Academy → Practical GuidesOfficial documentation · Arabic guidance

Register a Microsoft Graph Application

تسجيل تطبيق Microsoft Graph

Intermediate6 min readLesson 323 questions✓ 2026-08-18
Before you read

What this page is, and what it holds.

This page covers Register a Microsoft Graph Application. You will use hermes gateway restart here; about 6 minutes to read. Do not disable approvals to save time. Start read-only and widen once you trust the results.

9sections
5code examples
4tables
1commands
1,040source words
The official one-line description

Azure portal walkthrough for creating the app registration that powers the Teams meeting pipeline

What you will be able to do

Outcomes taken from this page, not a template.

  • Understand what الأمان والموافقات is and when you need it.
  • Run hermes gateway restart and understand what happens next.
  • Read the table and take only the row that applies to you.
  • Set MSGRAPH_CLIENT_ID in the right place.
Identifiers you will meet

Exactly as they appear in Hermes.

Commands
  • hermes gateway restart
Environment variables
  • MSGRAPH_CLIENT_ID
  • MSGRAPH_TENANT_ID
  • MSGRAPH_CLIENT_SECRET
Page map

Jump to the part you need.

  1. 01Prerequisites
  2. 02Step 1: Create the App Registration
  3. 03Step 2: Create a Client Secret
  4. 04Step 3: Grant Graph API Permissions
  5. 05Step 4: (Recommended) Scope the App with an Application Access Policy
  6. 06Step 5: Write the Credentials to Your Env File
  7. 07Step 6: Verify the Token Flow
  8. 08Rotating the Client Secret
  9. 09Next Steps
The full official page

Nothing summarised away.

The documentation body below is reproduced from the official source so commands and identifiers stay exact. Each section carries a short note describing what it contains.

The Teams meeting pipeline reads meeting transcripts, recordings, and related artifacts from Microsoft Graph using app-only (daemon) authentication — no user sign-in, no interactive consent per meeting. That requires an Azure AD application registration with admin-consented application permissions.

This guide walks through:

  1. Creating the app registration
  2. Creating a client secret
  3. Granting the Graph API permissions the pipeline needs
  4. Admin-consenting those permissions
  5. (Optional) Scoping the app to specific users with an Application Access Policy

You need tenant admin rights (or an admin to grant consent on your behalf) to finish this. Bookmark the values you collect — they go into ~/.hermes/.env at the end.

Prerequisites

Explains the idea itself. Read it slowly; the later sections build on it.

  • A Microsoft 365 tenant with Teams Premium or Teams licenses that produce meeting transcripts and recordings
  • Admin access to the Azure portal at entra.microsoft.com ↗
  • A publicly reachable HTTPS endpoint for Graph change notifications (set up later, in the webhook listener step)

Step 1: Create the App Registration

Ordered, practical steps. Run one and confirm it worked before moving on.

  1. Sign in to entra.microsoft.com ↗ as a tenant admin.
  2. Navigate to Identity → Applications → App registrations.
  3. Click New registration.
  4. Fill in:
  5. Name: Hermes Teams Meeting Pipeline (or any name you'll recognize).
  6. Supported account types: Accounts in this organizational directory only (Single tenant).
  7. Redirect URI: leave blank — app-only auth does not need one.
  8. Click Register.

You'll land on the app's overview page. Copy two values:

  • Application (client) ID → MSGRAPH_CLIENT_ID
  • Directory (tenant) ID → MSGRAPH_TENANT_ID

Step 2: Create a Client Secret

Ordered, practical steps. Run one and confirm it worked before moving on.

  1. In the left nav, open Certificates & secrets.
  2. Click New client secret.
  3. Description: hermes-graph-secret. Expires: pick a value that matches your rotation policy (6-24 months is typical).
  4. Click Add.
  5. Copy the Value column immediately — it's only shown once. That value is MSGRAPH_CLIENT_SECRET.
The Secret ID column is not the secret. You want the Value column.

Step 3: Grant Graph API Permissions

Ordered, practical steps. Run one and confirm it worked before moving on.

The pipeline uses a minimum-viable set of application permissions. Add only what you need; each one widens what the app can read tenant-wide.

  1. In the left nav, open API permissions.
  2. Click Add a permission → Microsoft Graph → Application permissions.
  3. Add the permissions from the table below that match what you want the pipeline to do.
  4. After adding, click Grant admin consent for <your tenant>. The Status column should flip to a green checkmark for every permission.

