, with your intervals. A side that is turned off shows
<label> inbound disabled. - If the status banner says auto-reply needs a chat model, it points to Settings > Assistant > Providers. Configure a model there before expecting replies. See Configure LLM Providers in TEDI.
- Post a new message or reply in the channel. Optionally attach a file shared from SharePoint or OneDrive.
- Send a new email to the watched folder from a sender who is in a Group.
- Confirm both appear in Control Panel chat after the poll interval and, with a model configured, that TEDI replies.
Expected outcome: Teams and Outlook inbound show active, and new posts and email are picked up.
After setup
Pending inbound after a start
After the TEDI runner or Windows Service starts, anything new in Teams or Outlook since the last run waits until an operator chooses Process or Clear. If nothing is pending, inbound does not wait.
- The Pending inbound panel appears at the top of Settings > Microsoft 365 only when pending items exist. Use Dismiss on an item, Refresh pending to reload the list, Clear pending to mark all as seen without replying, or Process pending to arm inbound to process them on the next poll.
- If Start-gate alert emails (optional) has addresses, the help text applies: When inbound is held after a runner/service start, TEDI posts a Teams thread (greeting + CTA) and emails these addresses. Reply in that thread (or email) with A to Process or B to Clear. The Teams thread is titled Pending Microsoft 365 inbound. The email is sent from the signed-in mailbox through Microsoft Graph (
Mail.Send), not through Settings > Email SMTP. The field is in the Teams panel but covers both Teams and Outlook.
Outlook calendar sync (optional)
Sync schedules to TEDI's Outlook calendar pushes Schedules, Monitors, and Bot due items onto a dedicated Outlook calendar named TEDI (not the primary calendar), which TEDI creates if missing. Sub-hourly schedules and always-on monitors are left out. It needs Calendars.ReadWrite, syncs every 15 minutes when enabled, and Sync now forces a sync. Errors show as Error: <message> under the checkbox and do not stop the runner.
Switch account
Switch Account opens the dialog Sign out of Microsoft 365?, which reads: The cached Microsoft account will be cleared. The next Test connection will prompt for device-code sign-in so you can pick a different account. Use Refresh permissions instead if you only need to consent to new Graph scopes for the same account. Select Sign out. TEDI shows Microsoft account signed out.
Only the cached Microsoft sign-in is cleared. The Team and Channel choices, inbound state (seen messages), and calendar sync settings are kept. Switch Account does not start a sign-in; run Test connection and sign in as the new account.
Reset baselines
Reset Teams inbound and Reset Outlook inbound re-baseline inbound: existing messages are marked seen, not replied to, and only new posts or mail trigger TEDI afterward. Use them when you want TEDI to ignore a backlog. Each opens a confirm dialog with a Reset baseline button:
- Reset Teams inbound baseline?: The next poll will re-snapshot existing messages. Post a new message or thread reply after that to trigger TEDI. Toast: Teams inbound baseline reset.
- Reset Outlook inbound baseline?: The next poll will re-snapshot existing Inbox mail. Send new mail after that to trigger TEDI. Toast: Outlook inbound baseline reset.
Turn inbound off
Uncheck the Enable inbound polling box for Teams or Outlook and select Save settings. Both watchers check that setting on every poll. Stopping the TEDI service in Services.msc also stops inbound, but it stops schedules and everything else too, so use it only as a full stop.
Teams file attachments
TEDI downloads files attached to Teams channel messages to <app data>\inbound-attachments\<message id>\. App data is the TEDI_APPDATA environment variable, or %LOCALAPPDATA%\tedi-runner if it is not set. There is no setting for this folder.
- The limit is 4 MB per file.
- Only files shared from SharePoint or OneDrive (file references) are downloaded. Inline or embedded content is skipped.
- Without
Files.Read.AllandSites.Read.All, the download fails and the attachment is skipped. The message is still handled.
