Skip to main content
You can put a chat agent you build — your instructions, your tools, your branding — in front of your own technicians in Microsoft Teams. It installs into your own Microsoft 365 tenant as its own bot, separate from the Neo AI Agent app, and runs with the full MSP toolbox you give it. This is the technician-facing counterpart to the branded end-user bot: same channel machinery, but pointed at your own tenant and your own team instead of a client’s.

Neo Support Agent vs. your own internal agent

Two different things can answer your technicians in Teams — and it’s easy to conflate them. Pick by what you need: Reach for the Neo Support Agent for “how does my Neo setup work?” or “find me a similar past ticket.” Build your own internal agent when you want a purpose-built assistant with your prompt and your tools — see the five common internal patterns, from a research copilot and on-demand reporting to a self-serve ticket dispatcher. You don’t have to start from scratch: copy the Neo Support Agent into your own editable agent and build from there.
The two coexist: a technician can have both the Neo AI Agent app and your custom bot in their Teams, side by side. Workflow notifications and Technician-in-the-Loop approval cards always arrive through the Neo AI Agent app — never through a custom internal bot.Your custom internal bots coexist too: you can run several internal bots at once — say one for dispatch and one for documentation — because each new internal channel gets its own bot identity. And an End-user bot can be installed in your own tenant alongside them, if you want to see exactly what your clients’ employees see. Internal channels created before this capability share one bot identity; if a new install reports the identity is taken, the fix is self-serve: open the older internal channel, remove its registration under Install in your tenant, and generate a new install link — the channel moves onto its own bot identity automatically. Finish the whole move before you install anything else on the shared identity. Removing the registration does not take the old app out of your Teams catalog, and neither does generating the link — the app is replaced when an administrator opens that link and approves it. An end-user bot installed in between would land on an identity the old app still holds, and your technicians’ existing chats would stop sending. Neo refuses that install until you have generated the new link. The refusal lifts then, before the approval, so wait for the approval yourself.Install from the new link, then retry the install that was blocked. Neo updates the app in your Teams catalog in place, so there is no old app to remove. Each technician’s existing chat with the bot stays behind, because Teams attaches a chat to the bot identity. Neo posts a message into that chat with a link to the new one; technicians can hide the old chat. The same link is on the channel itself as Open the chat in Teams, so you can re-send it to anyone who lost the message. If you then install an end-user bot in your own tenant, it takes over that old chat, and its first message says so.

Deploy your internal bot

Before you start: an Internal chat agent you’ve tested, an admin sign-in to the dashboard, and the ability to install custom Teams apps in your own Microsoft 365 tenant.
1

Build an Internal chat agent

Create a chat agent and set its Audience to Internal. An Internal agent carries the MSP toolbox you give it — PSA, RMM, Microsoft 365, documentation, cross-company lookups — unlike an End-user agent, which is locked to one company. For a head start, copy the Neo Support Agent and customize the copy instead of starting blank. Test it from ChatAgentsChat.
2

Create an Internal channel

Open ChatChannelsNew Channel. Set Audience to Internal, pick the Teams transport, and assign your internal agent (the agent picker only shows agents whose audience matches). Under Branding, set the name, icon, and welcome message your technicians will see — blanks use a Neo default. Leave the status on Active.
3

Install it in your tenant

On the saved channel’s page (Chat → Channels → open the channel), under Install in your tenant, click Generate install link and open it yourself as a Teams or Global administrator of your tenant. One sign-in publishes the bot into your own Microsoft 365 and switches routing on.
That sign-in adds a Neo Installer app to your tenant’s Enterprise applications — this is expected and safe: it only publishes your bot to the catalog and gets no standing access to your data. If a sign-in ever errors, open the link again — don’t delete the Neo Installer app to “start fresh.” Deleting it soft-deletes the underlying service principal and keeps its app ID reserved, so the next sign-in fails with AADSTS650051: …service principal name is already present, and the deleted object isn’t shown on the portal’s Deleted applications page. If you’ve already hit this, see recovering from a failed install.
Prefer a manual upload? Teams app package gives you the .zip to sideload in your Teams admin center; then use Already installed it manually? Register directly to bind routing.
4

Make it reach your team

Publishing puts the app in your org catalog — to give it to everyone, open your Teams admin centerManage apps, find your app, then Users and groupsInstallsInstall appInstall to: EveryoneApply. New technicians then get it automatically.
5

Verify

Click Open the chat in Teams under Install in your tenant and ask the bot something. It answers as your MSP with the toolbox you configured — it can work across all your companies, exactly as the same agent does in the dashboard. Typing “start a new chat” starts a fresh conversation.Use that link rather than searching Teams. A bot nobody has messaged yet is in no chat list and no search result, and a chat left over from an earlier bot identity carries the old name. The link always opens the right one, and it is the link to pass to a technician who cannot find the bot.

Who can message it

Who may message an internal bot is set under Roles & AccessChat Agent Access (Everyone, Admins only, or Specific people), exactly as for any internal chat agent. A technician who isn’t permitted gets “You don’t have access to this assistant” in Teams. Under Admins only or Specific people, a technician needs a membership in Roles & Access to be admitted at all. Add the ones who only use Teams through Add technicians, with the Chat only role. Messaging the bot and reading your company’s data through it are separate settings. A technician in Teams with no dashboard account may still be allowed to message it, and what it may read for them comes from AI chat data access — their own grants, or the workspace default for people without an account.

Why it installs only in your own tenant

An Internal channel can be installed only in your own Microsoft 365 tenant. Because it runs with your full, cross-company MSP toolbox, Neo refuses to install it into a client tenant — that would hand a client’s employees an agent that can see your whole client base. The dashboard offers an end-client-company picker only for End-user channels, and the server enforces the same rule regardless of how the request is made. To serve a client’s employees instead, build an End-user bot: those are scoped to one company by construction and safe to install in a client’s tenant.

Using it in a chat with a client

You can add an internal bot to a group chat that includes people outside your tenant — a client in a federated (external) chat, for example — and your technicians can use it there. A tech can pull a ticket up, check a device, or look something up without leaving the client’s chat. Only your own people can ask it anything, or approve what it wants to do. It never answers, takes an action, or runs a command for anyone outside your tenant — a federated client, or a guest account in your directory. When one of them asks it something or taps one of its cards, it replies “I can only answer questions from people inside the organisation I work for”. Your technicians keep using it normally in the same chat. This holds in every conversation, a one-to-one chat with the bot included. A guest account lives in your own directory, so a guest can open a one-to-one chat with the bot — and the bot declines it there too.
The answer is posted into the chat, so everyone in it can read it. The bot works with your full cross-company toolbox, so treat asking it something in a client’s chat exactly like typing the answer in yourself: it is your technician’s call what to surface there.
If you want a bot a client can talk to directly, that is an End-user bot — scoped to one company by construction.
If the bot answers “I couldn’t confirm who you are just now”, Microsoft did not return the sender’s profile in time. Send the message again.

Branding updates

Editing the welcome message or the assigned agent takes effect immediately. Changing the display name or icons changes the installed Teams app, so click Push update under Install in your tenant to re-publish to your tenant (or, for a manual-zip install, re-upload the package in the admin center). This mirrors the end-user bot’s update flow. If a technician’s Teams then says You cannot send messages to this bot, have them quit and reopen Teams (details).