Building, integrating, or customizing apps and workflows within Microsoft Teams using developer tools and APIs
The error "errorCode":"InvalidUserId" with the message "Incorrect bot configuration/registration. Check the bot settings." indicates a bot registration/configuration problem in Microsoft Entra ID / Azure Bot, not an issue with the client secret, client ID, or tenant ID alone.
From similar Teams bot issues, this typically occurs when:
- The Azure Bot resource and the Entra app registration are not aligned (for example, one is single‑tenant and the other is multi‑tenant, or they are not correctly linked).
- The bot adapter / CloudAdapter is initialized incorrectly for the tenant or cross‑tenant scenario.
- The Service Principal for the app registration is missing in the tenant where Teams is running.
Use the following checks and fixes:
- Align bot and app registration tenancy
Ensure the Azure Bot resource and the corresponding Microsoft Entra app registration use the same tenant model:- If the bot is configured as
SingleTenantin Azure Bot Service (msaAppType: 'SingleTenant'), the app registration should also be single‑tenant, and the bot should be used only in that tenant. - If cross‑tenant use is required, ensure the adapter and auth configuration explicitly handle the target tenant; misalignment here is a common cause of 400/Unauthorized/InvalidUserId errors.
- If the bot is configured as
- Verify Service Principal exists in the tenant
If the bot is used in a tenant where the Service Principal for the app registration does not yet exist, token acquisition and identity resolution can fail:- In the Azure portal, go to App registrations and open the app registration used by the bot.
- Check the Managed application in local directory field.
- If no Service Principal exists, select Create Service Principal.
- After creation, restart the bot and test again in Teams.
- Review adapter / CloudAdapter initialization
In the bot code, ensure the adapter is initialized according to the latest SDK guidance (especially for cross‑tenant or multi‑tenant scenarios). Incorrect initialization of the adapter for cross‑tenant communication is known to cause authorization/identity errors when sending or receiving activities. Updating the adapter configuration to match current samples (including correct tenant handling) has resolved similar issues. - Confirm OAuth connection and token configuration (if using SSO)
If the bot uses SSO or OAuth:- Verify the OAuth connection in the Azure Bot resource has the correct client ID, client secret, tenant ID, and scopes.
- Use Test connection in the bot resource to confirm the OAuth connection succeeds.
Misconfigured OAuth/SSO can surface as invalid user or auth errors when Teams tries to obtain a token for the user.
If, after these steps, the error persists, re‑create the bot registration and app registration in a clean, single‑tenant configuration, validate that Teams can send and receive messages successfully, and then re‑introduce any cross‑tenant or advanced auth configuration incrementally.
References: