Monday, December 23, 2024

How-to join as B2B guest a Teams meeting with ‘bypass lobby’

The lobby function in Teams gives some control over who joins a meeting, and when to allow entrance. This capability is convenient to prevent unknown people join your meeting. For known persons, it can be preferred to have ‘an open door’ policy. This can be configured via Teams policies, including for Entra ID B2B guests as known + trusted identities. However, to actual bypass the lobby, does require some ‘trickery’ on the guest side. The trick is to make sure you are indeed in a ‘known’ state in the inviting tenant; as “Unverified” you will still need to wait and enter via the lobby.
Teams Policy to allow B2B guests to bypass lobby
Join meeting in external organizing tenat still routes to lobby
Inspecting the situation from the inviting side gives indication on why the B2B guest is not automatic allowed in: the identity is not 'verified' as known:
2 ways to direct join as Entra ID B2B guest, bypassing lobby
Approach 1 is to explicit self change to the organizing tenant, before joining the meeting:
The 2nd approach is the most simple and seamless, direct join the meeting from the notification popup that the meeting is started in external tenant:
Both approaches result that on moment of joining the Teams Meeting, in the context of organizing tenant the joiner is verified as a known B2B guest, and therefore allowed to direct enter - bypassing the lobby:

Sunday, August 20, 2023

Overcome JSON column formatting limitation that it does not support Rich Text Multiline

Inspired by the visualization of Microsoft 365 roadmap, I want to achieve similar for collecting and communicating the architecture vision and refined roadmap of our ART (Agile Release Train). As the purpose is mainly about communicating, I decide to just leverage a SharePoint list for it, no need to administrate in a planning tool (eg Jira Align). In the information architecture I add a column per aspect of the architectural roadmap topics: title, description, theme, year of delivery. And for the roadmap refinement a column per year in which to enumerate the steps I foresee in that year. The steps collected in a bulleted list, thus the column must be of type Multiline / Rich Text.
However, this decision results in a visualization challenge. Standard, SharePoint truncates in ListView the value of multiline columns to 4; and the roadmap does not display in entirety. List View / JSON formatting is not helpful to resolve: 1) ColumnFormatting does not support Multiline / Rich Text, and I don’t want to reduce to plain text ("It is NOT recommended to use Rich text fields in your formats"); 2) RowFormatting requires to specify the formatting for full view, while I am satisfied with the standard formatting of all other columns.
As pragmatic resolution I decided to revert to old-skool approach of DOM formatting. In Modern SharePoint you cannot directly inject a custom style, but via Modern Script Editor this is easily possible: [[Code]].

Saturday, April 9, 2022

Too compulsive cleaning up PnPSearchResults SelectedProperties can destroy some of its behaviors

I utilize PnP Modern Search v4 for a business search solution on data that is administrated in a SharePoint list. In the business solution I display multiple list columns in the search results layout (Details List), and thus need to ensure that their mapped managed properties are included in 'selectedProperties' of the PnP Search Results webpart. Default already a lot of other properties are included in the configuration, some of which are not even present in the SharePoint list, and others that I do not intend to use. So as good citizen I limit the 'selectedProperties' to only "what you need / want to display":
Well, this good citizenship resulted that some behavior was broken: it no longer worked to open a listitem from the PnP Search Results overview. Direct cause was the property 'PreviewUrl' was without a value in the mapped search results Slots, and this was result that I excluded 'Path' from the 'selectedProperties'. Lesson: although good to limit data retrieval to only what you need; you also must have understanding of 'for what purpose you may need'.
See for more details: PnP Modern Search - Slots

Sunday, March 20, 2022

How-to Join as external attendee an access-controlled Teams Live Event without explicit Teams Guest Access

MS Teams Live Event is current the only service in the Microsoft 365 landscape that enables audience outside the own organization. Teams Live Event supports both full public (anonymous) Live Events without any access control, as well as Live Events with the permission mode 'People and Groups'. In the last mode, also externals can on named base be allowed by applying the Azure AD B2B guest concept. Besides that (1) the external must be known in the identity system of the tenant in which the Teams Live Event is produced, another requirement (2) is that the external must switch in Teams first to that tenant aka 'Organization' before allowed to join the Teams Live Event.
For reference, below the prerequisites to enable external to attend a Teams Live Event in your tenant.
On Organizing part
  • For each external that needs to be granted access, provision an Azure AD B2B guest account
  • Schedule in Teams a Live Event, with permission type: People and Groups
  • Authorize all the externals via their provisioned Azure AD B2B guest account for access to that Teams Live Event
  • Share the attendee link with the invited externals
Per external
  • Redeem the provisioned Azure AD B2B guest account
  • Enroll for Azure MFA via MS Authenticator App; against the organizing tenant
  • In Teams context; first explicit switch to ‘<organizing> tenant’ ⇒ without this, Teams displays message that you are prohibited to access
  • Then click the attendee link ⇒ and the external will be allowed to access
Externals that are authorized via Teams Guest Access concept in any arbitrary team in the organizing tenant, can do this 'tenant-switch' direct in the Teams App and web application, via so-called 'tenant-switcher':
For externals that are not within any team, there is no reason for the Teams App and web application to list that tenant as organization within the 'tenant-switcher'. The easy way out is then to just add all the authorized externals to 'a' team in the organizing tenant. But for multiple reasons this is not always a preferred / good approach. For one, it doesn't "feel right" to add persons to a team with its full set of capabilities, only because they are invited to participate in a temporary digital event. Also as all members of a team instance can 'see' all the other members, and then contact each other; via teams chat, or via the discovered email addresses. For privacy and compliance reasons the event organization might not want this, or even not be allowed to do. Another reason has to do with timing aspect: in the Teams operational model it takes unpredictable yet significant time (can take up to 36 hours) after adding an external to a team instance, before the external sees the effect of this in the 'tenant-switcher' of the own local Teams App.
Luckily there is an alternative approach in which the externals can do the 'tenant-switch'. Namely by visiting in the browser the link "https://teams.microsoft.com/?tenantId=<organizing tenant-id>". The external must then sign-in via his/her Azure AD B2B guest account, and typical also answer on multi-factor authentication challenge (imposed by the organizing / inviting tenant), and if both successful the external is then allowed in the Teams context of the event organization. For the externals that are not member of any team, Teams will display the message "You’re currently not part of any teams…".
And now from this context in Teams, the external can join via the attendee link the Teams Live Event. Be aware that this approach only works from the browser via Teams web application, the external can not watch the live event in the Teams App. But on user experience that makes no difference; Teams App and Teams web application have same behavior wrt Teams Live Event.
Update:It is also possible to achieve both via one single link: making the attendee link of the Teams Live Event tenant-switch enabled. The trick is to insert "/_?tenantId=<organizing tenant-id>" immediate after "https://teams.microsoft.com" and before the "/l/meetup-join/..." part. On navigating to this link, the browser (1) first switches in Teams Web Application to the referred tenant, and (2) next from that context it joins the Teams Live Event in that same tenant.

