Microsoft Teams Virtual Meeting Integration

Microsoft Teams Virtual Meeting Integration within Absorb provides Admins a way to manage all virtual meeting creations, updates, and deletions for Instructor-Led Course (ILC) Sessions from within the LMS, without entering or adjusting anything within Microsoft Teams. Learners can launch and participate in virtual ILCs within the LMS or from their calendar invitation, even as guests on the Teams tenant.

Authenticating Admin Advisory

Before authenticating the Microsoft Teams Integration, confirm you have set up a shared or corporate account with the correct permissions. Configuring this integration with a single or private User account may cause permissions issues when editing items such as Teams Sessions. This is because all Teams Meetings created via the integration are created on behalf of (and owned by) the User who authenticated the integration.

 

Getting Started

You can enable the Microsoft Teams Virtual Meeting Integration within your Absorb LMS Portal by adjusting the Portal Settings. Once enabled, a Venue can be created and attached to ILC Sessions.

Animated overview of the Microsoft Teams Virtual Meeting Integration in Absorb LMS

 

Step 1: Setting Up Microsoft Teams

Work with your Microsoft Teams Tenant Administrator to register and configure an app in your Azure portal. Keep the following in mind before you begin:

  • Add a registered app via Manager from your Microsoft Teams account in the Azure portal.
  • When adding the LMS URL, include the extension /Admin/VirtualMeetingsOAuth/Callback.
  • Punctuation and case (the capitalization of letters) are important and must match exactly as written. For example, the full path looks similar to https://routename.myabsorb.com/Admin/VirtualMeetingsOAuth/Callback.

 

Important Note

When setting up your Microsoft Teams integration with Azure, you must set up Redirect URIs.

 

How to Create an App Registration in Azure Portal

Follow the steps below to create and configure the app registration. Leave the Azure portal open until you complete Step 2. For more details, see the Microsoft documentation article.

  1. Go to your Microsoft Teams account in the Azure portal and click App registrations.

    App registrations option in the Azure portal

     

  2. Click New registration.

    New registration button on the App registrations page in Azure

     

  3. Set up the registration:

    Register an application form in Azure

     

    1. Set the Name to Absorb LMS Integration.
    2. Select the supported account type Accounts in this organizational directory only.
    3. Add the Redirect URI. A Redirect URI must be added for each Route set up in the LMS. If you have more than one Portal Route set up, contact your Client Success Manager (CSM) or Absorb Support to obtain a list of active Routes. Add one of the Redirect URIs now in the Redirect URI field in Azure:
      1. Select Web in the dropdown.

        Web platform selected in the Redirect URI dropdown in Azure

         

      2. Enter the Redirect URI, replacing {domain-name} with the LMS Route: https://{domain-name}/Admin/VirtualMeetingsOAuth/Callback
    4. Click Register at the bottom of the page.

      Register button at the bottom of the Register an application page in Azure

       

    If you have additional Routes set up in the LMS, complete the following:

    1. Navigate back to the new App Registration.

      Navigating back to the Absorb LMS Integration app registration in Azure

       

      Absorb LMS Integration app registration details in Azure

       

      Redirect URI configuration area of the app registration in Azure

       

    2. Add all additional Redirect URIs from the LMS Routes table.

      Additional Redirect URIs added to the app registration in Azure

       

  4. Copy the Application (Client) ID and Directory (Tenant) ID. You will use these values when enabling Microsoft Teams Virtual Meeting in the LMS.

    Application (Client) ID and Directory (Tenant) ID on the app registration overview in Azure

     

  5. Create a client secret:

    1. Click Certificates & Secrets in the sidebar.
    2. Add a new client secret.
    3. Enter a description. The default expiry should be fine.

    Certificates and Secrets page in Azure

     

    Add a client secret panel with description and expiry fields in Azure

     

  6. Copy the client secret Value. This is required for configuring the LMS.

    Note: Make sure to copy the Client Secret Value (not the ID) before leaving the page. Once you leave the page, the Value is hidden.

    Client secret Value column in Azure

     

  7. Now that the App Registration is created, click Roles and Administrators on the left-hand side. There will likely only be a Cloud Application Administrator role, so you will need to create a new custom read only role. To create this role, follow the steps below:

    Roles and Administrators page for the app registration in Azure

     

    1. Navigate to the Roles page by clicking the link that appears above the roles.
    2. Click New Custom Role.
    3. Name the role Read Only Admin.

