For nudge and playbook delivery setup, start at Settings → Communications →
Channels and click the Microsoft Teams card. This page covers the
underlying Teams app configuration.
Prerequisites
Before configuring Microsoft Teams, ensure you have:- A Microsoft Teams administrator who can upload and approve organization apps. The same person may hold both administrator roles.
- A Microsoft Entra administrator only if you want to enable optional email/UPN lookup fallback with tenant-wide
User.Read.Allapplication consent - Living Security administrator privileges
- An active Living Security organization
- The team and channel names where security announcements should be delivered, if channel announcements are enabled
- Your Microsoft Entra tenant ID, available under Microsoft Entra admin center → Identity → Overview
Who Does What
These can be different people. Share the package checksum, Teams app ID, Bot app ID, and intended rollout population with the Microsoft Teams administrator. Share the generated consent URL with a Microsoft Entra administrator only when enabling the optional email/UPN lookup fallback. Do not share unrelated Living Security credentials.
Setup
1
Open the Microsoft Teams setup panel
In Living Security, go to Settings → Communications → Channels and select Microsoft Teams.The panel shows your organization region, package filename, Teams app ID, bot app ID, SHA256 checksum, Microsoft tenant configuration status, install instructions, install message controls, validation, and test notification tools.
The region shown in Living Security matches the region where your organization is hosted.
2
Connect your Microsoft tenant
In Connect your tenant, enter the Microsoft Entra tenant ID that owns the users and Teams channels receiving notifications, then click Save Microsoft tenant. One Microsoft tenant can belong to only one Living Security organization.If the tenant control is unavailable, work with your Living Security implementation owner or support contact to connect or change the tenant before installing the app.
Living Security shows Microsoft tenant connected before you continue.
Connect the tenant before installing the Teams app when possible. If the app is already installed, save the tenant and select Validate install first. Living Security attempts to associate the existing installation automatically; reinstall only if validation cannot detect it.
3
Download the regional Teams package
Click Download Teams package. Living Security provides a region-specific ZIP package for your organization. Do not edit the manifest before uploading it to Microsoft Teams.
Keep the SHA256 checksum shown in Living Security available for verification during rollout.
4
Upload and install the package in Teams admin center
In Microsoft Teams admin center, go to Teams apps → Manage apps → Actions → Upload new app, then upload the ZIP file downloaded from Living Security.Confirm:
- The app name and publisher are Living Security
- The app is unblocked
- The app is available to the intended users or groups
- The app is installed through app setup policies or targeted install for the users and teams/channels that should receive notifications
If validation or a test fails immediately after an app-policy change, confirm the policy assignment in Microsoft Teams admin center and retry after Microsoft finishes propagating it.
5
Install or open the app
Distribute the personal app to the intended users. Before Living Security can
send a personal test to a detected installation, at least one user must
install or open the Living Security personal app in Microsoft Teams. This
allows the bot to capture the user’s trusted identity and personal
conversation reference. A channel installation alone cannot be used for a
personal detected-install test.For channel delivery, install the app in the intended team and channel so the
bot can capture that channel conversation reference.
A target user has installed or opened the personal app, or the app is
installed in the intended channel.
6
Configure install messages
In the Install message controls section, choose whether Teams install messages are sent and customize the one-way copy for your organization.Available controls:
- Send install messages
- Send personal install messages
- Send channel install messages
- Default message
- Personal message
- Channel message
{{installerName}}, which resolves to the display name of the user who installed the app. Leave a personal or channel message blank to use your configured default message. If the default message is also blank, Living Security uses the built-in message for that scope.7
Validate the setup
Click Validate install in Living Security. Validation checks that the regional package is available, the Microsoft tenant configuration is present and unique to this Living Security organization, regional bot credentials are configured, and an active app installation has been detected for the connected tenant.
Validation shows Validation passed before you send live notifications.
8
Send test notifications
For the default personal test, click Send test to detected installation.
Living Security selects a detected active personal installation and uses its
stored trusted identity and conversation reference. This test does not call
Microsoft Graph and does not require Review the corresponding attempt in the Communication Log when delivery diagnostics are needed.
User.Read.All consent.If no personal installation is detected, ask a user to install or open the
Living Security personal app, select Validate install again, and then
resend the test. Use the advanced targeted email/UPN test only when the
optional lookup fallback is enabled.The one-way test notification appears in Microsoft Teams.
Optional: Enable Email/UPN Lookup Fallback
Normal personal delivery uses a trusted Microsoft Entra object ID already known to Living Security together with the bot conversation reference captured when the user installs or opens the app. Channel delivery uses its stored channel conversation reference. Neither route requires Microsoft Graph. If a recipient does not have a trusted Entra object ID, Living Security can optionally use Microsoft Graph to resolve the recipient by email address or UPN. To enable that fallback, ask a Microsoft Entra administrator to click Grant optional User.Read.All consent in the Teams setup panel and approve the Microsoft GraphUser.Read.All application permission for the regional Living
Security Teams application.
