Microsoft Teams
Connect Microsoft Teams to Layer to inventory teams, channels, members, and per-user activity for collaboration governance and offboarding workflows.
The Microsoft Teams integration syncs every team in your tenant, the unique members across those teams, and a 30-day activity report so you can see which users actually use Teams. It's the companion to Microsoft 365 — connect both for full coverage of the directory and the collaboration surface.
What you'll need
- Microsoft 365 Teams Administrator or Global Administrator role.
- Two minutes.
Set it up
Open the Microsoft Teams integration in Layer
In Layer, go to Integrations, find Microsoft Teams, and click Connect.
Sign in with your admin account
You'll be redirected to Microsoft's sign-in. Use a Teams Administrator or Global Admin account for the tenant you want to connect.
Grant tenant-wide admin consent
Microsoft will list the requested scopes. Tick Consent on behalf of your organization and click Accept.
Scopes requested:
Team.ReadBasic.All— list every team in the tenantChannel.ReadBasic.All— read channel metadataTeamMember.Read.All— read team membershipTeamSettings.Read.All— read team configurationReports.Read.All— read Teams user activity reports (last sign-in per user)
Wait for the first sync
The initial sync enumerates all teams, deduplicates members across them, and pulls the 30-day activity report. Typically finishes in 5–15 minutes.
What gets synced
| Object | Fields | Refresh cadence |
|---|---|---|
| Teams | id, display name, visibility | Every 6 hours |
| Members | email, display name, Microsoft user ID, last Teams activity | Every 6 hours |
| Microsoft Teams app | One SaaS asset emitted to the Apps view | Every 6 hours |
Members are deduplicated by email across all teams, so a user who sits in 12 teams shows up once in your People view. The last_active_teams field on each user reflects the most recent activity date from the Teams user activity report (D30 window) when Reports.Read.All is granted.
Activity report
If Reports.Read.All consent was granted, Layer pulls the Teams user activity user detail report and records the last activity date per user (UPN). When the scope is missing — for example, on tenants where Reports has been deliberately scoped down — the connector skips the activity call silently and members are still emitted without a last_active_teams value. The connection stays healthy in either case.
Token refresh
Microsoft delegated access tokens expire approximately one hour after they are issued. Layer automatically refreshes tokens in the background each time a sync runs, so your connection stays active without any manual re-authorization. If a refresh fails — for example, because an admin revoked consent in the Azure portal — the connection status changes to needs re-auth and you can reconnect with one click.
Troubleshooting
The connector silently skips the activity report when Reports.Read.All is not granted. Reconnect from Integrations → Microsoft Teams and approve the full scope set on the consent screen.
Private teams require explicit membership for the consenting admin or tenant-wide read consent. Confirm Team.ReadBasic.All was approved at the tenant level rather than for a single user.
Go to Integrations → Microsoft Teams → Disconnect in Layer. To fully revoke, also remove the Axiom app from Enterprise Applications in the Azure portal.
Slack
Connect a Slack workspace to Layer with one-click OAuth to discover installed apps, Slack Connect partners, channel activity, and member counts.
Notion
Connect a Notion workspace to Layer with one-click OAuth to inventory the workspace, its members, and installed apps without pasting any API tokens.