الأكاديمية ← قنوات المراسلةتوثيق رسمي · إرشاد عربي

قناة Microsoft Teams

Microsoft Teams

متوسط إلى متقدم9 دقائق قراءةالدرس 64 أسئلة✓ 2026-08-18
قبل أن تقرأ

ما هذه الصفحة، وماذا تحتوي.

بوابة المراسلة: الوصلة التي تجعلك تكلّم Hermes من تطبيق تستعمله أصلًا، مثل Telegram أو WhatsApp، بدل الطرفية. الوكيل الذي تصله من هاتفك تستعمله فعلًا. الذي يحتاج فتح الحاسوب تنساه بعد أسبوع. الصفحة فيها تحذير من المصدر، و9 دقائق قراءة. انتبه: افتح القناة لنفسك فقط في البداية عبر قائمة سماح. القناة المفتوحة تعني أن أي شخص يراسل وكيلك.

13أقسام
16أمثلة برمجية
4جداول
4أوامر
1,475كلمة من المصدر
الوصف الرسمي في سطر

Set up Hermes Agent as a Microsoft Teams bot

ماذا ستستطيع بعدها

نتائج مأخوذة من هذه الصفحة، لا من قالب.

  • تعرف ما بوابة المراسلة ولماذا قد تحتاجه.
  • تنفّذ hermes gateway run وhermes gateway setup وتفهم ما يحدث بعدها.
  • تقرأ الجدول وتأخذ منه السطر الذي يخصّك فقط.
  • تضبط TEAMS_ALLOWED_USERS في المكان الصحيح.
ما ستقابله من أسماء

كما تظهر تمامًا داخل Hermes.

الأوامر
  • hermes gateway run
  • hermes gateway setup
  • hermes gateway status
  • hermes gateway restart
متغيرات البيئة
  • TEAMS_ALLOWED_USERS
  • TEAMS_PORT
  • CLIENT_ID
  • CLIENT_SECRET
  • TENANT_ID
  • TEAMS_CLIENT_ID
  • TEAMS_CLIENT_SECRET
  • TEAMS_TENANT_ID
خريطة الصفحة

انتقل مباشرة إلى ما تحتاجه.

  1. 01How the Bot Responds
  2. 02Step 1: Install the Teams CLI
  3. 03Step 2: Expose the Webhook Port
  4. 04Step 3: Create the Bot
  5. 05Step 4: Configure Environment Variables
  6. 06Step 5: Start the Gateway
  7. 07Step 6: Install the App in Teams
  8. 08Configuration Reference
  9. 09Features
  10. 10Production Deployment
  11. 11Troubleshooting
  12. 12Security
  13. 13Related Docs
الصفحة الرسمية كاملة

بلا اختصار أو حذف.

النص أدناه منقول من المصدر الرسمي بالإنجليزية حتى تبقى الأوامر والأسماء دقيقة كما هي. قبل كل قسم شرح عربي يوضّح ما بداخله.

Connect Hermes Agent to Microsoft Teams as a bot. Unlike Slack's Socket Mode, Teams delivers messages by calling a public HTTPS webhook, so your instance needs a publicly reachable endpoint — either a dev tunnel (local dev) or a real domain (production).

Need meeting summaries from Microsoft Graph events rather than normal bot conversations? Use the dedicated setup page: Teams Meetings.

Run hermes gateway setup and pick Microsoft Teams for a guided walk-through.

How the Bot Responds

شرح للفكرة نفسها. اقرأه ببطء، فبقية الأقسام تبني عليه. تذكير: الوصلة التي تجعلك تكلّم Hermes من تطبيق تستعمله أصلًا، مثل Telegram أو WhatsApp، بدل الطرفية.

ContextBehavior
Personal chat (DM)Bot responds to every message. No @mention needed.
Group chatBot only responds when @mentioned.
ChannelBot only responds when @mentioned.

