Hi @Amanda Fuchs
Regarding whether this is caused by policy or identity, it is more likely that a policy in the destination tenant is blocking the bot. However, without a request trace, this cannot be confirmed with certainty.
The 403 BotDisabledByAdmin error is described in the Teams Conversation API error-code table as a case where the tenant administrator has disabled the bot. An incorrect tenant authority or identity mismatch would usually result in a 401 error, as some agent framework cases have reported when a token was obtained from the wrong authority. Since you are receiving a 403, it appears that the token has likely been accepted. Common causes include the app being blocked under Manage apps in the destination tenant’s Teams admin center or being restricted by an app permission policy. These are only common scenarios that I’m suggesting, not a verified or exhaustive list of conditions.
There also appears to be a mismatch in the current configuration that should be clarified. Your Azure Bot resource is configured as SingleTenant, while the Entra app registration uses AzureADandPersonalMicrosoftAccount. Although an Azure Bot can use a multitenant Microsoft Entra application, Microsoft documentation states that the bot’s TENANT_ID must still be the tenant in which the Entra application is registered. The documentation also notes that a bot configured as Single Tenant must request the correct access token for the Bot Connector. In addition, the creation of new multitenant bots was discontinued on July 31, 2025, so I would not recommend relying on a multitenant app registration as a long-term solution.
First, ask the Teams administrator of the destination tenant to open Manage apps, locate your app, and confirm that it is not marked as Blocked. They should also verify that no app permission policy is preventing the affected users from accessing the app.
Confirm that the Teams app package referencing your bot has actually been installed in the correct team that you are querying in the destination tenant. The teamId and serviceUrl should come from an activity originating from that tenant.
You should also confirm that MicrosoftAppType, MicrosoftAppId, and MicrosoftAppTenantId in the bot’s runtime environment exactly match the Azure Bot resource and the corresponding Entra application. You should not replace MicrosoftAppTenantId with the destination tenant ID when requesting the Connector token.
After that, collect a trace of the failed request and compare it with a successful request from the bot’s home tenant. Also make sure that the failed request uses the serviceUrl obtained from an activity received from the destination tenant. Microsoft documentation states that the serviceUrl property in the incoming activity should be used as the base URI for subsequent Bot Connector requests.
Ref: API reference for the Bot Framework Connector service
I’m only a fellow community user, not a Microsoft employee, but I hope this gives you a useful direction for the investigation.