

# Integrations
<a name="integrations"></a>

Amazon Q Business integrations enhance user productivity by bringing AI-powered assistance directly into daily workflows. To get started, choose the integrations you want Amazon Q to integrate with. Then, deploy your integrations to bring Amazon Q's capabilities directly within those enterprise tools.

In this section, you will find the different integrations that Amazon Q Business supports and how to configure them for your company.

The following is a list of the integrations supported by Amazon Q Business.
+ **Browser extensions** (Google Chrome, Microsoft Edge, and Mozilla Firefox)

  Available for: Lite and Pro tiers
+ **Slack**

  Available for: Pro tier only
+ **Microsoft Teams**

  Available for: Pro tier only
+ **Microsoft Outlook**

  Available for: Pro tier only
+ **Microsoft Word**

  Available for: Pro tier only

**Topics**
+ [Enhancing web browsing with Amazon Q Business](browser-extensions.md)
+ [Integrating Slack with Amazon Q Business](slack.md)
+ [Integrating Microsoft Teams (Teams) with Amazon Q Business](msteams.md)
+ [Integrating Microsoft Outlook with the Amazon Q Business Add-in](integration-msoutlook.md)
+ [Integrating Microsoft Word with the Amazon Q Business Add-in](integration-msword.md)
+ [IAM roles and trust policy for your integrations](amazon-q-business-integrations-iam.md)

# Enhancing web browsing with Amazon Q Business
<a name="browser-extensions"></a>

The Amazon Q Business browser extension enhances your users' web browsing experience. As your users browse the web, the Amazon Q Assistant can answer questions, provide summaries, generate content, and complete tasks based on data made available to it or from its general knowledge right in their browser enhancing your users' productivity by bringing Amazon Q's AI-powered assistance directly into their daily workflows.

With the Amazon Q browser extension your users can:
+ Summarize a snapshot of any web page
+ Ask questions about one or more web pages
+ Access Amazon Q's general knowledge and your company's knowledge
+ Upload documents and use other features available in [the Amazon Q web experience](https://docs.aws.amazon.com/amazonq/latest/qbusiness-ug/using-web-experience.html#upload-documents).

**Topics**
+ [Configuring the Amazon Q Business browser extension for use](configuring-browser-extension.md)
+ [Removing the browser extension as an integration](removing-browser-extension.md)
+ [Using the Amazon Q Business browser extension](using-browser-extension.md)

# Configuring the Amazon Q Business browser extension for use
<a name="configuring-browser-extension"></a>

After installation and authentication, your users can access Amazon Q while browsing the web.

**Note**  
Amazon Q does not support users who authenticate using external SAML providers.
The Safari browser is not supported.
Amazon Q Business does not use user data for service improvement or for training its underlying large language models (LLMs). For more information, see [Amazon Q Business Service improvement](https://docs.aws.amazon.com/amazonq/latest/qbusiness-ug/service-improvement.html).
Upload your documents and have Amazon Q answer contextual questions about them.

**Topics**
+ [Prerequisites for integrating the Amazon Q browser extension](#browser-extensions-prerequisites)
+ [Integrating the browser extension with Amazon Q Business](#integrating-browser-extension)
+ [Activating and deploying the browser extension](#activating-deploying-extension)

## Prerequisites for integrating the Amazon Q browser extension
<a name="browser-extensions-prerequisites"></a>

As admins, before you can integrate the Amazon Q Business browser extension, you must complete the following steps.

1. [Get started with Amazon Q Business](https://docs.aws.amazon.com/amazonq/latest/qbusiness-ug/getting-started.html)

1. [Create an IAM Identity Center-integrated application](https://docs.aws.amazon.com/amazonq/latest/qbusiness-ug/create-application.html) or [Create an IAM federated application environment](https://docs.aws.amazon.com/amazonq/latest/qbusiness-ug/create-application-iam.html) and create your Amazon Q Business web experience.

1. To use this feature, do the following
   + Enable **Allow end users to send queries directly to the LLM** in your Admin controls and guardrails. For more information, see the [Response settings](https://docs.aws.amazon.com/amazonq/latest/qbusiness-ug/guardrails-global-controls.html#guardrails-global-response) topic in [Admin controls and guardrails](https://docs.aws.amazon.com/amazonq/latest/qbusiness-ug/guardrails.html) and [https://docs.aws.amazon.com/amazonq/latest/api-reference/API_ChatSync.html#qbusiness-ChatSync-request-chatMode](https://docs.aws.amazon.com/amazonq/latest/api-reference/API_ChatSync.html#qbusiness-ChatSync-request-chatMode) if you are configuring programmatically.
   + If you are using the IAM Identity Center or OpenID Connect (OIDC) provider in IAM, make sure your IAM role for an Amazon Q Business web experience using IAM Federation is up to date. For more information, see [IAM role for an Amazon Q Business web experience using IAM Federation](https://docs.aws.amazon.com/amazonq/latest/qbusiness-ug/web-experience-iam-role-iam.html).