Required for transcript-first summaries

PermissionWhat it lets the app do
OnlineMeetings.Read.AllRead Teams online meeting metadata (subject, participants, join URL).
OnlineMeetingTranscript.Read.AllRead meeting transcripts generated by Teams.

Required for recording fallback (when a transcript is unavailable)

PermissionWhat it lets the app do
OnlineMeetingRecording.Read.AllDownload Teams meeting recordings for offline STT processing.
CallRecords.Read.AllResolve meetings from call records when only the join URL is known.

Required for outbound summary delivery (Graph mode only)

If platforms.teams.extra.delivery_mode is graph, the pipeline posts summaries into a Teams channel or chat via the Graph API. Skip these if you use incoming_webhook delivery mode instead.

PermissionWhat it lets the app do
ChannelMessage.SendPost messages into Teams channels on behalf of the app.
Chat.ReadWrite.AllPost messages into 1:1 and group chats (only if you set chat_id as the delivery target).
  • OnlineMeetings.ReadWrite.All / Chat.ReadWrite without .All — broader than the pipeline needs.
  • Delegated permissions — the pipeline uses app-only (client-credentials) flow; delegated permissions won't work without user sign-in.

Step 5: Write the Credentials to Your Env File

Ordered, practical steps. Run one and confirm it worked before moving on.

Put the three values you collected into ~/.hermes/.env:

Shell3 lines
MSGRAPH_TENANT_ID=<directory-tenant-id>
MSGRAPH_CLIENT_ID=<application-client-id>
MSGRAPH_CLIENT_SECRET=<client-secret-value>

Set file permissions so only you can read the secret:

Shell1 line
chmod 600 ~/.hermes/.env

Step 6: Verify the Token Flow

Ordered, practical steps. Run one and confirm it worked before moving on.

Hermes ships a Graph auth smoke-test. From your Hermes install:

Python8 lines
python -c "

from tools.microsoft_graph_auth import MicrosoftGraphTokenProvider
provider = MicrosoftGraphTokenProvider.from_env()
token = asyncio.run(provider.get_access_token())
print('Token acquired, length:', len(token))
print(provider.inspect_token_health())
"

A successful run prints a long token string and a health dict showing cached: True and an expires_in_seconds value near 3600. Failures produce a MicrosoftGraphTokenError with the Azure error code — the most common are:

Azure errorMeaningFix
AADSTS7000215: Invalid client secretSecret value mismatched or expired.Generate a new secret in step 2; update .env.
AADSTS700016: Application not foundWrong MSGRAPH_CLIENT_ID or wrong tenant.Double-check the values from step 1 are from the same app.
AADSTS90002: Tenant not foundTypo in MSGRAPH_TENANT_ID.Copy the Directory (tenant) ID from the app overview again.
insufficient_claims at call time (not token time)Token acquires but Graph returns 401/403.You skipped step 3 admin-consent, or added permissions but haven't re-consented. Revisit API permissions and click Grant admin consent again.

Rotating the Client Secret

Settings you configure once. Change one at a time so you can see what each does. Commands here: hermes gateway restart. Set MSGRAPH_CLIENT_SECRET in your environment, not in the chat.

Azure client secrets have a hard expiry. Before yours expires:

  1. Create a second client secret in step 2 without deleting the first one.
  2. Update MSGRAPH_CLIENT_SECRET in ~/.hermes/.env with the new value.
  3. Restart the gateway so the new secret is picked up: hermes gateway restart.
  4. Verify with the smoke test above.
  5. Delete the old secret from the Azure portal.

Next Steps

Ordered, practical steps. Run one and confirm it worked before moving on.

Once credentials verify cleanly, continue with:

  • Webhook listener setup — stand up the msgraph_webhook gateway platform that receives Graph change notifications.
  • Pipeline configuration — configure the Teams meeting pipeline runtime and operator CLI.
  • Outbound delivery — wire summaries back into a Teams channel or chat.

Those pages land alongside the PRs that add the corresponding runtime. This credentials setup is a standalone prerequisite and is safe to complete in advance.

Knowledge check

3 questions answered by this page alone.

Every option is a real identifier from the Hermes documentation. The wrong ones are real too, just from other pages.

1. In this lesson's table, what is the “Meaning” for “AADSTS7000215: Invalid client secret”?
2. Which of these environment variables actually appears in this lesson?
3. Which of these headings does not appear in this lesson?