Teams won't talk to Azure Bot Messaging endpoint

%3CLINGO-SUB%20id%3D%22lingo-sub-2691631%22%20slang%3D%22en-US%22%3ETeams%20won't%20talk%20to%20Azure%20Bot%20Messaging%20endpoint%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2691631%22%20slang%3D%22en-US%22%3E%3CP%3EThe%20%22Web%20Chat%22%20channel%20works%20fine%2C%20but%20the%20%22Microsoft%20Teams%22%20doesn't.%20A%20few%20clues%20as%20to%20what%20might%20be%20going%20on...%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E1)%20If%20I%20point%20to%20an%20ngrok%20tunnel%20that%20goes%20directly%20to%20the%20https%20service%20(haproxy)%20it%20works%20fine.%3CBR%20%2F%3E2)%20I'm%20seeing%20the%20occasional%20portal.azure.com%20pre-flight%20(OPTIONS)%20request%20logged%20against%20the%20service%2C%20but%20nothing%20else.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ESo%2C%20Teams%2FAzure%20Bot%20can%20reach%20the%20service%2C%20and%20it%20would%20seem%20that%20it's%20pretending%20to%20be%20a%20browser%20and%20doing%20CORS%20stuff.%20I've%20permitted%20and%20exposed%20all%20the%20headers%20the%20pre-flight%20is%20asking%20for.%20I%20also%20respond%20with%20the%20required%20specific%20Origin%20-%26gt%3B%20%3CA%20href%3D%22https%3A%2F%2Fportal.azure.com%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3Ehttps%3A%2F%2Fportal.azure.com%3C%2FA%3E%20header%20and%20allow%20authentication%20(because%20Azure%20Bot%20sends%20an%20authorization%20header).%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAny%20ideas%20about%20what%20could%20be%20going%20on%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-2691631%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EDeveloper%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EMicrosoft%20Teams%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2698221%22%20slang%3D%22en-US%22%3ERe%3A%20Teams%20won't%20talk%20to%20Azure%20Bot%20Messaging%20endpoint%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2698221%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F1139235%22%20target%3D%22_blank%22%3E%40stephenmdyoung%3C%2FA%3E%26nbsp%3B%3A%20Hey%20are%20you%20trying%20to%20run%20bot%20from%20local%20or%20have%20you%20deployed%20it%20on%20app%20service%3F%26nbsp%3B%3CBR%20%2F%3EAlso%2C%20the%20endpoint%20you%20are%20giving%20should%20be%20publicly%20accessible%20and%20in%20channels%2C%20it%20should%20be%20connected%20to%20Teams.%26nbsp%3B%3CBR%20%2F%3E%3CBR%20%2F%3EPlease%20have%20a%20look%20at%20this%3A%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fbot-service%2Fchannel-connect-teams%3Fview%3Dazure-bot-service-4.0%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%22%3E%3CFONT%20size%3D%223%22%3EConnect%20a%20bot%20to%20Microsoft%20Teams%3C%2FFONT%3E%3C%2FA%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2705495%22%20slang%3D%22en-US%22%3ERe%3A%20Teams%20won't%20talk%20to%20Azure%20Bot%20Messaging%20endpoint%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2705495%22%20slang%3D%22en-US%22%3EThanks%20%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F1092873%22%20target%3D%22_blank%22%3E%40HunaidHanfee-MSFT%3C%2FA%3E%20-%20but%20yes%2C%20the%20endpoint%20is%20publicly%20available%20and%20the%20bot%20has%20both%20the%20Teams%20and%20Web%20Chat%20channels.%20What's%20more%2C%20the%20relevant%20Microsoft%20services%20must%20be%20seeing%20the%20relevant%20settings%20or%20we%20wouldn't%20be%20seeing%20the%20OPTIONS%20request%20at%20the%20endpoint.%3CBR%20%2F%3E%3CBR%20%2F%3ESteve%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2712612%22%20slang%3D%22en-US%22%3ERe%3A%20Teams%20won't%20talk%20to%20Azure%20Bot%20Messaging%20endpoint%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2712612%22%20slang%3D%22en-US%22%3EAs%20I%20understand%20from%20the%20question%20app%20is%20working%20when%20pointed%20to%20ngrok.