      New Custom Role option on the Roles page in Azure

       

    4. Navigate to Permissions. Permissions appear in the format microsoft.directory/(Permission Set Names)/read, and may also end in update, delete, and so on. There may also be other values between the Permission Set Names and the endings. Focus on selecting permissions that have the Permission Set Names listed in the next step and end in read.

      Permissions list for a new custom role in Azure

       

    5. Select all permission sets that end in read for the following: Application Policies, Applications, Audit Log, Connector Groups, Connectors, Groups, and Users.
    6. Click Next at the bottom of the page.
    7. Click Create. A full list of roles appears.
    8. Click your new read only role.
    9. Click Add Assignment.

      Add Assignment option for the custom role in Azure

       

      Read Only Admin role assignment page in Azure

       

    10. Search for Absorb LMS Integration and select it.
    11. Click Add at the bottom of the page.

      Absorb LMS Integration selected for the role assignment in Azure

       

  8. Go back to App Registration and click API Permissions on the left-hand side. Set the configured permissions as listed below.

    API Permissions page for the app registration in Azure

     

    1. Click Add a permission.
    2. Click Microsoft Graph.

      Microsoft Graph option in the Request API permissions panel in Azure

       

    3. Select the following permissions: Directory.Read.All, offline_access, OnlineMeetingArtifact.Read.All, OnlineMeetings.ReadWrite. If your Portal uses the reduced permission set (see Step 2), select User.ReadBasic.All instead of Directory.Read.All. All other permissions are unchanged.
    4. Click Add permissions at the bottom of the screen.
    5. On the API Permissions page, click the check mark for Grant Admin Consent.

      Grant Admin Consent option on the API Permissions page in Azure

       

  9. Click Overview in the left-hand menu to return to the App Registration.

 

Step 2: Setting Up the LMS

The Microsoft Teams Integration is available to add to an organization's LMS from the Info Tab of Portal Settings.

If you want to use the Teams Co-Organizer Functionality, we recommend that you enable the following Portal Settings toggle and save the Portal Settings page before enabling the Teams Integration.

Co-Organizer toggle on the Portal Settings page

 

Confirm If You Need the Co-Organizer Functionality

The User who enabled the integration is always the Organizer for the meeting. For multiple Instructors to have Permissions in the Teams meeting, the Co-Organizer Functionality must be enabled.

 

Enable Reduced Permission Set for Microsoft Teams Integration

If your organization's security policy does not permit Directory.Read.All, the Enable reduced permission set for Microsoft Teams integration toggle in Portal Settings makes the integration request User.ReadBasic.All instead. The toggle appears above the Co-Organizer toggle. Turning it on also turns Co-Organizer on and disables the Co-Organizer toggle on the page.

Set this toggle before you enable the Teams Integration. If the integration is already enabled, follow these steps:

  1. Disable the integration.
  2. Change the toggle.
  3. Save Portal Settings.
  4. Re-enable the integration.
  5. Re-authenticate the integration.

 

Before Changing This Toggle

Because this toggle turns on Co-Organizer, review Step 4: Using the Co-Organizer Functionality before you turn it on. When you re-authenticate, use the same account that originally set up the integration. If a different User re-authenticates, existing Sessions can only be managed by the original organizer. For more information, see Changing the Authenticating User below.

 

Enable the Microsoft Teams Integration

Turning the Enable Microsoft Teams toggle on displays the following options:

  • App ID: Enter the Application (Client) ID value you copied in step 4 of Step 1.
  • Tenant ID: Enter the Directory (Tenant) ID value you copied in step 4 of Step 1.
  • Client Secret: Enter the client secret Value you copied in step 6 of Step 1.

Once all the required IDs and values are entered, click Enable and then Save. You may be prompted to accept permissions from Microsoft to complete the setup.

Important Notes: Keep the following in mind during setup:

  • During the Setup process, ensure a System Admin has logged in to the Portal and proceeds through the integration process. The System Admin must log in to the Portal manually, not via Single Sign-On (SSO).
  • Absorb Client Advocacy and Support cannot enable, disable, or authenticate the integration. If a Client Advocacy or Support member attempts to enable it, the Teams Integration returns an error.
  • To add a new secret value, you must first disable the integration to trigger the prompt for a new secret value. To disable the integration, go to your Portal Settings and click Disable on the Microsoft Teams integration.

