Microsoft Teams Auto-Attendance tracking automatically tracks learner attendance on MS Teams webinars (online or hybrid) linked to Event Sessions.
This guide covers delegated mode — "Each user is their own organiser." In this mode the platform does not hold broad, tenant-wide permissions. Instead, each session organiser connects their own Microsoft account once, and attendance is retrieved using that person's account. This suits organisations whose security teams prefer not to grant application-level, tenant-wide access.
(If you want a single nominated service account to organise every meeting instead, use the app-only version of this guide — it uses Application permissions and a Teams application access policy rather than per-user connections.)
The following instructions clarify the jobs to be done and the responsibilities for you and Confirm.
If you require any assistance please contact Confirm Support.
Pre-requisites
- A Microsoft 365 tenant with Azure Active Directory
- Admin access to the Azure Portal for app registration
- Admin consent rights for Microsoft Graph API permissions
- Each session organiser must have their own Microsoft 365 account and will connect it once inside the platform
Note: delegated mode does not require PowerShell or an Application Access Policy. Those are app-only-mode steps and do not apply here.
One time set up
The LXP fetches attendance data from Microsoft Teams meetings linked to Event Sessions. In delegated mode, when a session ends the system authenticates as the session's organiser (the person who created the session and connected their Microsoft account) and pulls the attendance report for their own meeting from the Microsoft Graph API, then matches attendees to enrolled users by email address.
Step 1: Create an Azure Application
- Log in to the Azure Portal
- Navigate to App registrations
- Click New registration
- Give the application a name (e.g. "LXP Teams Integration") and click Register
Step 2: Add a Redirect URI
Delegated mode uses a sign-in (OAuth) flow, so a redirect URI is required.
- In the sidebar, click Authentication
- Click Add a platform → Web
- Enter the callback URL supplied by Learning Pool and click Configure
This URL is specific to your environment. Raise a support request to Confirm to receive your environment's redirect URI before completing this step. It is the address Microsoft returns organisers to after they connect — without it, the "Connect my Microsoft Account" step will fail.
Step 3: Create a Client Secret
- In the sidebar, click Manage then select Certificates & secrets
- Click New client secret and add a description
- Important: Copy and safely store the client secret value immediately — it will not be shown again
Step 4: Copy your credentials
- Go to the Overview page of your app registration
- Copy the Application (client) ID
- Copy the Directory (tenant) ID
- Use the client secret you saved in Step 3
- All credentials are encrypted before being stored in the LXP
Step 5: Configure API Permissions
- In the sidebar, click API permissions
- Click Add a permission > Microsoft Graph > Delegated permissions
- Add the following permissions
| Permission | Admin Consent Required | Purpose |
| OnlineMeeting,ReadWrite | NO | Create/update/cancel the user's own Teams meeting; look up a meeting by join URL |
| Calendars.ReadWrite | NO | Create the calendar event that carries the meeting |
| User.Read | NO | Sign-in; confirm the Microsoft email matches the LXP account |
| offline_access | NO | Refresh token so we can keep pulling attendance without re-prompting |
| OnlineMeetingArtifact.Read.All | YES | Read the attendance report + records after the meeting |
These are Delegated permissions — they only ever access the signed-in organiser's own data, never other users'. This is the key difference from app-only mode, which uses Application permissions.
For clarity and to distinguish from app-only mode:
- OnlineMeetings.ReadAll is only for app-only mode. Delegated uses OnlineMeeting,ReadWrite
- OnlineMeetingArtifact.ReadAll is for app-only mode, not Delegated mode
- User.Read.All is for app-only mode, not Delegated mode
Important: Grant admin consent once, so each organiser gets a single clean approval rather than an individual prompt (some tenants require this one-time admin approval for the attendance permission regardless).
If you are also using the auto-create Teams meetings feature, the same connection additionally requests OnlineMeetings.ReadWrite and Calendars.ReadWrite. When an organiser connects, the Microsoft consent screen will list all of the scopes the platform requests — add these two here as well so consent is clean.
Step 6: Configure the Service in the LXP
- Contact Confirm Support to enable the Microsoft 365 Integration Service and set the organiser mode to "Each user is their own organiser."
Step 7: Send credentials from steps 3-4 to Confirm Support
- Send:
- Tenant ID - The Directory (Tenant) ID from your Azure AD app registration
- Application (Client) ID - The Application (Client) ID from your Azure AD app registration
- Client Secret - The client secret generated for your Azure AD application (please send via a secure channel — this is a live credential)
Step 8: Each organiser connects their Microsoft account
Once Learning Pool confirms the integration is live and set to delegated mode:
- Each person who will create Event Sessions signs in to the LXP and clicks "Connect my Microsoft Account."