## Integrating the browser extension with Amazon Q Business
<a name="integrating-browser-extension"></a>

To use the Amazon Q Business browser extension, you must allow it to connect to your Amazon Q Business application environment and web experience. To do this, admins can use the Amazon Q console, API, SDK, or AWS CLI.

**Topics**
+ [Using the console](#integrating-browser-extensions-using-console)
+ [Using the AWS API](#integrating-browser-extensions-browser-extensions-using-aws-api)

### Using the console
<a name="integrating-browser-extensions-using-console"></a>

1. Sign in to the Amazon Q console.

1. Choose **Applications**, then select the name of your application environment from the list.

1. Choose **Integrations** under **Enhancements**.

1. Choose **Edit** in the **Browser extensions** section on the main page.

1. Choose the **Browser extensions** your want integrate with.

### Using the AWS API
<a name="integrating-browser-extensions-browser-extensions-using-aws-api"></a>

Admin users can enable your browser extensions using the [https://docs.aws.amazon.com/amazonq/latest/api-reference/API_UpdateWebExperience.html](https://docs.aws.amazon.com/amazonq/latest/api-reference/API_UpdateWebExperience.html) and [https://docs.aws.amazon.com/amazonq/latest/api-reference/API_CreateWebExperience.html](https://docs.aws.amazon.com/amazonq/latest/api-reference/API_CreateWebExperience.html) operations.

## Activating and deploying the browser extension
<a name="activating-deploying-extension"></a>

After enabling the browser extension, complete these steps to activate and deploy it:

1. Allow-list URLs. If you are using

   1. An OIDC provider like Okta: you must configure your identity provider (IdP) to support browser extension as follows. You will need to consult your provider on how to do this.

      1. Make sure you enable refresh grants

      1. Allow-list the following URLs with the IdP

         1. Mozilla based browsers — `https://ba6e8e6e4fa44c1057cf5f26fba9b2e788dfc34f.extensions.allizom.org`

         1. Chromium based browsers — `https://feihpdljijcgnokhfoibicengfiellbp.chromiumapp.org`

   1. IAM Identity Center, the above is not required and you can move to the next step of installing the browser extension for your users.

1. Install the browser extension for all users using the software deployment processes of your organization. The following is some information about policy settings from the browser vendors using mobile device management (MDM) software that may be helpful:

   1. Firefox policy settings: [https://mozilla.github.io/policy-templates/\$1extensionsettings](https://mozilla.github.io/policy-templates/#extensionsettings)

   1. Chrome policy settings: [https://chromeenterprise.google/policies/\$1ExtensionSettings](https://chromeenterprise.google/policies/#ExtensionSettings)

   1. Edge policy settings: [https://learn.microsoft.com/en-us/DeployEdge/microsoft-edge-policies\$1extensionsettings](https://learn.microsoft.com/en-us/DeployEdge/microsoft-edge-policies#extensionsettings) and guide: [https://learn.microsoft.com/en-us/deployedge/microsoft-edge-manage-extensions-ref-guide](https://learn.microsoft.com/en-us/deployedge/microsoft-edge-manage-extensions-ref-guide)

1. Provide your selected users the browser store URL \$1 Web experience URL so they can download and install the browser extension and connect to Amazon Q.

# Removing the browser extension as an integration
<a name="removing-browser-extension"></a>

To disable the browser extension to your existing web experience, Admin users can use the Amazon Q Business console or the Amazon Q Business API, AWS SDK, or AWS CLI.

