DaemonLayer Logo
Microsoft Teams

Approval cards in Microsoft Teams that reach the right technician

Approval and urgent-ticket cards post to the Teams channels your team already watches — and the technician who owns the ticket gets @mentioned, so nothing sits unclaimed while an approval quietly counts down.

N
Nordic Systems L2 Network · General
DaemonLayer
DaemonLayer Bot 9:41 AM
Approval needed
@Sara Lindqvist — a workflow is waiting for your approval.
Ticket#2044
ClientMeridian Health
WorkflowPassword Reset
UrgencyHigh
Reset password & send temporary credentials to the verified requester.
👍 1 Assigned to Sara Lindqvist
Optional & additive

Cards already post to Teams. This makes them personal.

Your Teams channels can receive approval and urgent-ticket cards on their own — connect a channel and they start arriving, no Microsoft consent required. The Teams integration is the extra step that turns a card in a shared channel into a personal ping for the technician who owns the ticket.

  • Route by queue — L1, L2, and onboarding each get their own channel
  • Deterministic routing on queue, client, and urgency — no AI deciding
  • Channel webhooks are stored encrypted and masked after saving
Webhook only
Card posts to the channel
Sara Lindqvist, an approval is waiting.
No personal ping
Webhook + integration
Card posts to the channel
@Sara Lindqvist, an approval is waiting.
Technician notified
Technician @mentions

The approval reaches a person, not just a channel

When a Human-in-the-Loop approval expires before anyone claims it, the ticket falls back to the service desk. DaemonLayer @mentions the technician assigned to the ticket, so the right person is notified personally — even though the card sits in a shared channel.

It matches on email and caches the result, so every mention after the first is instant.

Resolving the mention
PSA assignee email
User.ReadBasic.All → Entra Object ID
7f3a…c19b
Mention entity on the card
@Sara Lindqvist
No match? The card still posts — just without the mention.
Consent & permission

One consent, in your own tenant. One permission.

There's no Azure app to register. You grant a shared enterprise app consent once, as a Global Admin, in your own MSP tenant — never in a client's. It asks for a single read-only permission and nothing else, so it's a clean line item on any security review.

It never reads mailboxes, posts messages, or touches your channels directly.

Requested permission Application
User.ReadBasic.All Resolve email → Entra Object ID (basic profile) for the @mention
× No mailbox access
× Never posts messages
× No direct channel access
Your MSP tenant only · never client tenants

Notification routing

Teams, Slack, email, and the in-app bell — in one place

Team channels connect a Teams or Slack channel to the queues that team owns. System alerts still reach your notification email and the in-app bell. It all lives under Notification Settings.

Frequently Asked Questions

Common questions about this integration

Do I need to register an Azure app for this?

No. DaemonLayer provides a shared enterprise application. You grant it consent in your tenant with a single Global Admin click — the same one-click admin-consent model as the Microsoft 365 Email integration. No client ID, secret, or tenant ID is entered by hand; DaemonLayer records your tenant ID from the consent response.

Do I need this integration to post to Teams channels at all?

No — this integration is optional and additive. Teams channel delivery works on its own: you connect a channel by pasting its incoming webhook URL under Notification Settings, and approval and urgent-ticket cards post there without any Microsoft consent. The Teams integration only adds the ability to @mention the assigned technician on those cards.

Is this the same as the Microsoft 365 connections for my clients?

No. Your client M365 connections (password resets, onboarding, and so on) authenticate against a customer's tenant. This one authenticates against your own MSP tenant and is used only to look up your technicians' Microsoft identities so they can be mentioned. It never touches client tenants.

What permission does DaemonLayer actually get?

A single application permission: User.ReadBasic.All. That lets DaemonLayer resolve a technician's email to their Entra Object ID from their basic profile. It never reads mailboxes, never posts messages, and never accesses Teams channels directly — card delivery happens entirely through the incoming webhook URLs you configure.

Why isn't a specific technician being mentioned?

Mentions are matched by email: the assignee's PSA email must match a user in your Entra tenant. If the integration isn't connected, the assignee has no email on record, or the lookup fails, the card still posts — just without the mention. A card is never delayed or dropped because a mention couldn't be resolved.

What happens if I disconnect?

Approval cards keep posting to your channels, without mentions. Technician Object IDs already cached remain and are still used; they're only refreshed while the integration is connected. To restore mentions after revoking consent, click Reconnect Microsoft 365 to grant consent again.

Automate your first ticket in under 30 minutes

Connect your PSA, and DaemonLayer starts triaging, resolving, and routing, no scripting, no setup calls. Cancel anytime.

Prefer a walkthrough? Book a demo →