Skip to content

Microsoft Teams — Personal Security Coach

If your organization runs on Microsoft 365, the daily security question comes to every employee inside Microsoft Teams — as a personal chat with the BS Security Coach. You install it once for everyone; employees never sign up for anything.

What employees get

Every day What happens in Teams
Morning A card: "Your daily security question is ready — Start (30 seconds)" with their streak, points and rank.
Tap Start The same card turns into the question with the answer choices and a timer — no clutter.
Answer The card turns into the result: ✅ / ❌ / ⏱, the explanation, points earned, streak and total. Wrong answers cost nothing — they teach.
Afternoon (optional) The morning card is refreshed with a gentle reminder for anyone who hasn't answered.
Coaching moments Clicked a simulated phishing link → "here's what gave it away". Reported one → 🎉 +25 points. Finished a training module → 🎓 +20. Hit a 3 / 7 / 30-day streak → 🔥 bonus.
Security broadcasts Tips, warnings and announcements your admin sends from BongoShield — with a one-tap Got it acknowledgement.
Report suspicious Right-click any Teams message → Report to BongoShield, or type report to the coach and paste an email, SMS or link.

Typing help, score, leaderboard or training to the coach shows the matching card.

Set-up (about ten minutes)

You need a Teams administrator and a Microsoft global administrator (for the one-time permission), and you must be a BongoShield Owner or Admin.

  1. Upload the app — in BongoShield go to Settings → Integrations → Microsoft Teams → Download Teams app package. Then either:

    • in Teams itself: Apps → Manage your apps → Upload an app → Upload an app to your org's app catalog (Teams admins only), or
    • in the Teams admin center → Teams apps → Manage apps → Upload new app.

    Either way the coach appears for everyone under Apps → Built for your org and its status in Manage apps should be Allowed. 2. Connect your tenant — on the same BongoShield card click Grant install permission and accept as a global admin. Microsoft shows exactly three permissions, all scoped to installing our own app:

    Permission Why
    Allow the app to manage itself for all users (TeamsAppInstallation.ReadWriteSelfForUser.All) install the coach for your staff — it cannot install any other app
    Read all app catalogs (AppCatalog.Read.All) find the coach in your organization's catalog
    Read all users' full profiles (User.Read.All) match each employee's email to their Teams account

    (If you already connected Microsoft for BongoShield sign-in, the tenant is detected automatically; an admin can also type pair ABCD-1234 to the coach using a code from the card.) 3. Install for everyone — click it on the card. BongoShield installs the coach into every enrolled employee's Teams in the background. Re-run it any time after adding people. 4. Send test to me — a card from BS Security Coach should appear in your Teams chats within seconds. 5. Tune — daily send time and timezone, the reminder, which coaching nudges to send, and whether broadcasts go to Teams.

Updating to a new version of the coach

When BongoShield releases a new package version, download it again and, in the Teams admin center → Teams apps → Manage apps → BS Security Coach (open the app's own page), click Upload file under New version. Uploading from the Teams client cannot update an existing app. Your policies and everyone's installation carry over.

Pinning the coach

In the Teams admin center you can pin BS Security Coach in the app bar for all users (Teams apps → Setup policies) so the daily question is always one tap away — optional, but it lifts answer rates.

Announcements channel (optional)

Point the coach at one Teams channel and it will post your admin broadcasts and a weekly top-10 leaderboard there — on top of, not instead of, the personal daily question in each employee's 1:1 chat.

  1. Re-upload the app package. The Teams package moved to version 1.1.0 to add team and group-chat scopes, so an install from before this feature needs the new package: Teams admin center → Manage apps → BS Security Coach (open the app's own page) → Upload file, same as any other version bump.
  2. Add the coach to a Team. Open the Team → ⋯ → Manage team → Apps → Add an app → BS Security Coach. BongoShield can only offer channels of Teams the coach has actually been added to — this is a deliberate security boundary, not a missing feature.
  3. Pick the channel in BongoShield. Go to Settings → Integrations → Microsoft Teams → Announcements channel, pick Team › channel from the list and Save, then Send test post to confirm it landed.
  4. Tune it. On the same section: toggles for Post broadcasts here and Post weekly leaderboard, plus the weekday and time the leaderboard goes out (default Monday 09:00, org timezone). Remove stops both and clears the channel.

The weekly leaderboard shows first names only, the top 10 by points for the current month's season, and how many people played this month — never a full name list or individual answers.

What is posted there / what never is

Posted to the channel Never posted to the channel
Admin broadcasts (no Got it button — acknowledgement stays in the personal chat) The daily question, or anyone's answer
Weekly top-10 leaderboard (first names, monthly season) Individual scores, streaks or risk data
— Nudges (streak, sim click/report, training)

@BS Security Coach score, training, today or leaderboard typed in a channel or group chat is answered with a private DM to the person who asked, plus a short one-line reply in the channel pointing them to it. Only help and report reply directly in the channel. Report to BongoShield on a channel message works the same as it does everywhere else.

Broadcasts sent from Popup Broadcast default to "Also post to the announcements channel" switched on — turn it off per-broadcast for anything that shouldn't go beyond personal chats.

Good to know

  • The question, scoring, streaks and risk score are the same as every other BongoShield channel. Someone who already answered today in Outlook or the portal isn't asked again in Teams.
  • BongoShield asks for one Microsoft permission — installing its own app for your users. It never reads mail, files or chats. Reported messages contain only the text the employee chose to report.
  • Reporting a BongoShield phishing simulation credits the campaign and the employee; reporting a real suspicious message files it for your security team. The employee sees the same acknowledgement either way, so the tests stay realistic.
  • Enrolment is automatic when you allow it. If your BongoShield Just-in-time provisioning mode is All, every employee who receives the coach (including everyone an org-wide Teams app policy installs it for) is enrolled in BongoShield the first time the coach reaches them — up to your licence's seat cap. Set the mode to Web only or Off if you prefer to enrol people yourself.
  • Disconnect on the card unbinds the tenant and stops all messages.

Troubleshooting

Symptom Likely cause Fix
"Install for everyone" says the app was not found The package hasn't been uploaded/allowed in the Teams admin center yet Finish step 1, then run it again
Some users show as unmatched after the install Their BongoShield email differs from their Microsoft account (mail/UPN) Align the email in BongoShield → Users, re-run the install
A user never gets the morning card They blocked the bot, or the app was removed for them Ask them to unblock / reinstall from the Teams app store, or re-run the install
"Tenant not connected" Consent was declined or done by a non-admin Repeat step 2 as a Microsoft global admin
"Consent unverified" after accepting The permissions were accepted by someone without rights to grant them org-wide, or a permission was skipped Repeat step 2 as a global administrator and accept all three permissions
Teams says "This app has already been submitted in your org" when uploading You're uploading a new version from the Teams client Use the admin center: open the app's page → Upload file (see note above)
"No channels to pick" under Announcements channel The coach hasn't been added to a Team yet, or you're still on the pre-1.1.0 package Add the coach to a Team first (Team → ⋯ → Manage team → Apps → Add an app), or re-upload package 1.1.0 if you haven't already