**Topics**
+ [Using the console](#removing-using-console)
+ [Using the AWS API](#removing-browser-extension-using-aws-api)
+ [Blocking and removing the browser extension](#blocking-removing-extension)

## Using the console
<a name="removing-using-console"></a>

1. Sign in to the Amazon Q console.

1. Choose **Applications**, then select the name of your application environment from the list.

1. Choose **Integrations** under **Enhancements**.

1. Choose **Edit** in the **Browser extensions** section on the main page.

1. Deselect the **Browser extensions** you no longer want integrate with.

## Using the AWS API
<a name="removing-browser-extension-using-aws-api"></a>

You can disable browser extensions using the [https://docs.aws.amazon.com/amazonq/latest/api-reference/API_UpdateWebExperience.html](https://docs.aws.amazon.com/amazonq/latest/api-reference/API_UpdateWebExperience.html) API

## Blocking and removing the browser extension
<a name="blocking-removing-extension"></a>

Once you disable your browser extension, your users will no longer be able to login. However, you will still need to take steps to uninstall the extension on user's browser via
+ Uninstall the browser extension for all users by updating the policy settings using the mobile device management software (MDM) using one of the following:
  + Firefox policy settings: [https://mozilla.github.io/policy-templates/\$1extensionsettings](https://mozilla.github.io/policy-templates/#extensionsettings)
  + Chrome policy settings: [https://chromeenterprise.google/policies/\$1ExtensionSettings](https://chromeenterprise.google/policies/#ExtensionSettings)
  + Edge policy settings: [https://learn.microsoft.com/en-us/DeployEdge/microsoft-edge-policies\$1extensionsettings](https://learn.microsoft.com/en-us/DeployEdge/microsoft-edge-policies#extensionsettings) and guide: [https://learn.microsoft.com/en-us/deployedge/microsoft-edge-manage-extensions-ref-guide](https://learn.microsoft.com/en-us/deployedge/microsoft-edge-manage-extensions-ref-guide)

# Using the Amazon Q Business browser extension
<a name="using-browser-extension"></a>

The browser extension is available to Amazon Q Business users on Google Chrome, Mozilla Firefox, and Microsoft Edge browsers.

**Topics**
+ [Prerequisites for using the browser extension](#user-prerequisites)
+ [Install and configure the browser extension](#install-configure-browser-extension)
+ [Common use cases for using the Amazon Q Business browser extension](#browser-extension-common-use-cases)
+ [Considerations for using the Amazon Q Business browser extension](#browser-extension-considerations)
+ [Troubleshooting the Amazon Q Business browser extension](#browser-extension-troubleshooting)

## Prerequisites for using the browser extension
<a name="user-prerequisites"></a>
+ You must be a user
+ Your Amazon Q Admin must connect the browser extension with your Amazon Q Business web experience.
+ Supported browsers are Google Chrome, Mozilla Firefox, Microsoft Edge, but reach out to their admin to find out which browsers are enabled for use with Amazon Q.

## Install and configure the browser extension
<a name="install-configure-browser-extension"></a>
+ To set up your browser extension, either wait for your IT department to configure and install it automatically, or follow their installation instructions.

  The following are browser extensions from third-party providers that may be helpful.
  + Mozilla based browsers — [ https://addons.mozilla.org/en-GB/firefox/addon/amazon-q-business/](https://addons.mozilla.org/en-GB/firefox/addon/amazon-q-business/)
  + Chromium based browsers (including Microsoft Edge) — [ https://chromewebstore.google.com/detail/amazon-q-business/feihpdljijcgnokhfoibicengfiellbp](https://chromewebstore.google.com/detail/amazon-q-business/feihpdljijcgnokhfoibicengfiellbp)
+ If you have an Amazon Q Business web experience and would like to connect to it, navigate to it in one of your other browser windows, the extension will automatically detect and suggest the link to connect your Amazon Q web experience. If not, you will need to paste the link to your Amazon Q web experience at the time of authenticating to the Amazon Q browser extension. Your browser extension will remember this link for future logins, but you can always choose a different Amazon Q web experience link.
+ Once you have successfully logged on, you can use your Amazon Q browser extension.

**Tip**  
You can also *pin* your Amazon Q browser extension to have it readily accessible while using your browser. Instructions for this are specific to your browser of choice. The following third-party information about pinning extensions might be helpful.  
Google Chrome — [https://www.howtogeek.com/683099/how-to-pin-and-unpin-extensions-from-the-chrome-toolbar](https://www.howtogeek.com/683099/how-to-pin-and-unpin-extensions-from-the-chrome-toolbar/)
Mozilla Firefox — [https://support.mozilla.org/en-US/kb/extensions-button\$1w\$1manage-pinned-extensions](https://support.mozilla.org/en-US/kb/extensions-button#w_manage-pinned-extensions)
Microsoft Edge — [https://www.microsoft.com/en-us/edge/features/pin-to-taskbar](https://www.microsoft.com/en-us/edge/features/pin-to-taskbar)

Safari browsers are not supported at the time.

