Teams integration setup guide


About

Kaltura's Teams integration enables you to effortlessly upload and archive your Teams recordings, ensuring everything stays neatly organized in one centralized location.

The integration supports both scheduled Teams meetings and ad-hoc session recordings.

As the owner and host, you'll retain full control and enjoy easy collaboration with co-hosts.

Before you start

  • A paid Microsoft Teams account
  • Administrator access to Microsoft Entra ID and the Microsoft Teams admin center
  • Rich Media CMS account and access
  • Teams integration service enabled in Kaltura (paid service) 

Each Teams account can be linked to only one Kaltura account.

Step 1 - Register and configure a Microsoft Entra app

Request permissions

  1. Navigate to the Microsoft Azure portal and sign in with your Azure account credentials.
  2. In the Azure Portal's left-hand menu, click Microsoft Entra ID.
  3. Under Manage, click App registrations.
  4. Click +New Registration.
    The Register an application page displays.
  5. In the Name field, type in a name, for example, Kaltura Teams Integration.

  6. At the bottom of the page, click Register.
    The settings page displays.
  7. Under Manage, click API permissions.
  8. On the API permissions page, click +Add a permission.
  9. The Request API permissions page displays.

  10. Under the Microsoft APIs tab, click Microsoft Graph.
  11. Under the Microsoft Graph tab, click Application permissions.
  12. Under Select permissions, check the checkbox for each of the following permissions:
    1. OnlineMeetingRecording.Read.All
    2. OnlineMeetings.Read.All
    3. OnlineMeetingTranscript.Read.All
    4. User.ReadBasic.All
    5. CallTranscripts.Read.All
    6. CallRecordings.Read.All
    7. CallRecords.Read.All

  13. At the bottom of the page, click Add permissions 
  14. The configured permissions display with the status Not granted for [your tenant].
  15. Click Grant admin consent for [your tenant], then confirm. If you can’t grant consent, ask your Microsoft administrator to complete this step.
  16. The status changes to Granted for [your tenant].

Create a client secret

  1. In the left sidebar under Manage, click Certificates and Secrets.
  2. Click +New client secret.
  3. The Add a client secret window displays.

  4. In the Description field, type in a description.
  5. In the Expires field, choose a time period from the drop-down menu.
  6. Please note that updating the secret in Kaltura isn't currently available. We recommend selecting a longer expiry date to avoid needing to recreate the integration when the secret expires.

  7. Click Add to create the client secret.
  8. After you add the client secret, its value displays.

Copy the client secret value and save it securely. You won't be able to see this value again after leaving this page.

6. In the left sidebar, click on the Overview tab to view your credentials which you will need for the configuration in Rich Media CMS.

Configure an application access policy

To allow your Azure app to access online meetings via Microsoft Graph, follow Microsoft’s instructions in Configure application access policy*.

*In Microsoft's instructions, you'll need to follow steps 1-3, then skip step 4 and proceed to step 5. Step 4 is not needed for Kaltura.

Below are example commands:

Connect to Microsoft Teams PowerShell

Connect-MicrosoftTeams

Create Application Access Policy

New-CsApplicationAccessPolicy -Identity Teams-policy -AppIds "REPLACE_WITH_APP_ID" -Description "Upload Teams recordings to Kaltura"

Grant the policy globally

Grant-CsApplicationAccessPolicy -PolicyName Teams-policy -Global

Enable transcript access in Teams

If you want to include Teams transcriptions with your recordings (Teams transcription set to Yes in the integration settings), a Teams administrator must allow apps to access meeting transcripts through Microsoft Graph. This setting is off by default.

  1. In the Teams admin center, go to Meetings > Meeting settings.
  2. Under Transcript API access, turn Microsoft Graph access On.

For details, see Manage transcript API access for Teams meetings.

Billing setup is no longer required

As of August 25, 2025, Microsoft Teams APIs in Microsoft Graph, including the recording and transcript download APIs used by this integration, are no longer metered. You don’t need to link your Azure app to an active subscription or configure billing.

For details, see Payment models and licensing requirements for Microsoft Teams APIs.

Step 2 - Configure Teams integration in Kaltura

  1. Log into the Rich Media CMS and click the settings icon at the top right.

  2. The Account page displays.

  3. Click the Integration tab.

  4. The Integration page displays.

  5. Scroll down to Teams integration.

  6.  In the Teams integration section, click Create new integration.

    The Add new Teams integration window opens.

  7. Complete the required fields
    • Name - Enter a name for your integration.
    • Directory (tenant) ID - Enter the Directory ID from the Overview page of your Microsoft Entra app.
    • Application (client) ID - Enter the Application ID from the Overview page of your Microsoft Entra app.
    • Application (client) Secret - Paste the client secret Value you saved earlier.
  8. Click Create.
  9. The edit window displays.

