Axiomancer
Integrations

Microsoft Teams

Connect Microsoft Teams to Layer to inventory teams, channels, members, and per-user activity for collaboration governance and offboarding workflows.

The Microsoft Teams integration syncs every team in your tenant, the unique members across those teams, and a 30-day activity report so you can see which users actually use Teams. It's the companion to Microsoft 365 — connect both for full coverage of the directory and the collaboration surface.

What you'll need

  • Microsoft 365 Teams Administrator or Global Administrator role.
  • Two minutes.

Set it up

Open the Microsoft Teams integration in Layer

In Layer, go to Integrations, find Microsoft Teams, and click Connect.

Sign in with your admin account

You'll be redirected to Microsoft's sign-in. Use a Teams Administrator or Global Admin account for the tenant you want to connect.

Microsoft will list the requested scopes. Tick Consent on behalf of your organization and click Accept.

Scopes requested:

  • Team.ReadBasic.All — list every team in the tenant
  • Channel.ReadBasic.All — read channel metadata
  • TeamMember.Read.All — read team membership
  • TeamSettings.Read.All — read team configuration
  • Reports.Read.All — read Teams user activity reports (last sign-in per user)

Wait for the first sync

The initial sync enumerates all teams, deduplicates members across them, and pulls the 30-day activity report. Typically finishes in 5–15 minutes.

What gets synced

ObjectFieldsRefresh cadence
Teamsid, display name, visibilityEvery 6 hours
Membersemail, display name, Microsoft user ID, last Teams activityEvery 6 hours
Microsoft Teams appOne SaaS asset emitted to the Apps viewEvery 6 hours

Members are deduplicated by email across all teams, so a user who sits in 12 teams shows up once in your People view. The last_active_teams field on each user reflects the most recent activity date from the Teams user activity report (D30 window) when Reports.Read.All is granted.

Activity report

If Reports.Read.All consent was granted, Layer pulls the Teams user activity user detail report and records the last activity date per user (UPN). When the scope is missing — for example, on tenants where Reports has been deliberately scoped down — the connector skips the activity call silently and members are still emitted without a last_active_teams value. The connection stays healthy in either case.

Token refresh

Microsoft delegated access tokens expire approximately one hour after they are issued. Layer automatically refreshes tokens in the background each time a sync runs, so your connection stays active without any manual re-authorization. If a refresh fails — for example, because an admin revoked consent in the Azure portal — the connection status changes to needs re-auth and you can reconnect with one click.

Troubleshooting

Was this page helpful?

On this page