## Common use cases for using the Amazon Q Business browser extension
<a name="browser-extension-common-use-cases"></a>

The following are some of the common use cases that will help you make the best use of your Amazon Q Business browser extension:

1. **Summarize a page**

   1. Open the Amazon Q Business browser extension

   1. Login and navigate to the web page that you want to summarize.

   1. Use the **summarize** for a summary of a snapshot of that web page for the moment when you navigated to it.

   1. Now your conversation contains a snapshot of this web page. You can continue to chat about the web page and ask followup questions.

1. **Add web pages and files as context to an Amazon Q conversation**

   1. Switch to General Knowledge mode.

   1. If you have clicked on the summarize button, the current web page is already in your conversation context. To add the current web page to the conversation without summarizing the page:

      1. Choose the paperclip icon

      1. Select add current page

   1. Ask questions about the current web page snapshot.

   1. To add a file, choose the paper clip icon and browse to the file of your choice (\$150MB maximum size limit, \$13.75MB per image)

   1. You can have up to a total of 20 web page snapshots or files in your conversation. To add another web page, navigate to the next web page that you'd like to add and repeat the first step.

   1. To remove an attachment, choose the paper clip icon and remove the web page snapshots or files of your choice.

1. **Access Amazon Q Business’ Knowledge from your company data sources**

   1. Switch to Company Knowledge mode

   1. Ask Q Business questions about your company’s data sources

   1. Get source attribution for your data sources

1. **Reset the context of your current conversation**

   1. To reset the context of your current conversation, choose the new chat bubble icon. Your chat will be free of past attachments and web page snapshots.

**Important**  
The Amazon Q Business browser extension integration does not support [actions or plugins](https://docs.aws.amazon.com/amazonq/latest/qbusiness-ug/actions.html).

## Considerations for using the Amazon Q Business browser extension
<a name="browser-extension-considerations"></a>

1. Amazon Q Business does not use customer data for service improvement or for improving its underlying large language models (LLMs). Also, none of the data you include in your browser extension conversations will be indexed into your company's Amazon Q Business instance. For more information, see [Amazon Q Business Service improvement](https://docs.aws.amazon.com/amazonq/latest/qbusiness-ug/service-improvement.html).

1. You can access all history of previous conversations (including attachments to those conversations) that have not been deleted from the Amazon Q web experience conversation history.

1. All conversations with Amazon Q including uploaded web page snapshots and files from the browser extension will be deleted after 30 days of inactivity.

1. If you close the Amazon Q browser extension, it will start a new conversation the next time you reopen it.

1. Amazon Q's responses aren't always 100% accurate. For more information, see [Hallucination](https://docs.aws.amazon.com/amazonq/latest/qbusiness-ug/concepts-terms.html#hallucination) in the topic Key concepts of Amazon Q Business.

## Troubleshooting the Amazon Q Business browser extension
<a name="browser-extension-troubleshooting"></a>
+ **My admin has enabled the browser extension, but I'm unable to login.**

  Try having a conversation on your Amazon Q web experience first and then try the browser extension again. If this doesn't work, then contact your Amazon Q admin or IT department.
+ **I am getting a "Can't access document" error.**

  This happens when a web uses an unsupported format from which the browser extension is unable to pull relevant data to provide a helpful response. If you encounter this error and would like your web page to be supported, please submit feedback via the feedback button in the browser extension
+ **Amazon Q doesn't respond helpfully or doesn't use the context of the web page I added.**

  Try starting a new chat and adding the web page snapshot or file again. If it still does not work, submit feedback using the feedback button and include any non-confidential details about the type of web page where the extension failed,
+ **I get the error, 'To use this browser extension, your administrator needs to enable "Allow end users to send queries directly to the LLM" in the Amazon Q Business console'**.

  Contact your Admin or IT department with the error.
+ **Amazon Q doesn't recognize updated information when my web page changes.**

  Amazon Q only has access to a snapshot of a web page. Similar to a photograph, this is all the information in the web page from the time it was uploaded to Amazon Q. To refresh the snapshot of your page, remove the current snapshot of the web page, choose a refreshed snapshot of the page, and choose **Summarize** or **Upload** for summarizing or further contextual analysis.