    Disable button for the Microsoft Teams integration in Portal Settings

 

Step 3: Create Your Venue

Create a Venue with the Teams Meeting type so it can be attached to ILC Sessions. For more information, see Instructor Led Courses: Venues.

  1. Click Courses in the Admin Menu.
  2. Click Venues in the sub-menu. The Venues administration page opens.
  3. Click Add Venue in the right-hand action menu. The Add Venue form opens.
  4. Complete the following fields:
    • Name: Enter the Venue's name. The name identifies the Venue to Learners and Admins and is visible in both the Admin and Learner experiences.
    • Description: Enter a description to provide details of the Venue. This is visible in the Admin experience only.
    • Max Class Size: Enter a number to set the maximum class capacity for the facility. This is a required field.
      • The Max Class Size is the default value when creating an ILC Session but can be adjusted on the ILC Session if needed.
    • Type: Click the Type dropdown menu and select Teams Meeting.
    • Department: To restrict this Venue to specific Department Admins, click Select Department to search for and find the Department the Venue belongs to.
      • Adding a Department restricts the Venue to the Admins who manage the identified Departments. Admins of other Departments will not see the Venue as an option when selecting locations for ILC Sessions.
  5. Click Save.

Once the Teams Meeting Venue is created, Admins and Instructors can add it to the ILC Session. When an Admin or Instructor selects the Teams Meeting Venue, a meeting is created in Microsoft Teams and the URL auto-populates within the Session upon clicking Publish.

 

Step 4: Using the Co-Organizer Functionality

Using the Co-Organizer Functionality in the Microsoft Teams Integration ensures that more than one person can manage important settings like meeting options, breakout rooms, and other capabilities in a meeting.

 

Enable Co-Organizer

If you want to use the Teams Co-Organizer Functionality, enable it using the following Portal Settings page toggle:

Co-Organizer toggle on the Portal Settings page

 

To use this functionality, you must re-enable your Teams Integration after turning on the toggle above.

If you are setting up your integration for the first time:

  1. Set the Co-Organizer toggle to on.
  2. Save your Portal Settings.
  3. Return to the Portal Settings page and enable the Teams Integration.

If you already have a working integration:

  1. Disable the Teams Integration.
  2. Set the Co-Organizer toggle to on.
  3. Save your Portal Settings.
  4. Return to the Portal Settings page.
  5. Re-enable your Teams Integration following the instructions in Step 2 above.

If Enable reduced permission set for Microsoft Teams integration is turned on, Co-Organizer is turned on automatically and the Co-Organizer toggle is disabled on the Portal Settings page.

 

Using ILC Sessions with Instructors as Co-Organizers

For the system to recognize your Instructor as a Co-Organizer, ensure that the Instructor's email address is a registered Email Address within your Teams organization account.

When configuring your ILC Session, select the Venue and Instructors as described above. As long as the Instructors are within your Teams organization, they are automatically set as Co-Organizers on the meeting. No process changes are required to use this functionality other than the setup mentioned above.

If your Instructors are not present in your Teams organization, you will receive an error message when adding Instructors.

Co-Organizers can manage some meeting settings, but not others. The following table compares the differences:

Co-Organizer Can Manage Setting Co-Organizer Cannot Manage Setting
  • Access and change meeting options
  • Manage breakout rooms
  • Bypass the lobby
  • Admit people from the lobby during a meeting
  • Lock the meeting
  • Present content
  • Change another participant's meeting role
  • End meeting for all
  • Manage the meeting recording
  • Remove or change the meeting organizer's role

 

Attendance and Meeting Policies

When setting up the Teams Integration, it is important to enable the Azure setting that allows organizers to access attendance records. This allows the autofill function to work in Teams. If this setting is not enabled, organizers may encounter a "No participants are found" error.

To confirm that this setting is enabled:

  1. Navigate to the Teams Admin Center.
  2. Click Meetings.
  3. Click Meeting Policies.
  4. Under the Meeting scheduling section, confirm that the Attendance and engagement report option is enabled.

    Attendance and engagement report option under Meeting scheduling in the Teams Admin Center

 

For more information, see the Microsoft documentation on Teams meeting policies.