- They approve the Microsoft consent screen once. Until an organiser connects, attendance will not sync for their sessions (and the auto-create Teams meeting option stays unavailable) — they'll see a clear prompt telling them to connect.
Important: This mode applies to the whole organisation. Once Confirm sets your organisation to delegated mode, every person who creates Event Sessions must connect their own Microsoft account before their sessions will track attendance — connecting one account does not cover colleagues.
Note: This is the end of the One-Time setup. The next steps are per-Event.
Set up for each meeting
When creating or editing an Event Session ensure you setup the following:
Step 1 - Session Type
Set the Session Type to Online or Hybrid to allow for a meeting URL.
Step 2 - Meeting Link
Paste the Teams meeting URL. The system automatically detects it as a Teams meeting.
Step 3 - Organiser (important difference from app-only mode)
In delegated mode there is no Meeting Owner Email field to complete — the system uses the connected account of the person who creates the session. Therefore:
- The session must be created by an organiser who has connected their Microsoft account (Step 8 above).
- The Teams meeting must be organised/owned by that same person. If the meeting was created by someone else, Microsoft will deny access to its attendance report and attendance will not sync.
In short: the session creator, the connected Microsoft account, and the Teams meeting organiser must all be the same person.
How Attendance Tracking works
Automatic Flow
- An admin creates an Event Schedule with Sessions linked to Teams meetings
- Learners sign up for the schedule
- The Teams meeting takes place
- After the session's scheduled end time, the system automatically triggers an attendance sync job
- The job identifies the session's organiser (its author) and loads that person's stored Microsoft connection, refreshing the access token automatically if needed
- It fetches the attendance report for the organiser's own meeting from the Graph API (/me/onlineMeetings)
- It matches attendees to signed-up learners by email address (case-insensitive)
- Attendance status is calculated and saved to each learner's signup record
Manual Refresh
Admins can also manually trigger an attendance refresh from the Session's Manage Attendance page by clicking Refresh Attendance. This is useful if:
- The automatic sync hasn't run yet
- You want to get updated data after a session that is still in progress
- There was an error during the automatic sync
There is a cooldown period between manual refreshes to avoid rate limiting.
Attendance status calculation
Attendance status is calculated based on the percentage of the meeting the learner attended:
| Status | Condition |
| Fully Attended | Attended >= 10% of meeting duration (default threshold) |
| Partially Attended | Attended > 0% but < 10% of meeting duration |
| No Show | No attendance data found |
The system uses "grace windows" to handle timing differences - if a meeting starts early or runs late compared to the scheduled times, learners are not penalised for joining at the scheduled start time.
Attendance matching
Attendees are matched to enrolled learners by comparing the email address from the Teams attendance report with the learner's email in the LXP (case-insensitive match). If a match cannot be found, the attendance record is logged but not applied.
Trouble shooting
No attendance data returned
- Check the meeting URL — ensure it's a valid Teams meeting link
- Confirm the session creator has connected their Microsoft account (Step 8)
- Confirm the Teams meeting was organised by that same person
- Check API permissions — ensure the delegated permissions are granted (and admin consent applied if your tenant requires it)
- Timing — attendance reports may not be available immediately after a meeting ends. Wait a few minutes and try refreshing
"Session author has not connected their Microsoft account"
- The person who created the session has not yet connected. They must sign in and click "Connect my Microsoft Account."
"Access denied to attendance reports" (organiser mismatch)
- Microsoft returned a permission error because the meeting was not organised by the session's connected author. The connected organiser must be the actual owner of the Teams meeting.
"Reconnect required" / authentication expired
- The organiser's connection has expired. They should click "Connect my Microsoft Account" again to reconnect. In the meantime, attendance can be imported manually.
Attendance shows for some users but not others
- Attendees are matched by email address. If a learner's LXP email differs from their Teams email, no match will be made
-
The learner must have an active signup for the session to receive attendance marking
Manage session attendance
Once registered, attendees will be marked as ‘Fully Attended’, ‘Partially Attended’ or a ‘No Show’ depending on their participation in the webinar. If the Session Type is set to ‘Hybrid’ then administrators can mark in person attendees manually or in bulk. You can also override the automatically generated attendance status if required. Attendance is stored and shown on Manage Attendance; Refresh Attendance re-pulls the latest from Teams, which only returns data once Microsoft has finished the post-meeting report.