There are different security levels and authentication methods in Microsoft Teams. When an app is installed in Teams, additional security requirements may be necessary for the setup, especially with a stricter security configuration in a tenant in Microsoft 365. Here are the most important points:
1. tenant security levels and SSO
- Tenant: The tenant is the account used by the organization for Microsoft 365, including Teams. Each organization has specific security settings that the IT administrator manages in the Microsoft 365 Admin Center.
- Single Sign-On (SSO): With SSO, users can sign in once and access multiple apps without having to sign in again. For Teams apps, this means that users can use the app directly without having to enter separate credentials.
2. additional approval requirements for SSO with increased security level
If the tenant requires a higher security level, it may be necessary for the IT administrator to approve the app in advance and set up additional authentication measures. These additional requirements can be
- Multi-factor authentication (MFA): Users must enter not only their password, but also a second level of security (e.g. a code via an authenticator app or SMS).
- Conditional access policies: Access to the Teams app or login via SSO may be restricted based on device, location or other factors.
3. SSO URL (in this case webchat.inwebco.com)
The SSO URL refers to the authentication server used to log in. With the URL webchat.inwebco.com, authentication is routed via this server so that the application in Teams can access the user information of the Microsoft account directly and enables login to the provider via SSO.
4. approval process for the app in Microsoft Teams
If an app uses a specific URL for SSO, the administrator can configure additional permissions to:
- Add the app to the approved app list, which is especially required for custom apps.
- Allow access to the service only for specific user groups or roles.
So if the stronger security level is active in the tenant, the administrator could additionally specify that only users from certain groups are allowed to use WebChat with SSO or that explicit approval from the administrator is required before users can install and use it.