§ 09 · DOCSPreview

Microsoft Teams permissions

Which Azure permissions each agent capability needs — and who grants them.

Status: Microsoft Teams support is in preview — not yet generally available. Awk Teams is Slack-first today (see the FAQ). This page documents the Azure permissions your tenant administrator will grant during onboarding. To join the Teams preview, request access.

When agents run inside Microsoft Teams, they talk to two different Microsoft APIs. Only one of them requires admin-consented permissions, so it helps to know which capability uses which.

Who grants these

These Microsoft Graph application permissions and the admin consent that activates them are granted by your tenant's Global Administrator (or a Privileged Role Administrator), in your own Microsoft Entra (Azure AD) directory.

Awk Teams does not perform this for you. The agent bots are registered as single-tenant apps in your own directory, and Microsoft only lets a Global Admin of that directory consent to applications that read its Teams data. The Awk Teams console onboarding wizard automates only the Teams app manifest, catalog upload, and app installation — it does not create the app registrations, request the Graph permissions, or grant admin consent.

The two APIs

SurfaceWhat it doesAdmin consent?
Bot Framework ConnectorSending and replying to messages, reading conversation membersNo — the bot's own identity (app ID + secret) is enough
Microsoft GraphListing channels and reading channel message historyYes — application permissions + admin consent required

Permission by capability

Agent capabilityAPIPermission requiredAdmin consent?
Send / reply in a threadBot Framework Connectornone beyond the bot identityNo
Read who is in a conversationBot Framework Connectornone beyond the bot identityNo
List a team's channelsMicrosoft GraphChannel.ReadBasic.All (Application)Yes
Read a channel's message historyMicrosoft GraphChannelMessage.Read.All (Application)Yes
Read a message's thread repliesMicrosoft GraphChannelMessage.Read.All (Application)Yes
Enumerate teams (resolve a team)Microsoft GraphTeam.ReadBasic.All (Application)Yes
Route a 1:1 direct message to an agentMicrosoft GraphUser.Read.All (Application)Yes

Takeaway: an agent can send, reply, and see conversation members with no Graph admin consent at all — that path is pure Bot Framework. The channel-reading capabilities (list channels, read history, read replies) need the Graph application permissions granted and admin-consented in your directory first.

Direct messages are the exception to watch. Replying in a channel works on the Bot Framework path alone, but a 1:1 DM can only be routed to the right agent once Graph can resolve the sender — so User.Read.All is required for direct messages. Without it, channel messages still work but DMs to a bot are silently dropped.

Reading the errors

Until the Graph permissions are consented, the channel-reading capabilities return a clean 403 Forbidden (missing <Permission>) — that is a consent/configuration gap on your Azure app registration, not a product fault. Once the permission is granted and admin-consented, the 403 clears.

A 404 Not Found is different: the permission is fine, but the team could not be resolved (for example, the directory/tenant ID was supplied where the team's Microsoft 365 group ID was expected).

Need the full step-by-step Azure setup (app registrations, bot resources, messaging endpoint, and these permissions)? See the Microsoft Teams bot setup guide, or ask your Awk Teams representative during Teams onboarding.