Skip to main content

Integration Hub: Microsoft Teams

Set up your Microsoft Teams integration.

Written by Martyna Butryn

The Microsoft Teams integration lets you connect your Microsoft tenant to the Learningbank communication system. This makes it possible for Learningbank to send notifications directly to users via Microsoft Teams, ensuring timely and visible communication.

To do this, Learningbank uses a dedicated account referred to as a service user. This user is the account that sends notifications to other users in Teams.


How the Connection Works

When you connect Microsoft Teams to Learningbank, you will be asked to sign in using Microsoft. This uses a secure sign-in method called OAuth.

It is important to note that the Microsoft account you are logged in with at the time you click “Sign In” will become the service user.

For this reason, make sure you are logged in as the correct service user before starting the connection.

Requirements for the service user:

  • The service user must be a licensed Microsoft user (a basic license is sufficient).

  • The service user must be able to sign in to Microsoft Teams.


How Notifications Are Sent

Notifications are sent as one-to-one chat messages in Microsoft Teams. The service user sends messages directly to individual users whenever a notification is triggered in Learningbank.


Sign-In Policies

Security settings such as multi-factor authentication (MFA), access policies, and password reset rules apply to the service user.

If the service user is required to sign in again, the integration will stop working and must be reconnected from the Learningbank platform.

💡 Best practice

For security reasons, we recommend allowing the service user to be prompted to sign in again every 90 days. It is possible to disable sign-in prompts completely, but please be aware that this may reduce security.


Security - Information and Best Practices

💭 Good to know

For personal one-to-one messages in Microsoft Teams, Microsoft requires the message to be sent on behalf of a signed-in user. Because of this, the integration uses a dedicated Microsoft user account with delegated Microsoft Graph permissions.

Messages sent from Learningbank are personal messages and must be sent as one-to-one messages in Microsoft Teams. App-only authentication, such as service principal or client credentials authentication, is only supported by Microsoft for certain service-based message scenarios.

This means Learningbank acts on behalf of the signed-in Microsoft user to send messages. The integration can only work within the combination of:

  • The Microsoft Graph permissions granted to the integration

  • The access and permissions available to the dedicated Microsoft user

The Microsoft user account should therefore be configured with least privilege. We recommend that you:

  • Create a dedicated Microsoft account

  • Avoid using a personal user account or admin account

  • Do not assign unnecessary admin roles, group memberships, mailbox access, or tenant-wide permissions

  • Only grant the access required for the integration to send the relevant messages

  • Review the account regularly as part of your normal security and access review process


Permissions

Only a Microsoft administrator can grant permission for the Microsoft Teams integration.

Using a dedicated account, it is possible from the account to request access, that an admin grants. This avoids giving the dedicated account admin priveleges.

Did this answer your question?