The admin consent flow follows this Microsoft Entra pattern:
- Teams app ID identifies the installable app package in Microsoft Teams admin center.
- Bot app ID identifies the regional bot’s Microsoft Entra application and is the client ID used for the optional admin consent flow.
Making consent optional does not remove
User.Read.All from existing regional
Living Security application registrations. Customers that already granted
consent can continue using email/UPN fallback without reconfiguration.Notification Types
Depending on your organization’s entitlements and configured playbooks, Living Security can send:Customization
Teams notifications use your Living Security organization configuration. Supported fields include customer display name, supported logo and brand fields, message copy, calls to action, destination links, rollout text, and support/contact text. Install messages are configurable from Settings → Communications → Channels → Microsoft Teams → Install message controls. You can disable install messages entirely, disable only personal or channel install messages, and configure default, personal, or channel-specific copy.Updating or Removing the App
- When Living Security provides an updated regional package, download it from the Microsoft Teams channel panel and upload that package through Teams admin center. Verify the displayed app ID, bot ID, and checksum before rollout.
- Re-run Validate install and send another test after an app or policy update.
- Removing or blocking the app prevents proactive notifications to that user or channel. Reinstall the app and send a new test so Living Security receives a current Teams installation event.
- If you are discontinuing Teams delivery, remove Teams from the relevant playbooks before removing the app from Microsoft Teams.
Troubleshooting
A user does not receive a personal notification
A user does not receive a personal notification
- Confirm the Living Security Teams personal app is installed and the user has opened it so Living Security has a current conversation reference
- Confirm the configured Microsoft tenant ID is the tenant where the user is located
- If diagnostics show that email/UPN fallback was attempted, confirm
User.Read.Alladmin consent was granted to the displayed Bot app ID for the correct tenant - When email/UPN fallback is used, verify the user’s email or UPN in Living Security matches Microsoft Entra ID
- Ask the user to unblock or reinstall the app if they previously removed or blocked it
A channel announcement does not appear
A channel announcement does not appear
- Confirm the Living Security Teams app is installed in the target team or channel.
- Confirm the channel mapping in Living Security uses the correct team and channel.
- Check whether the channel was removed, renamed, archived, or restricted.
- Reinstall the app in the target team or channel and send another test notification.
Optional email/UPN lookup or consent fails
Optional email/UPN lookup or consent fails
- Confirm a Microsoft Entra administrator granted tenant-wide consent for
Microsoft Graph
User.Read.Allto the displayed Bot app ID. - Confirm the configured tenant ID is the tenant where users and Teams are located.
- Verify the user exists in Microsoft Entra ID and is not a guest from another tenant.
Communication Log shows Microsoft admin consent required
Communication Log shows Microsoft admin consent required
The error category
TEAMS_ADMIN_CONSENT_REQUIRED, or Microsoft error AADSTS7000229, means an email/UPN recipient lookup attempted the optional Microsoft Graph fallback, but the regional Living Security Teams app has no service principal (enterprise application) in the connected Microsoft Entra tenant. The default trusted-ID and stored-conversation routes do not require this consent. This is not an expired Living Security secret.- Open Settings → Communications → Channels → Microsoft Teams. You can also use Open Microsoft Teams setup from the Communication Log error.
- Confirm the correct Microsoft Entra tenant ID is connected.
- If email/UPN fallback is required, ask a Microsoft Entra administrator to click Grant optional User.Read.All consent and approve
User.Read.Allfor the displayed Bot app ID. Otherwise, ensure the recipient has opened the personal app and that Living Security has their trusted Entra object ID. - After Microsoft finishes processing the consent, send an advanced targeted email/UPN test from Microsoft Teams setup. Communication Log shows delivery history and diagnostics; it does not redeliver the failed message.
The app is installed but notifications fail
The app is installed but notifications fail
- Check whether the bot was blocked, removed, or uninstalled
- If the app was installed before the tenant was connected in Living Security, save the tenant and select Validate install so Living Security can associate the existing installation
- Reinstall only if validation cannot detect the existing installation
- Confirm the target user or channel has received the latest app install event
- Send a new test notification after reinstalling the app
Security
Living Security uses Microsoft GraphUser.Read.All only for the optional email/UPN recipient lookup fallback. By default, personal notification routing uses a trusted Entra object ID from Living Security’s entity data and the bot conversation reference captured from Microsoft Teams. Caller-supplied object IDs and conversation references are not trusted routing data. Microsoft Teams messages are delivered through the Living Security notification-only Teams bot using Microsoft Teams proactive messaging.
Living Security does not require customers to create their own Microsoft Entra app registration or share a customer-owned client secret for the standard Teams app setup.
Region-specific Teams packages keep the app ID, bot ID, and messaging endpoint aligned with the Living Security region where your organization is hosted.
Related
Email Integration
Configure email as a delivery channel.
Slack Integration
Configure Slack as a delivery channel.
Communication Log
Track Teams delivery status and history.
Authentication
Microsoft Entra ID and SSO configuration.