Teams delivers @mentions as regular messages with <at>BotName</at> tags, which Hermes strips automatically before processing.

---

For source or local installs, include the Teams extra so the bundled adapter can

Shell3 أسطر
uv sync --extra teams
# or, for editable installs:
uv pip install -e ".[teams]"

Step 1: Install the Teams CLI

خطوات عملية بالترتيب. نفّذ خطوة وتأكد أنها نجحت قبل الانتقال للتالية.

The @microsoft/teams.cli automates bot registration — no Azure portal needed.

Shellسطران
npm install -g @microsoft/teams.cli@preview
teams login

To verify your login and find your own AAD object ID (needed for TEAMS_ALLOWED_USERS):

Shellسطر واحد
teams status --verbose

---

Step 2: Expose the Webhook Port

خطوات عملية بالترتيب. نفّذ خطوة وتأكد أنها نجحت قبل الانتقال للتالية.

Teams cannot deliver messages to localhost. For local development, use any tunnel tool to get a public HTTPS URL. The default port is 3978 — change it with TEAMS_PORT if needed.

Shell10 أسطر
# devtunnel (Microsoft)
devtunnel create hermes-bot --allow-anonymous
devtunnel port create hermes-bot -p 3978 --protocol http  # replace 3978 with TEAMS_PORT if changed
devtunnel host hermes-bot

# ngrok
ngrok http 3978  # replace 3978 with TEAMS_PORT if changed

# cloudflared
cloudflared tunnel --url http://localhost:3978  # replace 3978 with TEAMS_PORT if changed

Copy the https:// URL from the output — you'll use it in the next step. Leave the tunnel running while developing.

The public tunnel URL uses HTTPS, but Hermes' local webhook listener uses plain HTTP. The tunnel terminates TLS and forwards HTTP to port 3978; do not configure the local tunnel port as HTTPS.

For production, point your bot's endpoint at your server's public domain instead (see Production Deployment ↗).

---

Step 3: Create the Bot

خطوات عملية بالترتيب. نفّذ خطوة وتأكد أنها نجحت قبل الانتقال للتالية.

Shell3 أسطر
teams app create \
  --name "Hermes" \
  --endpoint "https://<your-tunnel-url>/api/messages"

The CLI outputs your CLIENT_ID, CLIENT_SECRET, and TENANT_ID, plus an install link for Step 6. Save the client secret — it won't be shown again.

---

Step 4: Configure Environment Variables

خطوات عملية بالترتيب. نفّذ خطوة وتأكد أنها نجحت قبل الانتقال للتالية.

Add to ~/.hermes/.env:

Shell8 أسطر
# Required
TEAMS_CLIENT_ID=<your-client-id>
TEAMS_CLIENT_SECRET=<your-client-secret>
TEAMS_TENANT_ID=<your-tenant-id>

# Restrict access to specific users (recommended)
# Use AAD object IDs from `teams status --verbose`
TEAMS_ALLOWED_USERS=<your-aad-object-id>

---

Step 5: Start the Gateway

خطوات عملية بالترتيب. نفّذ خطوة وتأكد أنها نجحت قبل الانتقال للتالية. الأوامر هنا: hermes gateway run، hermes gateway status.

Docker (must run from the directory that contains docker-compose.yml — usually your cloned hermes-agent repo, not ~):

Shellسطران
cd /path/to/hermes-agent
HERMES_UID=$(id -u) HERMES_GID=$(id -g) docker compose up -d gateway

Native / systemd install (typical hermes one-liner installer under ~/.hermes/hermes-agent):

Shellسطران
hermes gateway restart
# or foreground: hermes gateway run

The Teams SDK is optional; when Teams is enabled, the gateway lazy-installs it into Hermes' own venv on first start (do not use system pip install on Ubuntu 24.04 — that hits PEP 668 externally-managed-environment). To install manually into the Hermes venv:

Shellسطران
~/.hermes/hermes-agent/venv/bin/pip install microsoft-teams-apps aiohttp
# or from a clone of the agent: uv sync --extra teams

