Incoming request security #2895
|
Hi teams, our organization wants to adopt Teams Bot at scale but now I am stuck with security team. They require all incoming requests must pass APIM check. The APIM gateway only allows token issuer by our own application registration. However, I believe issuer of Teams token is |
Replies: 1 comment
|
Hi Bao Tran (@n1340t), since you're using a cross-tenant system with User managed Identity, I recommend configuring APIM to validate Bot Framework token directly. Make sure to confirm exact
Other options that would be less suitable:
Some links:
Hope this helps :) |
Hi Bao Tran (@n1340t), since you're using a cross-tenant system with User managed Identity, I recommend configuring APIM to validate Bot Framework token directly.
Make sure to confirm exact
audandissclaims for your bot. For User Managed Identity, I believe the audience is your MI's client ID, but w…