Custom Teams App 401 Unauthorized issue

Nimesh 230 Reputation points
2026-06-10T05:03:22.95+00:00

Hi Everyone,

I created a custom Teams App using the developer portal to embed a SharePoint site within Teams. Below is the manifest file.

User's image

I have added "/?app=portals" because I want to display site navigation at the top. When using below, site navigation is not displayed properly.

_layouts/15/teamslogon.aspx?spfx=true&dest=SITEURL"

When I use the "/?app=portals", sometimes it displays below error. When I click on CoPilot App and then click on this app again, it works.

User's image

The 2nd option makes sure that it loads Teams credentials before loading the app but it doesn't display site navigation. 1st option displays site navigation but doesn't load Teams Credentials sometimes before loading the app.

How to have both these options where site navigation is also displayed and Teams Credentials are loaded before loading the app?

Please note that I do not want to have a separate VIVA Connections page because I want this as a separate app.

Microsoft Teams | Development
Microsoft Teams | Development

Building, integrating, or customizing apps and workflows within Microsoft Teams using developer tools and APIs

0 comments No comments

Answer accepted by question author
Sayali-MSFT 6,476 Reputation points Microsoft External Staff Moderator
2026-06-11T06:57:17.77+00:00

Hello @Nimesh,

You cannot reliably achieve both behaviors together.

  • Using teamslogon.aspx ensures Teams authentication loads correctly but renders SharePoint in embedded/SPFx mode, which hides the top navigation.
  • Using /?app=portals shows full site navigation but may fail intermittently because authentication isn’t completed before the page loads.

There is currently no supported way to guarantee both pre-authentication and full portal navigation in a single Teams tab, so you must choose between consistent auth or full navigation experience.
Reference:
https://learn.microsoft.com/en-us/microsoftteams/platform/resources/samesite-cookie-update


Your feedback is important to us. Please rate us: 🤩 Excellent 🙂 Good 😐 Average 🙁 Needs Improvement 😠 Poor

Was this answer helpful?

1 person found this answer helpful.
0 comments No comments

Answer accepted by question author
Anonymous
2026-06-10T06:10:18.6633333+00:00

Hi @Nimesh

Based on the behavior you described, it appears that the two URL approaches are triggering different SharePoint-in-Teams experiences.

When using /_layouts/15/teamslogon.aspx?spfx=true&dest=<SITEURL>, the teamslogon.aspx endpoint is designed to establish the required Teams/SharePoint authentication context before redirecting the user to the destination page. This generally provides more reliable sign-in behavior within Teams, but the SharePoint site navigation/header may not be displayed because SharePoint can render content differently when hosted within Teams compared to the full browser-based portal experience.

When using <SITEURL>?app=portals, the SharePoint portal experience is loaded directly, which allows the site navigation to be displayed. However, this approach does not appear to use the same Teams authentication bootstrap mechanism as teamslogon.aspx, which may explain why the page occasionally fails to load correctly until you navigate away and return to the app.

At this time, there does not appear to be a Microsoft-documented or supported method that guarantees both behaviors simultaneously within a custom Teams app tab. The ?app=portals parameter is used by SharePoint portal experiences (including Viva Connections), while teamslogon.aspx is designed to establish Teams authentication before loading SharePoint content. As a result, the behavior you are seeing is most likely a limitation of the current integration model rather than a manifest configuration issue.


Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread. 

Was this answer helpful?

1 person found this answer helpful.

1 additional answer

Sort by: Newest
  1. AI answer

    2026-06-10T05:03:39.88+00:00

    Use the Teams–SharePoint integration pattern that goes through TeamsLogon.aspx and teamshostedapp.aspx so that Teams credentials are always established, and then let SharePoint render the page (including navigation) instead of calling the site URL directly with ?app=portals.

    For a personal tab, the manifest should use the Teams-hosted SPFx URL format, for example in staticTabs[..].contentUrl:

    https://{teamSiteDomain}/_layouts/15/TeamsLogon.aspx
      ?SPFX=true
      &dest=/_layouts/15/teamshostedapp.aspx%3Fteams%26personal%26componentId={{SPFX_COMPONENT_ID}}%26forceLocale={locale}
    

    Key points from this pattern:

    1. TeamsLogon.aspx ensures the Teams user is authenticated to SharePoint before the destination page loads, avoiding intermittent 401 errors.
    2. teamshostedapp.aspx hosts the SharePoint Framework component inside Teams. Navigation and other SharePoint chrome are controlled by the SharePoint page that hosts the component, not by appending ?app=portals directly in the Teams manifest URL.
    3. Use the runtime tokens:
      • {teamSiteDomain} for the tenant URL.
      • {teamSitePath} if targeting a specific site path.
      • {locale} for localization.
    4. Ensure the manifest includes the required webApplicationInfo block so SharePoint APIs work correctly when called from Teams:
    "webApplicationInfo": {
      "resource": "https://{teamSiteDomain}",
      "id": "00000003-0000-0ff1-ce00-000000000000"
    }
    

    To keep navigation while avoiding 401s, host the desired navigation experience on a SharePoint page (or SPFx page/portal) and reference that page via the Teams-hosted URL pattern above, instead of using the raw site URL with ?app=portals in contentUrl.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.