Forum Discussion
How to receive app mentions only from a channel, while having the consent to read user messages?
We're building a Teams bot (Azure Bot + Entra app) that a customer adds into a standard Teams channel. Members @mention the bot and it replies in the same thread. To make replies useful, when the bot is mentioned we want to read recent messages in that thread for context, including messages where the bot was not mentioned.
We have two requirements that appear to be in tension, and we'd like your guidance on the best-supported way to satisfy both:
a. Delivery: we want Teams to send our bot only the activities where it is @mentioned (not every channel message), to avoid unnecessary inbound load and Bot Framework rate-limit pressure in busy channels.
b. Context read: on those mention turns, we want to read recent thread messages via Microsoft Graph (/teams/{team}/channels/{channel}/messages/{id}/replies).
We've identified two approaches, each with their drawbacks:
a. RSC (ChannelMessage.Read.Group) - all channel messages; team-scoped & consented by team owner at install (low friction) Concern: RSC forces delivery of every channel message; heavy backend filtering + bot framework rate-limit risk
b. App permission (ChannelMessage.Read.All) - @mention-only; tenant-wide consent; tenant-admin consent Concerns: setup friction (admin consent URL, per app per tenant); read grant spans all standard channels, including ones the app isn't a member of
Our core question: Option 1 gives the delivery we don't want but the scoping we like; Option 2 gives the delivery we want but a tenant-wide read grant we'd prefer to avoid. Specifically:
- Is there any supported way to keep @mention-only delivery and a channel-scoped (RSC-style) read grant, i.e. decouple RSC's message delivery from its read authorization?
- Can the tenant-wide read in Option 2 be narrowed to specific teams/channels (e.g., via a Teams application access policy or any resource-scoping mechanism), so the app can only read where it's intended to operate?
- Given our two requirements, which approach does Microsoft recommend, and is there any option we've missed?
TIA!
1 Reply
The two behaviors cannot currently be separated with that RSC permission. Microsoft documents that ChannelMessage.Read.Group lets a bot receive channel messages even when it is not mentioned. It is also the least-privileged application permission for reading that team’s channel messages and replies through Graph.
ChannelMessage.Read.All grants organization-wide application access. Microsoft does not document a Teams application access policy that narrows it to selected teams or channels, so it is unsuitable when team-level isolation is mandatory.
The supported least-privilege design is to install the app only in intended teams, request ChannelMessage.Read.Group there, and discard non-mention activities before expensive processing. When mentioned, use the team, channel, and root-message identifiers to fetch only that thread’s replies. Avoid storing unrelated message bodies and explain the behavior to the consenting owner. If mention-only delivery is absolute, omit RSC; the bot then cannot app-only read unmentioned thread history. Delegated access would be a different, user-dependent design