- Creating the app registration
- Creating a client secret
- Granting the Graph API permissions the pipeline needs
- Admin-consenting those permissions
- (Optional) Scoping the app to specific users with an Application Access Policy
~/.mibyan/.env at the end.
Prerequisites
- A Microsoft 365 tenant with Teams Premium or Teams licenses that produce meeting transcripts and recordings
- Admin access to the Azure portal at entra.microsoft.com
- A publicly reachable HTTPS endpoint for Graph change notifications (set up later, in the webhook listener step)
Step 1: Create the App Registration
- Sign in to entra.microsoft.com as a tenant admin.
- Navigate to Identity → Applications → App registrations.
- Click New registration.
- Fill in:
- Name:
Mibyan Teams Meeting Pipeline(or any name you’ll recognize). - Supported account types: Accounts in this organizational directory only (Single tenant).
- Redirect URI: leave blank — app-only auth does not need one.
- Name:
- Click Register.
- Application (client) ID →
MSGRAPH_CLIENT_ID - Directory (tenant) ID →
MSGRAPH_TENANT_ID
Step 2: Create a Client Secret
- In the left nav, open Certificates & secrets.
- Click New client secret.
- Description:
mibyan-graph-secret. Expires: pick a value that matches your rotation policy (6-24 months is typical). - Click Add.
- Copy the Value column immediately — it’s only shown once. That value is
MSGRAPH_CLIENT_SECRET.
The Secret ID column is not the secret. You want the Value column.
Step 3: Grant Graph API Permissions
The pipeline uses a minimum-viable set of application permissions. Add only what you need; each one widens what the app can read tenant-wide.- In the left nav, open API permissions.
- Click Add a permission → Microsoft Graph → Application permissions.
- Add the permissions from the table below that match what you want the pipeline to do.
- After adding, click Grant admin consent for
<your tenant>. The Status column should flip to a green checkmark for every permission.
Required for transcript-first summaries
Required for recording fallback (when a transcript is unavailable)
Required for outbound summary delivery (Graph mode only)
Ifplatforms.teams.extra.delivery_mode is graph, the pipeline posts summaries into a Teams channel or chat via the Graph API. Skip these if you use incoming_webhook delivery mode instead.
Not recommended
OnlineMeetings.ReadWrite.All/Chat.ReadWritewithout.All— broader than the pipeline needs.- Delegated permissions — the pipeline uses app-only (client-credentials) flow; delegated permissions won’t work without user sign-in.
Step 4: (Recommended) Scope the App with an Application Access Policy
By default, application permissions likeOnlineMeetings.Read.All grant the app access to every meeting in the tenant. For partner demos and dev tenants that’s fine; for production you almost certainly want to restrict which users’ meetings the app can read.
Microsoft provides Application Access Policies for Teams exactly for this. The policy is a PowerShell-only surface; there’s no portal UI for it.
From an admin PowerShell with the MicrosoftTeams module installed and connected (Connect-MicrosoftTeams):
Step 5: Write the Credentials to Your Env File
Put the three values you collected into~/.mibyan/.env:
Step 6: Verify the Token Flow
Mibyan ships a Graph auth smoke-test. From your Mibyan install:cached: True and an expires_in_seconds value near 3600. Failures produce a MicrosoftGraphTokenError with the Azure error code — the most common are:
Rotating the Client Secret
Azure client secrets have a hard expiry. Before yours expires:- Create a second client secret in step 2 without deleting the first one.
- Update
MSGRAPH_CLIENT_SECRETin~/.mibyan/.envwith the new value. - Restart the gateway so the new secret is picked up:
mibyan gateway restart. - Verify with the smoke test above.
- Delete the old secret from the Azure portal.
Next Steps
Once credentials verify cleanly, continue with:- Webhook listener setup — stand up the
msgraph_webhookgateway platform that receives Graph change notifications. - Pipeline configuration — configure the Teams meeting pipeline runtime and operator CLI.
- Outbound delivery — wire summaries back into a Teams channel or chat.

