This standalone release introduces a reduced permission set option for the Microsoft Teams Virtual Meeting Integration.
This release adds a new Portal Settings option to the Microsoft Teams Virtual Meeting Integration. The option lets the integration request a narrower Microsoft Graph permission when validating Instructors.
Who's affected: Portals using the Microsoft Teams Virtual Meeting Integration
Default state: Off by default
Admin control: Toggle available to System Admins in Portal Settings
Introducing a new option for organizations that need to limit the Microsoft permissions granted to the Microsoft Teams Virtual Meeting Integration.
Reduced Permission Set for Microsoft Teams Integration
The new Enable reduced permission set for Microsoft Teams integration toggle makes the integration request User.ReadBasic.All instead of Directory.Read.All. This option is designed for organizations whose security policy does not permit Directory.Read.All.
When the toggle is turned on, the integration requests the following Microsoft Graph permissions:
offline_accessOnlineMeetings.ReadWriteOnlineMeetingArtifact.Read.AllUser.ReadBasic.All
User.ReadBasic.All performs the same Instructor lookup as Directory.Read.All, confirming that an Instructor's email address matches a user in your Microsoft tenant, but uses a narrower permission.
How the Toggle Works with Co-Organizer
The toggle appears in Portal Settings, above the Co-Organizer toggle. Turning it on also turns Co-Organizer on and disables the Co-Organizer toggle on the page. With Co-Organizer on, Instructors within your Teams organization are automatically set as Co-Organizers on meetings.
If your organization does not currently use the Co-Organizer Functionality, turning on this toggle sets your Instructors as Co-Organizers on Teams meetings. Review the Co-Organizer section of the Microsoft Teams Virtual Meeting Integration article before turning it on.
Configuring Azure
If you use the reduced permission set, select User.ReadBasic.All instead of Directory.Read.All when setting the API permissions for your app registration in Azure. All other permissions are unchanged.
Re-Authentication Required
You must re-authenticate the integration after turning the toggle on or off. For new integrations, set this toggle before you enable the Teams Integration. If the integration is already enabled, follow these steps:
- Disable the integration.
- Change the toggle.
- Save Portal Settings.
- Re-enable the integration.
- Re-authenticate the integration.
Re-authenticate with the same account that originally set up the integration. If a different User re-authenticates, existing Sessions remain valid but can only be managed by the original organizer.
For full setup instructions, see Microsoft Teams Virtual Meeting Integration.
Comments
Article is closed for comments.