- An Azure subscription with permission to create a resource and register an application in your Microsoft Entra ID directory. The free F0 tier is enough; the Teams channel costs nothing extra.
- A Teams admin who can allow custom app uploads or approve an app for the organization.
- An agent with a promoted production version; see Release an agent.
1
Provider console: create the Azure Bot
In the Azure Portal search for Azure Bot (publisher Microsoft) and select Create. Give it a bot handle (an internal name), pick the subscription and a resource group, choose Free (F0), set Type of App to Single Tenant, and leave Create new Microsoft App ID selected so Azure registers the bot’s identity for you. Select Review + create, then Create, then Go to resource.
2
Provider console: set the messaging endpoint
Under Settings → Configuration, set Messaging endpoint to the address Microsoft calls for every message and select Apply. It is the same for every organization.
3
Provider console: collect the three values
On the same page copy the Microsoft App ID. Select Manage Password to open the bot’s app registration; its Overview shows Application (client) ID (the App ID again) and Directory (tenant) ID (your tenant ID). Under Certificates & secrets → Client secrets, select New client secret, pick an expiry, and copy the Value column at once; Azure hides it when you leave the page. That value is the app password.
4
Provider console: enable the Teams channel
Back on the Azure Bot resource, open Settings → Channels, select Microsoft Teams, accept the terms, keep Microsoft Teams Commercial, and apply. Teams shows as running.
5
Dashboard: connect the bot to your agent
In the admin dashboard open Agents, select the agent, select + in the Channels section of its Overview tab, choose Microsoft Teams in Connect a channel, then Bring your own Azure Bot and Yes, I already have an Azure Bot. Enter the App ID, App password, and Tenant ID and select Connect; the wizard has no tenant-type switch and assumes the single-tenant bot from the first step. The channel is active immediately. The dialog that follows repeats the messaging endpoint to check against Azure and offers Download app package (.zip), a ready-made Teams app you can upload instead of building one in the next step.
6
Provider console: build the Teams app
In the Teams Developer Portal create a new app, fill in the required basic information (names, descriptions, developer, website, privacy and terms URLs), and under App features → Bot select your existing Azure Bot or paste its App ID. Tick the Personal, Team, and Group chat scopes. Under Permissions add the seven resource-specific permissions from Teams permissions. For group chats:
ChatMessage.Read.Chat, ChatMember.Read.Chat, ChatSettings.Read.Chat, TeamsAppInstallation.Read.Chat. For team channels: ChannelMessage.Read.Group, TeamMember.Read.Group, TeamsAppInstallation.Read.Group. Together they let the agent keep the whole transcript of a group chat, see who is in it, read what was said before it joined, and know which permissions the chat granted. The package the dashboard offers already declares all seven. Add a 192×192 color icon and a 32×32 outline icon, then either Publish to org for admin approval or Download app package for a manual install.7
Verify
In Teams, open Apps → Manage your apps → Upload a custom app and pick the package, or add the published app. Send the bot
hello in a direct message; your agent answers. Mention it in a channel; it answers there.Values and settings
Limits
- One App ID and tenant pair per agent. A second connection for the same pair is refused with
A Teams channel for this bot and tenant is already connected. - Inbound files: 25 MB. In a direct message they always reach the agent; in a group chat or channel they need the optional
Files.Read.Allbelow. See Connect Microsoft Teams for what Teams delivers where. - The client secret expires on the date you chose. When it does, the bot stops answering until you create a new secret and update the channel.
Permissions to set up next
Azure gives the agent its identity. Two more things decide what it can see once it is in a chat, and both are covered in full on Teams permissions.- The seven resource-specific permissions in the Teams app manifest. The package the admin dashboard offers already declares them. Whoever adds the bot to a group chat or a team consents for that chat or team, and no tenant administrator is involved. The grant is taken when the bot is added, so after publishing a new version of the app, remove the bot and add it again in each group chat and team.
- The optional
Files.Read.AllMicrosoft Graph permission. A Microsoft 365 administrator grants it once, with admin consent, on the app registration you created above, and it takes effect within about an hour with no re-add. It is what lets the agent open files people attach in group chats and channels, and the channel card shows No file access until it is granted. It is read-only; Lua never writes to a drive. See Optional tenant-wide permission for the exact steps in Microsoft Entra.
Troubleshooting
The bot never replies
The bot never replies
Check the messaging endpoint is exactly
https://wa.heylua.ai/teams/webhook and was applied, that the Microsoft Teams channel shows as running on the Azure Bot, and that the app password is the secret’s Value, not its ID.This Microsoft Teams workspace isn't connected to a Lua agent yet
This Microsoft Teams workspace isn't connected to a Lua agent yet
Lua received a message for your App ID from a tenant other than the one you entered. Check the tenant ID against Directory (tenant) ID on the app registration; the bot is connected as single-tenant, so only that tenant can reach the agent.
It worked, then stopped
It worked, then stopped
The client secret expired. Create a new one under Certificates & secrets, copy its value, and update the app password on the channel in the admin dashboard.
Next steps
Connect Microsoft Teams
What Teams delivers to the agent, group chats, limits, and proactive sends.
Teams permissions
The seven manifest permissions, the optional file permission, and who consents.
Send proactive messages
Follow up with a person or a group conversation.

