---
title: "Creating a Teams Service Account"
canonical: "https://help.callroute.com/space/CKB/721125442/Creating%20a%20Teams%20Service%20Account"
format: markdown
---
**Applies to: **[callroute] [orto] 

A service account provides an efficient way to connect Microsoft Teams and Callroute/Orto. The configuration and management tasks from the Callroute portal will use the service account for purposes of access. This makes configuration easy and allows Administrators and Managers in your organisation to have greater control over the access permissions we use to complete the configuration tasks.

This guide must be followed by someone in your organisation who manages your Microsoft 365 setup.

### Create an Office 365 Service Account

Go to the [Microsoft 365 Admin Center](https://admin.microsoft.com/) and sign in using an account with Administration privileges.

Click **Users** and then **Active users** in the top left-hand corner

![Active user dropdown screenshot]()

Click **Add a user**

![Add active user screenshot]()

Complete the information requested, and click **Next**

![Basic setup screenshot]()

Scroll down the list and select - **Create user without product license (not recommended)** – a license is not required for a Service Account.

![Create without a license screenshot]()

Within the Roles section click - **Admin center access**

![Select role screenshot]()

Now scroll and expand - **Show all by category**

![Show by category screenshot]()

## Callroute Voice Requirements - [Skip to Orto](https://help.callroute.com/space/CKB/721125442/Creating+a+Teams+Service+Account#Orto-or-Orto-Pro-Requirements)

**Applies to **[callroute] 

Now grant the new service user the relevant roles.

*A Microsoft user account in your target Microsoft tenant with the following ****Administrator rights***:

- **Global Administrator**

or if you prefer to be more granular the below combination can be used:

- **Teams Administrator**
- **Domain Name Administrator**
- **User Administrator**
- **Application Administrator**

You will also require* one ****unassigned**** Microsoft 365 or Office 365 user license in your 365 tenant*. The following license types can be used (the is for purposes of creating a user for domain verfication):

- Teams Common Area Phone
- A1, A3, A5 – Microsoft Edu A1-5 SKUs
- O365 Business Essentials or Premium
- E1, E3, E5
- F1, F3
- Microsoft Teams Rooms Basic
- Microsoft Teams Rooms Pro
- Microsoft Teams Trial (Microsoft Team Exploratory)
- Microsoft Teams Commercial Cloud

![Free license screenshot]()

When the Callroute service is initially configured, a temporary User account is created in Office 365 to complete the activation. This user is assigned a license during the activation process.  Once the integration is finished, you can safely remove this user from your Office 365 setup and unassign the license.

![Teams gateway item screenshot]()

## Orto or Orto Pro Requirements

**Applies to **[orto] 

You will need to ensure you have the following assigned to the new service user:

*A Microsoft user account in your target Microsoft tenant with the following ****Administrator rights***:

- **Global Administrator**

or if you prefer to be more granular the below combination can be used:

- **Teams Administrator**
- **User Administrator**
- **Application Administrator**

## Descoping Your Service Account after initial set-up

**Applies to **[callroute] 

As previously mentioned, the initial deployment requires elevated admin rights to perform the setup. These are different from what is needed to operate Callroute post-deployment. **Domain Name Administrator** and **Application Administrator** can be safely removed with no impact on functionality, leaving just **Teams Administrator.**

It is possible to be more granular and use **Teams Telephony Administrator** **(TTA)** or **Teams Communication Administrator (TCA) **vs **Teams Administrator**; however, note that there are limitations associated with the policies that can be applied using the Persona feature (policies will be limited to voice - **TTA** or voice and collaboration - **TCA**). It is therefore recommended **Teams Administrator** be used.

> ⚠️ Please note that these roles are not recommended for use with Orto due to the wider Orto feature set (Licenses and Teams Group management) .

**Applies to ** ** **[orto] 

If you use Orto Standard or Pro, the roles assigned to the service account user will dictate the enabled features set. Post deployment for full functionality, the following is required:

- **Teams Administrator**
- **User Administrator**

> 📝 You can reduce the permission further to just **Teams Telephony Administrator OR Teams Communication Administrator vs Teams Administrator ***if* you don’t use the Teams Groups, License assignment features. However, noting the limitations associated with managing non voice related policy types.

#### Using Teams Telephony Administrator

#### **Applies to **[orto]  [CALLROUTE] 

Using this role, you will be able to:

- Assign phone numbers
- Assign calling related Teams policies
  - Dial Plan
  - Voice Routing Policy
  - Call Park Policy
  - Caller ID Policy
  - Call Hold Policy
  - Calling Policy
  - Emergency Calling Policy
  - Emergency Routing Policy
  - Shared Calling Policy
  - IP Phone Policy
  - Voicemail Policy
  - SBA Policy
  - Voice App Policy
- Assign Teams Phone users to call queues

You **will not be** able to:

- Assign any other Teams user policy not listed above, even if they are configured in Orto Personas
- Assign Microsoft Licenses
- Add users to Teams teams
- Use Orto Pro automation rules for automatic provisioning where any of these limitations are configured

Using **Teams Communication Administrator** extends the manageable policy set to meetings.

More details on the various Teams Administrator roles can be found on the [Microsoft Learning site](https://learn.microsoft.com/en-us/microsoftteams/using-admin-roles).


> ⚠️ We don’t limit the configurable policies by Teams Admin role within Orto to prevent you from misconfiguring or trying to assign policies, licenses, and teams that aren’t compatible with this admin role. 
> ⚠️ 
> ⚠️ Doing so will produce errors in the system, and provisioning may fail if personas or automation rules contain incompatible policies.
> ⚠️ 
> ⚠️ Therefore we strongly recommend using the **Teams Admin role** for the best experience with Orto.

> ℹ️ If you delete the Callroute or Orto service want to redeploy to your tenant, then you will need to re-elevate the service account to contain the original permissions for the purpose of redeployment.


Make a note of the **Username** and **Password**.  You will need these credentials when you add Microsoft Teams to your Callroute setup. Once finished, click **Close**.

![Callroute service added screenshot]()