Security and data handling

Teams Phone Configurator writes to Microsoft Teams, so the permission question matters more than for a read-only tool. This page lists exactly what it holds, and why that is still a smaller surface than handing PowerShell to everyone who assigns numbers.

At a glance

Permissions

The app’s service principal needs the following. They are all admin-consented and used app-only:

PermissionTypeUsed for
TeamsTelephoneNumber.ReadWrite.AllApplicationReading number assignments, assigning and unassigning numbers
TeamsPolicyUserAssign.ReadWrite.AllApplicationApplying the location’s calling policies and dial plan to the user
User.Read.AllApplicationFinding the employee in your directory and checking their Teams Phone licence before anything changes
Teams Administrator (directory role)Role on the service principalRequired by the Teams telephony operations the app performs

This is a write-capable integration, and it should be reviewed as one. The point of the design is where that power sits: in one service principal with a documented scope, instead of in the PowerShell rights of every engineer and service desk agent who provisions numbers today.

Sign-in and roles

What is stored, and where

The database holds your locations, number ranges, the user-to-number assignments, and an audit log of who assigned what to whom, when, and whether it succeeded. It runs on SQL Server (the free Express edition is sufficient) on infrastructure you control.

Audit retention is configurable from 1 day to 10 years. Set it to match your records policy; the default is 30 days.

Hosting and network

Who builds it

Teams Phone Configurator is built by IDE Solutions UG (haftungsbeschränkt), Krombach, Germany, registered at Amtsgericht Aschaffenburg under HRB 17253 (see the Impressum). If you run it yourself, we have no access to your tenant or your data. If we operate it for you, the contract includes a data processing agreement under Art. 28 GDPR.

See also deployment options and pricing.

Security review questions

Can the app change our voice routing or SBC configuration?

No. It assigns and removes numbers and applies policies your engineers already defined. Operators, session border controllers and policy definitions stay in the Teams admin center.

Do service desk agents need Teams admin rights?

No. They sign in to the app with the TelephonyAdmin app role. The privileged permissions sit with the app’s service principal, not with each person who provisions numbers.

Does it send data anywhere except Microsoft?

No. It connects to Microsoft Graph and Entra sign-in only. There is no telemetry and no connection to IDE Solutions.

Review the permissions with us

We go through the service principal, the roles and the audit trail with your team during the demo. Book a demo