Saturday, March 19, 2022

Best-practices for delivering webcast via Teams Meeting

Complementary to post Bad-Practice: Include 'presentation / video production' as camera input in MS Teams Meeting + Teams Live Event, here some best-practices to apply upon delivering a webcast / digital event via Teams Meeting.
Tips to practice / try-out:
  1. Ensure that the workstation on which you 'produce/present' the digital event, and are including camera, audio and likely also content, is qua CPU and memory sufficient equiped for it. And close all other applications, in particular CPU, memory and/or network intensive, on it during the period of the digital event production.
  2. Be in particular careful with using OBS Studio on that same workstation. I love OBS for its webcast / digital events capabilities, but it puts extensive strain on the workstation. Together with Teams Meeting, this might become a bottleneck; and result that the production in Teams Meeting suffers. Better to have OBS on another workstation, and cast its output to the workstation on which presenting in Teams Meeting.
  3. In the Teams Meeting where the webcast is produced, turn off 'incoming video' of the attendees aka audience.
  4. If possible, connect to wired iso wifi; prevent potential disruption of WIFI signal, hotspots, others consumers.
  5. Dedicate the 'presenter' role to only those persons that will actually present; avoid the role is assigned to everyone in the audience.
  6. In case you need 'access-control' on who is allowed as audience, apply the lobby function (Teams Meeting Options). Note: in case you apply the lobby as manual access-control, there is an additional reason to assign 'presenter' to only event organization; any 'presenter' is namely empowered to allow people in from the lobby. Even external attendees with presenter role can do this, risking the 'access-control' via lobby.
  7. Include 'production' from external device (mixer, encoder) as shared content, do not misuse the possibiliy to include it as 'attendee camera' (see Bad-Practice: Include 'presentation / video production' as camera input in MS Teams Meeting + Teams Live Event).
  8. In case producing without external device, then use PowerPoint Live to include PowerPoint presentation. And leverage Teams Meeeting 'presentation modes' (link) to turn the layout of the digital event in a more professional / (televion) reporter look.

Saturday, March 12, 2022

Bad-Practice: Include 'presentation / video production' as camera input in MS Teams Meeting + Teams Live Event

Via MS Teams Settings you have the option to configure an external camera as device. This can be used to include the video output signal from external mixer (e.g. vMix, OBS Studio) into a Teams Meeting or Teams Live Event, and then to spotlight it for all participants in the Meeting.
But be aware of a serious caveat with such setup. From Teams perspective, that video signal is regarded as the camera display of 'face of a participant'. And Teams will continuous process it for optimal contrast of 'face' against the background. As long as in the video production there is indeed only a face, there will not be a real issue. But in situations where there is not (only) a face in the video production, e.g. slides are presented, the mismatch with Teams understanding results inevitable that the slides are on occassion not sharp rendered but blurry. The correct way to include the produced video signal into a Teams Meeting or Teams Live Event is via 'Share Content'; Teams Meeting prioritizes 'screen / content sharing' above the local 'camera'.
Nice outline on this:

Friday, March 11, 2022

Tip: Reuse authentication of MFA secured account over multiple Connect-PnPOnline calls

A best security practice to connect into SharePoint Online is configure MultiFactor Authentication (MFA). When connecting from PowerShell to SharePoint Online this can give some challenges, as the default 'Credentials' based logon is not MFA aware. Resolution for this is to use either '-Interactive' or '-PnPO365ManagementShell' flag: both result that you are enabled to interactive address the MFA challenge.
Need to address the MFA challenge is acceptable to do one-time. But in an administration context, it might be that you need to execute settings over a set of sitecollections. Then it is not a pleasant experience to everytime need to (re)logon including MFA challenge. Common way to address this is by piping the authenticated SPO connection into the subsequent PnP calls. But Connect-PnPOnline does not support the '-Connection' flag (other PnP cmdlets do support it; PnP is not consistent across all its cmdlets). But I found an alternative that works:
  • $connection = Connect-PnPOnline -Url $spoAdminUrl -PnPO365ManagementShell -ReturnCollection
  • Connect-PnPOnline -Url <Url to other site collection> -Interactive -ClientId $connection.ClientId