Register a Microsoft Graph Application
Register a Microsoft Graph Application
Start with meaning, then move to detail.
This lesson explains Register a Microsoft Graph Application as part of Hermes internals and extension points. You will learn what it does, when it matters, and the smallest safe test that proves it works.
If you are new, do not memorize names. Focus on three questions: what problem does this solve, what access does it need, and how can you verify the result?
For practice, inspect the first example, identify its effects, run it on test data, and compare the result with the source claim.
For advanced readers, inspect Prerequisites, Step 1: Create the App Registration, Step 2: Create a Client Secret, then verify failure modes and version compatibility.
Know Python, Git, and basic project structure before changing code.
A clear outcome before you read.
- Understand Register a Microsoft Graph Application without assumed prior knowledge.
- Separate the source description from what still needs testing in your environment.
- Read the first command and identify its inputs and outputs before copying it.
Azure portal walkthrough for creating the app registration that powers the Teams meeting pipeline
What does the source say, and in what order?
- 01Prerequisites
Start here to understand the core idea or structure.
- 02Step 1: Create the App Registration
Read this after the foundation, then connect it to the previous step.
- 03Step 2: Create a Client Secret
Read this after the foundation, then connect it to the previous step.
- 04Step 3: Grant Graph API Permissions
Read this after the foundation, then connect it to the previous step.
- 05Required for transcript-first summaries
Read this after the foundation, then connect it to the previous step.
- 06Required for recording fallback (when a transcript is unavailable)
Read this after the foundation, then connect it to the previous step.
- 07Required for outbound summary delivery (Graph mode only)
Read this after the foundation, then connect it to the previous step.
- 08Not recommended
Read this after the foundation, then connect it to the previous step.
- 09Step 4: (Recommended) Scope the App with an Application Access Policy
Read this after the foundation, then connect it to the previous step.
- 10Step 5: Write the Credentials to Your Env File
Finish here to verify the result and special cases.
Copy only after you understand the effect.
# Create a policy scoped to the Hermes app
New-CsApplicationAccessPolicy `
-Identity "Hermes-Meeting-Pipeline-Policy" `
-AppIds "<MSGRAPH_CLIENT_ID>" `
-Description "Restrict Hermes meeting pipeline to allow-listed users"
# Grant the policy to specific users whose meetings the pipeline may read
Grant-CsApplicationAccessPolicy `
-PolicyName "Hermes-Meeting-Pipeline-Policy" `
-Identity "alice@example.com"
Grant-CsApplicationAccessPolicy `
-PolicyName "Hermes-Meeting-Pipeline-Policy" `
-Identity "bob@example.com"Test-CsApplicationAccessPolicy -Identity "alice@example.com" -AppId "<MSGRAPH_CLIENT_ID>"MSGRAPH_TENANT_ID=<directory-tenant-id>
MSGRAPH_CLIENT_ID=<application-client-id>
MSGRAPH_CLIENT_SECRET=<client-secret-value>Read the first command and identify its inputs and outputs before copying it.
Match every command to your installed Hermes version, review the files and accounts it can reach, and use non-sensitive data for the first test. If this explanation differs from the source, the official source wins.