The default webhook port is 3978 (override with TEAMS_PORT). Check that it's running:

Shell5 أسطر
curl http://localhost:3978/health   # should return: ok
# Docker:
docker logs -f hermes
# Native:
hermes gateway status -l

Look for:

Textسطر واحد
[teams] Webhook server listening on * (all interfaces, IPv4+IPv6):3978/api/messages

---

Step 6: Install the App in Teams

خطوات عملية بالترتيب. نفّذ خطوة وتأكد أنها نجحت قبل الانتقال للتالية.

Shellسطر واحد
teams app get <teamsAppId> --install-link

Open the printed link in your browser — it opens directly in the Teams client. After installing, send a direct message to your bot — it's ready.

---

Configuration Reference

جدول مرجعي. لا تقرأه كله، ابحث عن السطر الذي يخصّك فقط.

Environment Variables

VariableDescription
TEAMS_CLIENT_IDAzure AD App (client) ID
TEAMS_CLIENT_SECRETAzure AD client secret
TEAMS_TENANT_IDAzure AD tenant ID
TEAMS_ALLOWED_USERSComma-separated AAD object IDs allowed to use the bot
TEAMS_ALLOW_ALL_USERSSet true to skip the allowlist and allow anyone
TEAMS_HOME_CHANNELConversation ID for cron/proactive message delivery
TEAMS_HOME_CHANNEL_NAMEDisplay name for the home channel
TEAMS_PORTWebhook port (default: 3978)

config.yaml

Alternatively, configure via ~/.hermes/config.yaml:

YAML8 أسطر
platforms:
  teams:
    enabled: true
    extra:
      client_id: "your-client-id"
      client_secret: "your-secret"
      tenant_id: "your-tenant-id"
      port: 3978

---

Features

إعدادات تضبطها مرة وتنساها. غيّر واحدًا في كل مرة حتى تعرف أثر كل تغيير.

Interactive Approval Cards

When the agent needs to run a potentially dangerous command, it sends an Adaptive Card with four buttons instead of asking you to type /approve:

  • Allow Once — approve this specific command
  • Allow Session — approve this pattern for the rest of the session
  • Always Allow — permanently approve this pattern
  • Deny — reject the command

Clicking a button resolves the approval inline and replaces the card with the decision.

Meeting Summary Delivery (Teams Meeting Pipeline)

When the Teams meeting pipeline plugin is enabled, this adapter also handles outbound delivery of meeting summaries — one Teams integration surface, not two. After a meeting's transcript is summarized, the writer posts the summary into your chosen Teams target.

Pipeline summary delivery is configured under the teams platform entry alongside the bot config:

YAML15 سطرًا
platforms:
  teams:
    enabled: true
    extra:
      # existing bot config (client_id, client_secret, tenant_id, port) ...

      # Meeting summary delivery (only used when the teams_pipeline plugin is enabled)
      delivery_mode: "graph"       # or "incoming_webhook"
      # For delivery_mode: graph — pick ONE of:
      chat_id: "19:meeting_..."    # post into a Teams chat
      # team_id: "..."             # OR post into a channel
      # channel_id: "..."
      # access_token: "..."        # optional; falls back to MSGRAPH_* app credentials
      # For delivery_mode: incoming_webhook:
      # incoming_webhook_url: "https://outlook.office.com/webhook/..."
ModeUse whenTrade-off
incoming_webhookSimple "post a summary into this channel" with a static Teams-generated URL.No reply threading, no reactions, shows as the webhook's configured identity.
graphThreaded channel posts or 1:1/group chat posts under the bot's identity via Microsoft Graph.Requires the Graph app registration with ChannelMessage.Send (channel) or Chat.ReadWrite.All (chat) application permissions.

If the teams_pipeline plugin is not enabled, these settings are inert — they only wire up when the pipeline runtime binds to the Graph webhook ingress.