Field reference
Fields are listed in on-screen order.
| Panel | Field or control | Required? | What it is |
|---|---|---|---|
| Microsoft account | Client id | Yes | Entra Application (client) ID |
| Microsoft account | Tenant id (optional) | Optional in TEDI; required in practice for single-tenant apps (the usual kind) | Entra Directory (tenant) ID. Blank uses the organizations authority (any Entra directory); filled uses https://login.microsoftonline.com/<tenant>. A single-tenant app left blank fails with AADSTS50194 |
| Microsoft account | Save settings, Test connection, Refresh permissions, Switch Account | No | Buttons, followed by the permission list |
| Teams | Team | Yes, for Teams inbound | Placeholder Select a team; filled by Load teams from Microsoft |
| Teams | Channel | Yes, for Teams inbound | Placeholder Select a channel |
| Teams | Team display name (optional) | No | Overrides the displayed Team name |
| Teams | Channel display name (optional) | No | Overrides the displayed channel name |
| Teams | Inbound poll interval (seconds) | No | Default 30, minimum 5 |
| Teams | Skip replies from author names (comma-separated) | No | Default TEDI. Case-insensitive exact match on the Teams author display name |
| Teams | Enable inbound polling (Teams channel → Control Panel chat → auto-reply) | No | Turns Teams inbound on or off |
| Teams | Start-gate alert emails (optional): Email address, Add Email | No | Removable list of addresses alerted when inbound is held after a start |
| Teams | Load teams from Microsoft, Reset Teams inbound | No | Buttons |
| Outlook | Default folder path | Yes | Default Inbox |
| Outlook | Default account (optional) | No | Account label only (placeholder user@company.com); mail from it is skipped. TEDI always uses the signed-in mailbox |
| Outlook | Inbound poll interval (seconds) | No | Default 30, minimum 5 |
| Outlook | Enable inbound polling (Inbox mail → Control Panel chat → auto email reply) | No | Turns Outlook inbound on or off. There is no sender field; access comes from Settings > Groups |
| Outlook | Reset Outlook inbound | No | Button |
| Outlook calendar sync | Sync schedules to TEDI's Outlook calendar, Sync now | No | Syncs to the TEDI Outlook calendar; shows last-sync status |
| Pending inbound | Dismiss, Refresh pending, Clear pending, Process pending | No | Shown only when pending items exist |
Checklist
- Client id entered, Tenant id entered for a single-tenant app, settings saved
- Test connection completed as the TEDI user
- Every permission green (Refresh permissions after any Entra change)
- Team and Channel selected, Teams inbound enabled, saved
- Outlook folder set, Outlook inbound enabled, saved
- Senders are members of a Group in Settings > Groups
- Status banner shows Teams and Outlook inbound active
- Chat model configured if you need auto-reply
- Smoke test passed with a new Teams post and a new email
Common mistakes
- Tenant id blank for a single-tenant app. Blank means the
organizationsauthority, so sign-in fails with AADSTS50194. Enter the Directory (tenant) ID. - Signing in with the wrong account. Use Switch Account, then sign in as the TEDI user.
- Using only Test connection after an Entra change. It can pass without new optional permissions. Use Refresh permissions.
- Waiting for teams to appear. They do not load automatically. Select Load teams from Microsoft after signing in.
- Choosing a private or shared channel. Only standard channels are verified for polling and replies.
- Relying on Skip replies to stop self-replies. TEDI already suppresses its own posts. The setting only matches other authors by display name.
- Not saving. Team, Channel, and Outlook values are used only after Save settings.
- Inbound checkboxes off. The status banner shows inbound disabled.
- Sender not in any Group. Outlook inbound skips the mail. Add the sender in Settings > Groups.
- Expecting auto-reply without a chat model. Inbound captures messages, but replies need a model under Settings > Assistant > Providers.
- Assuming closing TEDI stops inbound. The Windows Service keeps polling. See Turn inbound off.
Next steps
- Prepare a Microsoft 365 account for TEDI: the Microsoft admin side.
- Configure LLM Providers in TEDI: enable auto-replies.
- Monitoring and Troubleshooting TEDI: when inbound is quiet.