Bot Service: Teams Channel Listing Returns 403 BotDisabledByAdmin — Investigation of Tenant Policy and Identity Mismatch

Amanda Fuchs 0 Reputation points
2026-10-08T05:51:50.62+00:00

Problem description

I am encountering a persistent 403 BotDisabledByAdmin error when attempting to list Teams channels via the Bot Connector API. This occurs specifically when the call targets a tenant different from where the bot is hosted, despite the bot being operational in my own tenant.

Environment

Azure Bot resource with Microsoft Teams channel enabled in a tenant where the bot is created using the Bot Framework SDK. The tenant is not specified in the case details.

What I've already tried

I verified that the Teams channel is enabled for the bot, and the bot is created with a SingleTenant configuration. I confirmed the bot's App ID and tenant ID in the Azure portal. I also checked that the bot's Microsoft Entra app registration is multitenant with signInAudience set to AzureADandPersonalMicrosoftAccount. Additionally, I confirmed the bot's messaging endpoint is correct and that the bot is enabled in the tenant. I have not performed any trace analysis of the failing request.

Current status

Currently, the call to list Teams channels returns a 403 BotDisabledByAdmin error when accessing a tenant different from my own, despite the bot being enabled and functioning in my tenant. I am seeking assistance to determine if this is due to tenant policy enforcement or an identity mismatch, and to identify the necessary configuration adjustments to resolve the issue.

Microsoft Teams | Development
Microsoft Teams | Development

Building, integrating, or customizing apps and workflows within Microsoft Teams using developer tools and APIs

0 comments No comments

2 answers

Sort by: Most helpful
  1. Ashlesha Pawar (Tata Consultancy Services Limited) 480 Reputation points Microsoft External Staff
    2026-10-08T12:14:29.26+00:00

    The 403 currently looks more like a destination-tenant app policy, installation, or conversation-context issue than a product bug. Enabling the Teams channel on the Azure Bot only enables the channel globally; the Teams app must also be allowed and installed in the destination tenant and the exact target team.

    Please call the channel-list API using the teamId and serviceUrl from a live activity received from that destination team. Also ask its Teams administrator to confirm that the app is Allowed under Manage apps and isn't excluded by app-centric management or custom-app policies.

    Separately, verify whether the SingleTenant Azure Bot and AzureADandPersonalMicrosoftAccount registration use the same App ID. If they do, align the bot identity to SingleTenant/AzureADMyOrg; if the multitenant registration is a separate SSO app, document that distinction.

    If normal bot messaging works in the destination team and only channel listing still returns BotDisabledByAdmin, collect the request/correlation IDs and escalate it as a possible Teams Connector API defect.

    Was this answer helpful?

    0 comments No comments

  2. Michelle Nguyen 1,940 Reputation points Independent Advisor
    2026-10-08T07:03:22.65+00:00

    Hi @Amanda Fuchs

    Regarding whether this is caused by policy or identity, it is more likely that a policy in the destination tenant is blocking the bot. However, without a request trace, this cannot be confirmed with certainty.

    The 403 BotDisabledByAdmin error is described in the Teams Conversation API error-code table as a case where the tenant administrator has disabled the bot. An incorrect tenant authority or identity mismatch would usually result in a 401 error, as some agent framework cases have reported when a token was obtained from the wrong authority. Since you are receiving a 403, it appears that the token has likely been accepted. Common causes include the app being blocked under Manage apps in the destination tenant’s Teams admin center or being restricted by an app permission policy. These are only common scenarios that I’m suggesting, not a verified or exhaustive list of conditions.

    There also appears to be a mismatch in the current configuration that should be clarified. Your Azure Bot resource is configured as SingleTenant, while the Entra app registration uses AzureADandPersonalMicrosoftAccount. Although an Azure Bot can use a multitenant Microsoft Entra application, Microsoft documentation states that the bot’s TENANT_ID must still be the tenant in which the Entra application is registered. The documentation also notes that a bot configured as Single Tenant must request the correct access token for the Bot Connector. In addition, the creation of new multitenant bots was discontinued on July 31, 2025, so I would not recommend relying on a multitenant app registration as a long-term solution.

    First, ask the Teams administrator of the destination tenant to open Manage apps, locate your app, and confirm that it is not marked as Blocked. They should also verify that no app permission policy is preventing the affected users from accessing the app.

    Confirm that the Teams app package referencing your bot has actually been installed in the correct team that you are querying in the destination tenant. The teamId and serviceUrl should come from an activity originating from that tenant.

    You should also confirm that MicrosoftAppType, MicrosoftAppId, and MicrosoftAppTenantId in the bot’s runtime environment exactly match the Azure Bot resource and the corresponding Entra application. You should not replace MicrosoftAppTenantId with the destination tenant ID when requesting the Connector token.

    After that, collect a trace of the failed request and compare it with a successful request from the bot’s home tenant. Also make sure that the failed request uses the serviceUrl obtained from an activity received from the destination tenant. Microsoft documentation states that the serviceUrl property in the incoming activity should be used as the base URI for subsequent Bot Connector requests.

    Ref: API reference for the Bot Framework Connector service

    I’m only a fellow community user, not a Microsoft employee, but I hope this gives you a useful direction for the investigation.

    Was this answer helpful?


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.