Identity and access · sources checked 10 August 2026

Entra ID roles and permissions for live chat in Microsoft Teams

SSO answers how someone signs in. Several other controls decide which customer chat they can see, answer, configure or retain after a role change.

Fact-checked: 6 Verified sources

Four control layers

SSO is not the same as authorisation

Entra establishes identity and can avoid a second agent password. It does not by itself grant the correct support-channel visibility or WebChat configuration rights. The daily agent path follows Teams-channel access; the configuration path also uses WebChat's administrator list.

Approval needs a task matrix rather than a successful login: who reads enquiries, replies externally, writes internal notes, manages membership, changes widget/channel settings or approves the Teams app for the organisation? None of these tasks automatically justifies the highest Microsoft or product role.

Access layers and evidence
LayerWhat it controlsAcceptance test
Entra identitySign-in, account and possible guest stateActive/disabled identity and tenant MFA/Conditional Access
Team and channelThread visibility and participationStandard/private/shared membership and history
Teams roleOwner, member, guest or moderator powersSeparate membership, app, channel and reply tasks
WebChat admin listChannel-specific WebChat configurationListed email plus channel membership and revocation
App/flow identityApproval, connectors, automation or service identityOwner, secret, runtime rights, cover and offboarding

Sources: 1, 2, 3

Channel type

Standard, private and shared channels change the audience

A standard channel is generally visible to team members. A private channel limits access to selected team members. A shared channel can include selected people across teams or organisations. This changes visibility, ownership, guests, apps, storage and revocation.

Microsoft also documents that a newly added private-channel member can see earlier conversations. Removing someone from the team removes their private-channel memberships; if they return, those memberships must be assigned again. Private is therefore not a substitute for need-to-know and retention rules.

Sources: 3, 4, 2

Joiner, mover, leaver

Govern access across every role change

  1. 01

    Constrain joiners

    Assign only the required team and channels; test agent reply, internal note and WebChat administration separately.

  2. 02

    Reassess movers

    Remove old department, brand or country channels and backend-admin rights before granting the new scope.

  3. 03

    Disable leavers

    Disable the Entra account and revoke team, channel, guest, group, app and access-package routes under the real tenant model.

  4. 04

    Close product paths

    Check WebChat admin list, flow owners, connector connections, service accounts, secrets, Meta assets and website/tag-manager access.

  5. 05

    Prove revocation

    After removal, negatively test sign-in, old browser session, Teams Mobile, direct channel link, backend URL and flow/API execution.

Sources: 5, 2, 4

Least-privilege acceptance

Eight role cases before production

  • Agent reads and replies in the intended channel but cannot manage members or WebChat settings.
  • WebChat administrator changes a harmless setting and loses that power after removal from admin list or channel.
  • Team owner manages members without unnecessary tenant-wide Entra or Teams administration.
  • Guest or external participant sees only the explicit surface; reply and history are assessed separately.
  • A user outside the channel cannot reach its thread or backend configuration.
  • A mover loses old brand/country channels and receives only the new scope.
  • A leaver loses web, desktop, mobile, direct links, flow/connector and product administration within target time.
  • At least two accountable owners provide continuity; elevated privileges are time-limited and traceable.

Sources: 6, 5, 3, 2

FAQ

Frequently asked questions

Do WebChat agents need another user account?

The vendor describes Entra SSO and no separate agent-user management for the Teams-channel path. WebChat configuration still has an administrator list, so test agent and administrator access separately.

Can every team member see every customer chat?

A standard channel is generally visible to team members. Private and shared channels have distinct membership. Select by need-to-know and test app and history behaviour.

Is disabling the Entra account enough for offboarding?

It is central, but acceptance should also inspect team/channel membership, WebChat admins, guests, flow owners, connectors, service accounts, secrets and connected systems.

Does operation require a Global Administrator?

The reviewed sources do not justify that as a standing role. Microsoft recommends least privilege. Find the smallest role for each approval, membership and operational task and time-limit elevation.

Verified sources

Sources and review date

  1. 01
    WebChat by inwebco GmbH

    Microsoft Marketplace / inwebco GmbH · Fact-checked:

    Open source
    verified
  2. 02
    Setting Up WebChat: The Complete Guide for Microsoft Teams

    inwebco GmbH · Fact-checked:

    Open source
    verified
  3. 03
    Overview of teams and channels in Microsoft Teams

    Microsoft · Fact-checked:

    Open source
    verified
  4. 04
    Private channels in Microsoft Teams

    Microsoft · Fact-checked:

    Open source
    verified
  5. 05
    Introduction to Microsoft Entra ID Governance deployment guide

    Microsoft · Fact-checked:

    Open source
    verified
  6. 06
    Recoverability best practices in Microsoft Entra ID

    Microsoft · Fact-checked:

    Open source
    verified