%20You%20are%20facing%20problem%20when%20you%20are%20giving%20some%20other%20endpoint.%20%3CBR%20%2F%3EIf%20you%20doing%20it%20locally%20make%20sure%20that%20bot%20is%20running%20and%20ngrok%20or%20other%20endpoint%20should%20point%20to%20the%20same%20port%20on%20which%20local%20bot%20is%20running.%3CBR%20%2F%3E%3CBR%20%2F%3EAlso%2C%20you%20should%20check%20on%20Teams%20web%20client%20and%20look%20console%20for%20errors.%20Please%20make%20sure%20that%20you%20have%20given%20the%20correct%20botId%20in%20the%20manifest.%3CBR%20%2F%3E%3CBR%20%2F%3ECould%20you%20please%20share%20bot%20Id%20and%20timestamp%20when%20you%20faced%20this%20issue%20so%20that%20we%20can%20check%20at%20our%20end%20what%20is%20wrong%3F%3CBR%20%2F%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2714502%22%20slang%3D%22en-US%22%3ERe%3A%20Teams%20won't%20talk%20to%20Azure%20Bot%20Messaging%20endpoint%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2714502%22%20slang%3D%22en-US%22%3EHi%20%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F1092873%22%20target%3D%22_blank%22%3E%40HunaidHanfee-MSFT%3C%2FA%3E%3CBR%20%2F%3E%3CBR%20%2F%3EIndeed%20the%20app%20is%20working%20when%20pointed%20to%20an%20ngrok%20endpoint%2C%20but%20the%20ngrok%20tunnel%20is%20pointed%20directly%20(initiated%20from%20inside%20the%20service's%20VM)%20to%20the%20%22live%22%20socket%20-%20i.e.%20to%20the%20same%20endpoint.%20This%20might%20seem%20to%20indicate%20that%20there%20is%20a%20firewall%20or%20other%20infrastructure%20issue%20blocking%20Teams'%20access%20to%20the%20endpoint%2C%20but%20we've%20eliminated%20that%20possibility.%20We%20can%20see%20the%20Teams%20traffic%20in%20tcpdump%20captures%2C%20*and*%20we're%20capturing%20Teams%20CORS%20OPTIONS%20requests%20at%20the%20endpoint.%3CBR%20%2F%3E%3CBR%20%2F%3Engrok%20uses%20an%20Authorisation%20header%20so%20will%20overwrite%20whatever%20comes%20from%20Azure%2FTeams.%20This%20might%20be%20a%20clue%20to%20what's%20going%20on.%3CBR%20%2F%3E%3CBR%20%2F%3EAs%20you've%20suggested%2C%20I've%20brought%20up%20the%20Teams%20web%20client%20in%20a%20clean%20version%20of%20Firefox%20(no%20blockers%20etc)%20on%20a%20linux%20VM%20and%2C%20for%20sure%2C%20Angular%20is%20spitting%20out%20a%20bunch%20of%20errors.%20There%20is%20plenty%20of%20data%20the%20client%20is%20expecting%2C%20but%20not%20getting.%20e.g.%3CBR%20%2F%3E%3CBR%20%2F%3EXML%20Parsing%20Error%3A%20no%20root%20element%20found%3CBR%20%2F%3ELocation%3A%20%3CA%20href%3D%22https%3A%2F%2Fpresence.teams.microsoft.com%2Fv1%2Fme%2Freportmyactivity%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fpresence.teams.microsoft.com%2Fv1%2Fme%2Freportmyactivity%3C%2FA%3E%3CBR%20%2F%3E%3CBR%20%2F%3EYou%20should%20know%20that%20we%20raised%20a%20ticket%20(Case%20%23%3A27092020)%20for%20this%20issue.%20We%20were%20asked%20for%2C%20and%20provided%2C%20all%20manner%20of%20information%20and%20data%20from%20the%20the%20desktop%20app%20and%20the%20machine%20it%20was%20running%20on.%20I%20think%20we've%20established%20that%20the%20problem%20is%20how%20the%20Teams%20(or%20Azure%20Bot)%20server-side%20application%20is%20interacting%20with%20our%20endpoint%20-%20and%20not%20with%20either%20the%20desktop%20or%20web%20client.%3CBR%20%2F%3E%3CBR%20%2F%3EThe%20bot%20id%20is%20%22ask-kaybot%22%20The%20issue%20is%20continuous%2C%20but%20I'll%20make%20a%20couple%20more%20requests%20to%20it%20at%20the%20same%20time%20I%20post%20this%20reply%20so%20that%20you%20have%20a%20timestamp.%3CBR%20%2F%3E%3CBR%20%2F%3ESteve%3CBR%20%2F%3E%3C%2FLINGO-BODY%3E
New Contributor

The "Web Chat" channel works fine, but the "Microsoft Teams" doesn't. A few clues as to what might be going on...