# Integrating Slack with Amazon Q Business
<a name="slack"></a>

Amazon Q Business can enhance your users' Slack experience by increasing their productivity, bringing Amazon Q's AI-powered assistance directly into their daily workflows. With the Amazon Q assistant in Slack, users can access Amazon Q's knowledge without context switching during communications. Users can ask Amazon Q questions about its company knowledge, general knowledge (if enabled), and uploaded files using the Slack AI assistant side panel. Users can also mention *@Amazon Q Business* in Slack threads to add it as a collaborator and ask contextual questions about the thread such as "*what are the action items from this thread?*" or "*summarize this thread*".

With the Amazon Q Slack integration your users can do the following:
+ Mention @*Amazon Q Business* in conversations to add it as a collaborator.
+ Ask contextual questions about conversations like "summarize this thread".
+ Access Amazon Q's general knowledge.
+ Access their company's knowledge (if enabled).
+ Upload documents and other features that they have access to in the [using the Amazon Q web experience](https://docs.aws.amazon.com/amazonq/latest/qbusiness-ug/using-web-experience.html#upload-documents).

**Topics**
+ [Configuring the Amazon Q Business Slack integration for use](slack-configuration.md)
+ [Using the Amazon Q Business Slack App](slack-using.md)

# Configuring the Amazon Q Business Slack integration for use
<a name="slack-configuration"></a>

The Amazon Q Business integration for Slack is only available for use by Amazon Q Business Pro users.

**Note**  
When Amazon Q is invoked by a user in a public Slack channel, it generates responses based on the invoking user's permissions, which may include content that other channel members aren't authorized to access. To prevent unintended exposure of sensitive information, carefully evaluate the use of Amazon Q in public channels. 
The Amazon Q Business customer integrating Slack must have a paid Slack workspace.
Amazon Q only supports user access management through IAM Identity Center for Slack integrations. This includes authentication using external SAML providers through IAM Identity Center. To integrate Slack with Amazon Q, you must create an IAM Identity Center-integrated application. For more information, see [Create an IAM Identity Center-integrated application](https://docs.aws.amazon.com/amazonq/latest/qbusiness-ug/create-application.html).
Amazon Q doesn't support Slack integrations for [Amazon Q applications using IAM federation](https://docs.aws.amazon.com/amazonq/latest/qbusiness-ug/create-application-iam.html) for user access management.
Access using the Amazon Q Business API is not supported at this time.
Amazon Q Business does not use your user data for service improvement or for training its underlying large language models (LLMs). For more information, see [Amazon Q Business Service improvement](https://docs.aws.amazon.com/amazonq/latest/qbusiness-ug/service-improvement.html).
Uploading documents and conversations will follow the same behavior as the web experience. For more information, see the [Chat and file uploads](https://docs.aws.amazon.com/amazonq/latest/qbusiness-ug/using-web-experience.html#upload-documents) section in the Using web experience topic.

**Topics**
+ [Prerequisites](#slack-configuration-prerequisites)
+ [Adding an Amazon Q Business integration for Slack](#slack-adding)
+ [Removing Slack as an integration](#slack-removing)

## Prerequisites
<a name="slack-configuration-prerequisites"></a>

As admins, before you can add the Amazon Q Business integration to your Slack, you must complete the following steps:

1. Must have a paid Slack workspace

1. [Get started with Amazon Q Business](https://docs.aws.amazon.com/amazonq/latest/qbusiness-ug/getting-started.html)

1. [Create an IAM Identity Center-integrated application environment](https://docs.aws.amazon.com/amazonq/latest/qbusiness-ug/create-application.html) environment and create your Amazon Q Business web experience.
**Note**  
Amazon Q doesn't support Slack integrations for [Amazon Q applications using IAM federation](https://docs.aws.amazon.com/amazonq/latest/qbusiness-ug/create-application-iam.html) for user access management.

1. Optionally, to enhance your end users' experience with Amazon Q in Slack, you can enable ** Allow end users to send queries directly to the LLM** in your Admin controls and guardrails. For more information, see the [Response settings](https://docs.aws.amazon.com/amazonq/latest/qbusiness-ug/guardrails-global-controls.html#guardrails-global-response) topic in [Admin controls and guardrails](https://docs.aws.amazon.com/amazonq/latest/qbusiness-ug/guardrails.html) and `chatMode` if you are configuring programmatically.

1. Add the two IAM roles and trust policies for adding integrations. For more information, see [IAM roles and trust policy for your integrations](https://docs.aws.amazon.com/amazonq/latest/qbusiness-ug/amazon-q-business-integrations-iam.html)

1. Admin access to your Slack workspace.

1. Your Slack workspace ID. Your WorkSpace ID must start with a *T*. One way to find your Slack workspace ID is by navigating to your Slack workspace and starting a chat with the *Slack Developer Tools* app running the `/sdt whoami` command. For more information, see [Locate your Slack URL or ID](https://slack.com/help/articles/221769328-Locate-your-Slack-URL-or-ID) in the Slack help center.