Edit integration settings

You can edit an existing Teams integration. The settings are as follows:

  • Name
  • Directory (tenant) ID (read only)
  • Application (client) ID (read only)
  • Publish to categories - Enter one or more categories for Teams recordings. 
  • Upload recordings management:
    • Upload all recordings - All recordings in the account will be uploaded to Kaltura.
    • Opt-in groups - Recordings will be uploaded to Kaltura if the owner of the recordings is in one of the opt-in groups.
    • Opt-out groups - Recordings will be uploaded to Kaltura if the owner of the recordings is not in one of the opt-out groups.
    • Upload ad-hoc sessions recordings – Select whether to upload recordings from ad-hoc Teams sessions in addition to scheduled meeting recordings.
  • Teams transcription - Set to 'Yes' to include the transcription when uploading the recording.

Assign user permissions for uploaded recordings

Co-organizers - Choose an option from the drop-down menu:

  • None
  • Co-viewers
  • Co-editors
  • Co-publishers
  • Co-editors & Co-publishers

Please note that the option co-organizers is not currently supported by Microsoft.

Presenters - Choose an option from the drop-down menu:

  • None
  • Co-viewers
  • Co-editors
  • Co-publishers
  • Co-editors & Co-publishers

Users - Choose an option from the drop-down menu:

  • None
  • Co-viewers
  • Co-publishers

The Users setting also applies to participants of ad-hoc session recordings.

Set owner for recordings

Microsoft Entra ID and Kaltura may use different identifiers for the same user. For example, the Microsoft User Principal Name (UPN) may include the full email address, such as first.last@company.com, while the Kaltura user ID may be first.last.

These settings let Kaltura match Microsoft Entra users with Kaltura users by adding or removing a postfix, such as @company.com, or by leaving the identifier unchanged.

Set user based on - Choose from the following:

  • Microsoft User Principal Name
    • Do not modify (default) - This will be the user ID.
    • Remove postfix - Select to remove postfix. For example, if your UPN is john.doe@example.com and the Kaltura user ID is john.doe, the postfix is @example.com.
    • Add postfix - Select to add a postfix to the field. For example, if your UPN is john.doe and the Kaltura user ID is john.doe@example.com, the postfix is @example.com.
  • Azure user ID
    • Use the unique user identifier assigned in Microsoft Entra ID.   
    • When you use Azure user ID for ad-hoc session recordings, only the recording owner is identified. Other participants don’t automatically receive permissions for the recording.

Find user by - Choose which Kaltura field to use to match the user:

  • User ID
  • User email
  • Both

In case the user doesn't exist - Choose one of the following:

  • Create new user based on Teams user (default)
  • Use default user - add user from account

Edit Teams account information

In Teams integration, you'll see a list of all active integrations.

The following information is available:

  • Account name
  • Creation date
  • Updated at
  • Status - Enabled or Disabled

Use the three-dot menu next to the relevant integration to:

  • Edit - opens the integration form
  • Enable / Disable - allows you to enable / disable the integration (Integration is created in 'disabled' status. To activate it, switch the status to 'enabled' manually.)
  • Delete - allows you to delete the account
  • If the profile status is enabled, a message will display: Please change integration status to 'Disable' in order to delete it.

Troubleshooting

If an error occurs, it will be indicated by a red exclamation mark in the status column.

Hover to see a message, such as Application policy is missing for the configured application registration.

Here's a list of possible error messages and troubleshooting tips:

Error message Troubleshooting
The provided application credentials are missing the 'OnlineMeetingRecording.Read.All' permission. Double-check the permissions created in 'Request permissions'.
The provided application credentials are missing the 'OnlineMeetingTranscript.Read.All' permission. Double-check the permissions created in 'Request permissions'.
Application policy is missing for the configured application registration. This likely means the application access policy wasn't created or granted correctly. Check Configure an application access policy.
Access to the Microsoft API was denied. This means we failed to access the Microsoft API using the configured credentials.
The provided application secret has expired. To fix this, create a new integration with a new secret. (In the future, it will be possible to update the secret.)
The provided application secret is invalid. This probably means the application secret was deleted in the Microsoft Entra admin center. To fix this, create a new integration with a new secret.
Application is disabled The Microsoft Entra app you registered for the Teams integration (e.g., “Kaltura Teams Integration”) is currently disabled. Ask your Microsoft administrator to enable the app in your organization's Microsoft Entra tenant, then try setting up the integration again.
Integration shows an error after setting Teams transcription to Yes Transcript access may be turned off in your Teams tenant. Ask your Teams administrator to turn it on (see Enable transcript access in Teams), or set Teams transcription to No.
Was this article helpful?
Thank you for your feedback!
User Icon

Thank you! Your comment has been submitted.

In this article
Related articles