Troubleshoot Microsoft Teams for Employee Service (ITSM)
When someone reports a Microsoft Teams for Employee Service failure — can't log in, a tab won't load, the feature isn't showing, the Agentforce agent won't reply, swarming or SSO is broken — this skill connects to the org, runs the pass/fail checklist for that specific problem, and reports each setting's actual value plus the exact Setup path to fix any that are wrong. It replaces "check every setting by hand" with a targeted, verified diagnosis.
Every read dispatches through headless-360 (dispatch_readonly for queries, dispatch only
for the optional swarming-token clear). No org password is needed.
Scope
- In scope: Diagnosing an already-attempted Teams ITSM setup that is failing. Routing the reported symptom to the right checklist and checking the exact settings it requires (CORS, External Client App, feature toggles, PSLs, profile session settings, auth provider, named credentials, messaging channel, Agentforce agent).
- Out of scope: First-time enablement (use
service-itsm-teams-configure/-itservice-configure/-itdesk-configure), building the embedded agent from scratch (useservice-itsm-teams-employee-agent-configure), and non-Teams Salesforce debugging.
Read-only by default. Every check is a
dispatch_readonlyquery — running the full checklist changes nothing. The only state-changing action is the optional swarming OAuth-token clear at the very end, and only with explicit user confirmation.
Step 1 — Identify the problem and collect inputs
Ask the user for their problem description if not already given. Match it to a checklist using
the Feature Map in references/configuration-checklists.md [blocked].
Some problems need extra inputs — ask for them up front:
Do not run the agent-specific checks until you have the mandatory inputs for that checklist
(e.g. don't skip asking for the end-user username on a login issue — the per-user checks are
MANUAL_CHECK_REQUIRED without it).
Step 2 — Route to the checklist
Pick the checklist from the Feature Map, then run its checks in order from
references/configuration-checklists.md [blocked]:
When an app is named for an SSO issue, run both the SSO checklist and the matching login
checklist (LOGIN_DESK / LOGIN_SERVICE_CCP / LOGIN_SERVICE_UEL) — skip duplicate checks.
Step 3 — Run the checks
Execute each check's query via dispatch_readonly (queries and API fields are spelled out in the
reference). Record for each check: a status and the configured value actually read from
the org.
Step 4 — Report
Render a table with all four columns — #, Check, Status, Configured Value (never
omit the configured value), plus an Action Required note carrying the remediation for any
failed check. End with a one-line summary: N passed | N failed | N require manual verification.
- All passed: tell the user the Salesforce backend is correctly configured; if the problem persists, reload the Teams app (⋯ on the IT Desk/IT Service app → Reload app).
- Any failed: don't add the reload note — the per-check
Action Requiredsteps are the fix.
The full report-rendering rules, special-case notes, the example report layout, and the optional
swarming OAuth-token clear are in
references/report-generation.md [blocked].


