Is Teams Tab SSO enough to validate user?

SadPython 0 Reputation points
2024-07-07T05:37:39.5466667+00:00

I have an app I want to embed as a tab in MS Teams. Users may already have an account outside of teams and I use magic login link to typically to log users in. I want to know if I can leverage teams tab SSO to log users into their existing account. So my idea is:

  1. User has an account with my app already. It is associated with their organization email.
  2. They access my app in Teams and grant permissions necessary, my app gets an auth token and validates it
  3. If that is successful, I find the user's account associated with their email and log them in with a magic login link

I'm wondering if this is a valid use case for teams tab sso? Is it enough to trust that the validated token means the user is good and can be logged in? I know typically there is a "sign in with microsoft" idp option but that is a larger lift. Was wondering if there are big security red flags here.

Microsoft Teams
Microsoft Teams
A Microsoft customizable chat-based workspace.
10,318 questions
Microsoft Teams Development
Microsoft Teams Development
Microsoft Teams: A Microsoft customizable chat-based workspace.Development: The process of researching, productizing, and refining new or existing technologies.
3,342 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. akinbade abiola 18,305 Reputation points
    2024-07-07T10:11:48.8233333+00:00

    Hello SadPython,

    Thanks for your question.

    IMO, It is viable if implemented correctly. It's not ideal for user identity within your main app. You can try try custom authentication flow or Sign in with Microsoft to minimize reliance on magic login links.

    See:

    Enable SSO for tab app

    How different technologies affect Microsoft Teams sign-in

    https://learn.microsoft.com/en-us/entra/identity-platform/authentication-flows-app-scenarios

    You can mark it 'Accept Answer' and 'Upvote' if this helped you

    Regards,

    Abiola


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.