Microsoft Teams
Introduction
This guide explains how to authenticate the Microsoft Teams connector in Swimlane using one of the following authentication methods:
- OAuth 2.0 Client Credentials (Application permissions)
- OAuth 2.0 Password Grant (Delegated permissions)
- OAuth 2.0 Refresh Token Grant (Delegated permissions with MFA)
You will create an Azure app, assign permissions, collect the required identifiers, and configure the connector inside Swimlane.
Prerequisites
Azure Access Requirements
- Register applications in Azure Active Directory
- Assign API permissions (Application + Delegated)
- Grant admin consent
- View tenant and directory information
- Create client secrets
Required Credentials
- Client ID
- Client Secret
- Tenant ID
- Token URL
- Scope
- (For delegated auth) Username and Password
- (For refresh token flow) Refresh Token
Authentication Methods Overview
OAuth 2.0 Client Credentials
Used for non-MFA accounts and for most server-to-server automations.
You will need:
- Client ID
- Client Secret
- Tenant ID
- Token URL (must include Tenant ID)
- Scope(s)
OAuth 2.0 Password Grant (Delegated)
Used when the connector must act on behalf of a user.
You will need:
- Username
- Password
- Client ID
- Client Secret (optional)
- Token URL
- Scope(s)
OAuth 2.0 Refresh Token Grant (Delegated + MFA)
Use when the Teams or Microsoft 365 account has MFA enabled.
You will need:
- Client ID
- Client Secret
- Refresh Token
- Tenant ID
- Redirect URI (added during Azure App Registration)
Azure Setup
Register the application
- Go to Azure Portal > Azure Active Directory > App registrations.
- Click New registration.
- Enter an application name.
- Select Accounts in this organizational directory only.
- Click Register.
Assign API permissions
- Open API permissions.
- Click Add a permission.
- Select Microsoft Graph.
- Add the required permissions based on your Microsoft Teams actions:
- ChannelMember.ReadWrite.All
- TeamMember.ReadWrite.All
- Channel.Create
- Channel.Create.Group
- Directory.ReadWrite.All
- Group.ReadWrite.All
- Team.Create
- Teamwork.Migrate.All
- Click Add permissions.
- Click Grant admin consent for your organization.
Create a Client Secret
- Navigate to Certificates & secrets.
- Click New client secret.
- Add description and expiration.
- Click Add.
- Copy and save the secret value.
Collect required identifiers
- Client ID
- Tenant ID
Password Grant Requirements
- oauth2_username β Azure username
- oauth2_password β Azure password
If MFA is enabled, use Refresh Token Flow instead.
Refresh Token Flow Setup
- Add a Redirect URI (Platform: Web) during registration.
- Assign Delegated Permissions.
- Use the Swimlane-provided Python script to generate a refresh token.
Connector Configuration in Swimlane
- Log into Turbine.
- Click ORCHESTRATION.
- Click Assets.
- Click the + icon to create a new asset.
- Select Microsoft Teams from the Asset Type list.
- Fill in the Asset Settings and Asset Input as shown as per your authentication method:
Configuration - Client Credentials
Field | Description | Required |
|---|---|---|
url | API endpoint | Required |
token_url | Token URL | Required |
client_id | Client ID | Required |
client_secret | Client Secret | Required |
scope | Permission scopes | Required |
verify_ssl | SSL verification | Optional |
http_proxy | Proxy details | Optional |
Fields with * marks are required.Β Β
Token URL format:

Configuration - Password Grant (Delegated Authentication)
Field | Description | Required/Optional |
|---|---|---|
url | API endpoint | Required |
token_url | Token URL | Required |
oauth2_username | Username | Required |
oauth2_password | Password | Required |
client_id | Client ID | Required |
client_secret | Client Secret | Optional |
scope | Delegated scopes | Required |
verify_ssl | SSL verification | Optional |
http_proxy | Proxy details | Optional |
Fields with * marks are required.Β Β

Configuration - Refresh Token Grant (Delegated + MFA)

Field | Description | Required/Optional |
|---|---|---|
url | API endpoint | Required |
tenant_id | Tenant ID | Required |
cl_id | Client ID | Required |
cl_secret | Client Secret | Required |
refresh_token | Refresh Token | Required |
verify_ssl | SSL verification | Optional |
http_proxy | Proxy details | Optional |
Fields with * marks are required.Β Β
- Click Create.
Troubleshooting
Error: 403 Forbidden
Occurs when:
- Missing Graph or Teams permissions
- Missing admin consent
- Incorrect tenant or token URL
- Using Application permissions where Delegated is required
Fix:
- Re-grant admin consent
- Verify permissions
- Ensure token URL includes the correct tenant ID
You have successfully authenticated the Microsoft Teams Connector using one of the supported OAuth flows.Β