 

1) If I point to an ngrok tunnel that goes directly to the https service (haproxy) it works fine.
2) I'm seeing the occasional portal.azure.com pre-flight (OPTIONS) request logged against the service, but nothing else.

 

So, Teams/Azure Bot can reach the service, and it would seem that it's pretending to be a browser and doing CORS stuff. I've permitted and exposed all the headers the pre-flight is asking for. I also respond with the required specific Origin -> https://portal.azure.com header and allow authentication (because Azure Bot sends an authorization header).

 

Any ideas about what could be going on?

8 Replies

@stephenmdyoung : Hey are you trying to run bot from local or have you deployed it on app service? 
Also, the endpoint you are giving should be publicly accessible and in channels, it should be connected to Teams. 

Please have a look at this: Connect a bot to Microsoft Teams

Thanks @HunaidHanfee-MSFT - but yes, the endpoint is publicly available and the bot has both the Teams and Web Chat channels. What's more, the relevant Microsoft services must be seeing the relevant settings or we wouldn't be seeing the OPTIONS request at the endpoint.

Steve
As I understand from the question app is working when pointed to ngrok. You are facing problem when you are giving some other endpoint.
If you doing it locally make sure that bot is running and ngrok or other endpoint should point to the same port on which local bot is running.

Also, you should check on Teams web client and look console for errors. Please make sure that you have given the correct botId in the manifest.

Could you please share bot Id and timestamp when you faced this issue so that we can check at our end what is wrong?
Hi @HunaidHanfee-MSFT

Indeed the app is working when pointed to an ngrok endpoint, but the ngrok tunnel is pointed directly (initiated from inside the service's VM) to the "live" socket - i.e. to the same endpoint. This might seem to indicate that there is a firewall or other infrastructure issue blocking Teams' access to the endpoint, but we've eliminated that possibility. We can see the Teams traffic in tcpdump captures, *and* we're capturing Teams CORS OPTIONS requests at the endpoint.

ngrok uses an Authorisation header so will overwrite whatever comes from Azure/Teams. This might be a clue to what's going on.

As you've suggested, I've brought up the Teams web client in a clean version of Firefox (no blockers etc) on a linux VM and, for sure, Angular is spitting out a bunch of errors. There is plenty of data the client is expecting, but not getting. e.g.

XML Parsing Error: no root element found
Location: https://presence.teams.microsoft.com/v1/me/reportmyactivity

You should know that we raised a ticket (Case #:27092020) for this issue. We were asked for, and provided, all manner of information and data from the the desktop app and the machine it was running on. I think we've established that the problem is how the Teams (or Azure Bot) server-side application is interacting with our endpoint - and not with either the desktop or web client.

The bot id is "ask-kaybot" The issue is continuous, but I'll make a couple more requests to it at the same time I post this reply so that you have a timestamp.

Steve

Hello @stephenmdyoung,
Please have a look at this FAQ. It explain which specific URLs you need to allow-list in your corporate firewall.

Also could please share your bot GUID Id that you used while creating bot channel registration or used in manifest. 

Thanks for this @HunaidHanfee-MSFT 

 

The endpoint sits on an AWS VM - not behind a corporate firewall.  No incoming hosts/IP addresses are blocked at this stage - only ports.

 

The ask-kaybot Microsoft App ID is ee4a1ffe-1d28-4d74-9aeb-e27f25d9acc0 - I hope this is the GUID you need.

@nexus-steve - To keep you updated - We have find that you are getting an exception 

Error when sending request to bot System.Net.Http.HttpRequestException: An error occurred while sending the request.
 ---> (Inner) System.Net.WebException: The request was aborted: Could not create SSL/TLS secure channel.

This might be the problem that is blocking request to get send. I am looking into this and working with internal team to get it sorted. 
Thanks 

Thanks for the update  @HunaidHanfee-MSFT - your efforts are much appreciated.

 

Can you let me know what ciphers Teams/Azure is expecting?  I'll make sure that haproxy has them covered.

 

Cheers

Steve