Updating Policies After Integration Configuration

If you update the attendance policies after the integration is configured, you will need to uninstall and re-install the integration for the policy changes to be applied.

 

Troubleshooting

Troubleshooting the Microsoft Teams Virtual Meeting Integration often requires action by the System Admin who authenticated the integration at the time of setup.

Re-Authenticating Is Generally Safe

When encountering issues with the Microsoft Teams Integration, it is sometimes worthwhile to re-authenticate the integration. Resolving some configuration concerns, such as switching from a personal email address to a general email address, requires re-authenticating. Absorb LMS should not be affected by re-authentication, and it is generally considered a safe troubleshooting practice.

 

Can't Edit Teams Session

This issue may affect components of the Microsoft Teams Integration beyond Sessions. The most common cause of being unable to edit a Teams Session, or a similar item, relates to the System Admin account that authenticated the integration. The account that authenticated the integration has ownership over Sessions.

The System Admin account used to authenticate and set up the Microsoft Teams Integration has greater access to the integration than other accounts. Accordingly, we recommend authenticating the Microsoft Teams Integration with a group, shared, or corporate account instead of a single or private User account.

This is important because all Teams Meetings created via the integration are created on behalf of (and owned by) the User who authenticated the Microsoft Teams Integration.

 

Changing the Authenticating User

If the User who authenticated the Teams Integration is changed, meaning the integration was disabled and re-enabled by a different User, existing Sessions are still valid but can only be managed by the original organizer. The original organizer is the User who authenticated the integration at the time the Session was created.

 

Domain Name in Azure

The following errors can occur when the domain name is not set up correctly in Azure.

Error: This error can occur while enabling the Microsoft Teams integration in the Client Portal:

Error message displayed when enabling the Microsoft Teams integration

 

This error can occur while creating the virtual meeting:

Error message displayed when creating a Teams virtual meeting

 

Cause: The most common problem with the Teams Integration relates to the domain name. This exact name must be set up in two locations:

  • In the list of Routes in the LMS Portal Settings
  • In Azure

The process works as follows:

  1. The LMS looks at the URL you are using in your browser's address bar.
  2. It uses that domain name to look up the Route in the LMS Routes table.
  3. It sends this domain name to Microsoft when you are connecting to Teams.
  4. Microsoft checks whether the domain name is set up in the list of Redirect URIs. If not, the connection fails.

Note: More than one Route is often set up in the LMS. Make sure you add them all to Azure.

Solution: Add this domain name to the list in Azure. Return to the App Registration in Azure and add the correct Redirect URI for each LMS Route, as described in step 3 of Step 1: Setting Up Microsoft Teams.

Additional causes for this error include:

  • The Client Secret ID was entered in the integration settings in Portal Settings instead of the Client Secret Value.
  • The integration was inactive for 90 days and the authentication token has expired.
  • The Client Secret has expired in Microsoft Azure and a new Client Secret needs to be generated.

To resolve these causes, re-authorize the integration. This corrects the authentication error.

This error can also occur if the Instructor on the Venue does not have the correct permissions to host a virtual meeting in Microsoft Azure. To resolve this issue, update the Instructor's permissions to allow them to host virtual meetings. A re-authorization of the integration should not be required.

 

Service Accounts and Multi-Factor Authentication

The following questions and answers address Multi-Factor Authentication (MFA) with service accounts:

  • Q: How is Absorb able to use the User account to create invites without causing a timeout or triggering MFA?
    • A: Absorb uses client secrets to authenticate, which does not trigger MFA. MFA is typically used when a human performs an interactive authentication via an interface, such as a login screen. When systems authenticate without an interface using a client secret, MFA is not required and does not trigger. The client secret securely identifies one system to the other, so User-level MFA is not required.
  • Q: Are there any cautions around MFA with the service account? Specifically, are any special configurations needed for the service account to prevent issues?
    • A: The service account must have a sufficient level of permission to add an app registration to your Azure portal. Azure app registrations are an easy and powerful way to configure authentication and authorization workflows for a variety of client types. An app registration identifies an app (Absorb), which allows Absorb to authenticate to the Azure portal and create and edit meetings for your Teams integration.
    • Because of the scopes required for the integration, Absorb validates hosts against your active Teams Users when an ILC Session is assigned to an Instructor. This confirms that the Instructor is a valid Teams User and will have all host capabilities once the meeting begins, such as recordings and breakout rooms.