---

Production Deployment

شرح للفكرة نفسها. اقرأه ببطء، فبقية الأقسام تبني عليه.

For a permanent server, terminate TLS at a reverse proxy and forward requests to the plain HTTP Hermes listener, normally http://127.0.0.1:3978. Register the proxy's public HTTPS endpoint with Teams:

Shell3 أسطر
teams app create \
  --name "Hermes" \
  --endpoint "https://your-domain.com/api/messages"

If you've already created the bot and just need to update the endpoint:

Shellسطر واحد
teams app update --id <teamsAppId> --endpoint "https://your-domain.com/api/messages"

Make sure the public HTTPS endpoint is reachable from the internet and uses a valid TLS certificate. Teams rejects self-signed certificates. Keep the Hermes listener behind the proxy; port 3978 does not serve HTTPS itself.

---

Troubleshooting

قسم لحل المشكلات. ابحث فيه عن العطل الذي يشبه حالتك بدل قراءته كاملًا.

ProblemSolution
Can't find a suitable configuration file from docker composeYou are not in the repo that has docker-compose.yml, or you are on a native install — use hermes gateway restart instead, or cd into the clone first
requirements not met / Teams SDK missing / No adapter available for teamsRestart gateway so lazy-install can run, or install into the Hermes venv: ~/.hermes/hermes-agent/venv/bin/pip install microsoft-teams-apps aiohttp. System pip fails on Ubuntu 24.04 (PEP 668) and would not affect the service anyway
health endpoint works but bot doesn't respondCheck that your tunnel is still running and the bot's messaging endpoint matches the tunnel URL
Logs show "UNKNOWN / HTTP/1.0" 400 when Teams sends a messageThe tunnel or reverse proxy is forwarding HTTPS to Hermes' plain HTTP listener. Terminate TLS at the proxy and forward HTTP to port 3978
KeyError: 'teams' in logsRestart the container — this is fixed in the current version
Bot responds with auth errorsVerify TEAMS_CLIENT_ID, TEAMS_CLIENT_SECRET, and TEAMS_TENANT_ID are all set correctly
No inference provider configuredCheck that ANTHROPIC_API_KEY (or another provider key) is set in ~/.hermes/.env
Bot receives messages but ignores themYour AAD object ID may not be in TEAMS_ALLOWED_USERS. Run teams status --verbose to find it
Tunnel URL changes on restartdevtunnel URLs are persistent if you use a named tunnel (devtunnel create hermes-bot). ngrok and cloudflared generate a new URL each run unless you have a paid plan — update the bot endpoint with teams app update when it changes
Teams shows "This bot is not responding"The webhook returned an error. Check docker logs hermes / hermes gateway status -l for tracebacks
[teams] Failed to connect in logsThe SDK failed to authenticate. Double-check your credentials and that the tenant ID matches the account you used in teams login

---

Security

فيه تحذير مهم. اقرأه قبل أن تنفّذ أي شيء من هذا القسم. نصّ التحذير من المصدر مذكور أسفل هذا الشرح.

  • Store credentials in ~/.hermes/.env with permissions 600 (chmod 600 ~/.hermes/.env)
  • The bot only accepts messages from users in TEAMS_ALLOWED_USERS; unauthorized messages are silently dropped
  • Your public endpoint (/api/messages) is authenticated by the Teams Bot Framework — requests without valid JWTs are rejected
اختبار الفهم

4 أسئلة إجاباتها كلها في هذه الصفحة.

كل خيار اسم حقيقي من توثيق Hermes. حتى الخيارات الخاطئة حقيقية، لكنها من صفحات أخرى.

1. أي متغير بيئة من التالي يظهر فعليًا في هذا الدرس؟
2. ما التحذير الذي يذكره المصدر في هذا الدرس؟
3. أي عنوان من التالي لا يظهر في هذا الدرس؟
4. أي مفتاح إعداد يظهر في أمثلة هذا الدرس؟