 

Who Is the Organizer for a Teams-Based ILC?

The User who enabled the integration is always the Organizer for the meeting.

For multiple Instructors to have permissions in the meeting, the Co-Organizer function must be enabled.

The Portal does not prevent you from adding multiple Instructors, but unless the Co-Organizer function is enabled, they are not added as Organizers or Co-Organizers.

 

Government Teams Tenant Support

Q: Can a government Teams Tenant be used rather than a corporate Teams Tenant?

A: Absorb does not support Microsoft Graph for US Government L4 or Microsoft Graph for US Government L5 (DOD). Absorb is unable to test other US government national clouds and cannot confirm that they will be supported.

 

Roles and Permissions

This integration requires specific permissions in both Absorb and Azure, as outlined below.

 

Azure Permission Guidance

In Azure, clients must configure permissions for both Administrators and the API. These are discussed further in the following sections.

 

Roles and Administrators

To use the Microsoft Teams Meeting integration effectively, the client Azure tenant needs specific permissions configured. Typically, only the Read-Only Administrator role is required. In most cases, you may also see the Cloud Application Administrator role.

Read-Only Administrator and Cloud Application Administrator roles assigned in Azure

 

API Permissions

The client also needs to configure API permissions. The API and permission names for all configured permissions exist in the Microsoft Graph permission set. The configured or other permissions may not look exactly the same as below, but each line item should appear (User.Read, Directory.Read.All, offline_access, OnlineMeetingArtifact.Read.All, and OnlineMeetings.ReadWrite, or User.ReadBasic.All in place of Directory.Read.All, if the reduced permission set is enabled).

Configured Microsoft Graph API permissions for the app registration in Azure

 

  • Directory.Read.All: Used to access user data to verify that the Instructors provided are valid hosts. Absorb performs a lookup to ensure a user with the Instructor's email exists in Microsoft.
  • User.ReadBasic.All: Performs the same Instructor lookup as Directory.Read.All, using a narrower permission. Requested in place of Directory.Read.All when the reduced permission set is enabled in Portal Settings.
  • offline_access: A standard OpenID Connect (OIDC) scope requested so that the app can get a refresh token. For more information, see the Microsoft documentation on getting access on behalf of a user.
  • OnlineMeetingArtifact.Read.All: Allows Absorb to read meeting artifacts (attendance reports) on the organization's behalf. This is required for the auto attendance marking feature.
  • OnlineMeetings.ReadWrite: Allows Absorb to create, update, delete, and retrieve details of meetings. This enables the core Microsoft Teams integration to operate.
  • User.Read: Not a required permission.

 

Instructor and Co-Organizer Assignments

There must be an exact match between the Email (not the Username) in Absorb and the email in the Azure user details for Instructor and Co-Organizer assignments to work. If there is no match to the email in Azure, a secondary check for a match to the User Principal Name (UPN) is done. An Instructor or Co-Organizer must have Host permissions in Teams to be able to create Teams Sessions in Absorb.

 

Required Permissions

Once all permissions are correctly configured in Azure and admin consent has been granted, no additional permissions are needed for the authorizing account because access is already provided through the app integration itself. The setup uses specific Microsoft Graph permissions to enable secure communication between systems, and in most environments the Read-Only Administrator role is sufficient for operation. However, if an organization has restrictive security controls, an Azure administrator may need to assign extra permissions to allow authorization to complete. We recommend confirming with your IT department that their policies permit the connection before activation.

 

Absorb Permissions

System Admins are the only Admins who can adjust settings within Portal Settings. Once the Microsoft Teams Integration options have been toggled on, all other Admins need the following permissions.

 

Required Role Permissions

You may need to adjust permissions. For more information, see Admin Roles & Permissions.

Role: Section Access Permission(s) Needed
Courses > Venues View or Modify permission
Courses > Instructor-Led Courses > Sessions Add, View, or Modify permission

 

Suggested Role Permissions

The following permission is suggested for Admins who work with this integration:

Role: Section Access Permission(s) Needed
Users View or Modify permission

 

Was this article helpful?
8 out of 13 found this helpful

Comments

0 comments

Article is closed for comments.