## Adding an Amazon Q Business integration for Slack
<a name="slack-adding"></a>

To use the Amazon Q Business Slack integration, you must allow it to connect to your Amazon Q Business application environment and web experience. To do this, admins can use the Amazon Q Business console, API, SDK, or AWS CLI.

**Note**  
This integration can only be added using the AWS Management Console at this time.

**Topics**
+ [Using the console](#slack-adding-console)
+ [Installing the Amazon Q Business App in your Slack workspace](#slack-installing)

### Using the console
<a name="slack-adding-console"></a>

1. Sign in to the Amazon Q console.

1. Choose **Applications**, then select the name of your application environment from the list.

1. Choose **Integrations** under **Enhancements**.

1. Choose **Add integration** from the **Integrations** section on the main page.

1. Choose **Slack** as your integration.

1. On the **Add Slack integration page**, enter the **Name** of your integration. This is the display name for the integration resource in AWS.

1. Add a **description** (optional).

1.  Enter your Slack workspace ID. This is a unique identifier of your Slack workspace starting and can be found using the Slack developer tools app. To find your workspace ID:

   1. Navigate to your Slack workspace and in “Apps” search for “Slack Developer Tools”.

   1.  Open the Slack Developer Tools app and run the command /sdt whoami 

   1.  You will receive a response that contains your Workspace ID starting with a “T” 

   1. For other ways to locate your workspace ID, refer to [Locate your Slack URL or ID](https://slack.com/help/articles/221769328-Locate-your-Slack-URL-or-ID) in the Slack help center.

1. Choose the type of **Service access** method that you want the Slack integration to use as authorization while accessing your service. You can **Create a new service role** or **Use an existing service role**. For more information, see [IAM role for allowing the integration to call Amazon Q Business on your end user's behalf](https://docs.aws.amazon.com/amazonq/latest/qbusiness-ug/amazon-q-business-integrations-iam-allow-integration-access.html).

1. Choose the **Access management access** for the Slack integration to authorize to connect to IAM Identity center. For more information, see [IAM role for allowing Amazon Q Business to monitor the resources that the integration creates in your account](https://docs.aws.amazon.com/amazonq/latest/qbusiness-ug/amazon-q-business-integrations-iam-allow-qbusiness-monitor.html).

1. Optionally, add any **Tags** that are relevant for this Slack integration.

1. Choose **Add integration**.

1. Once the integration has been successfully created, you will move to the **Integration details page**.

1. Choose **Deploy integration**.

1. Choose **Access Slack**.
**Note**  
This link will take you to the Slack domain outside of AWS.

1. You will continue this procedure within the Slack domain.

### Installing the Amazon Q Business App in your Slack workspace
<a name="slack-installing"></a>

The following instructions show how to install the Amazon Q Business App in your Slack workspace using a link from the Amazon Q console as shown in the previous topic.

**Note**  
Only a Slack workspace owner can use the link to install the Amazon Q App into your Slack workspace.
There can be only one instance of the Amazon Q App per Slack workspace. That instance will be connected to the application environment that integration was configured with in the previous topic.
You may see a "This app is not approved by Slack banner." This message can be ignored.

1. The link will open to a Slack login page where after you login (as admin) you will need to find and be asked to install the Amazon Q app within your Slack workspace.

1. Choose **Allow** to install your Amazon Q App for Slack.

1. Once the installation is complete, you will see the page confirming that the **Congratulations\$1 Your Slack App has been successfully installed.**

1. Choose **Open the Amazon Q Business App in Slack**.

1. This will open your Slack workspace where all users will be required to sign-in.

## Removing Slack as an integration
<a name="slack-removing"></a>

To remove the Slack integration, admin users can use the Amazon Q Business console.

**Note**  
This integration can only be removed using the AWS Management Console at this time.

### Using the console
<a name="slack-removing-console"></a>

1. Sign in to the Amazon Q console.

1. Choose **Applications**, then select the name of your application environment from the list.

1. Choose **Integrations** under **Enhancements**.

1. Find and select your Slack integration from the **Integrations** section on the main page.

1. Choose **Delete** and confirm your choice.

Once you disable your Slacks integration, your users will no longer be able to login. However you will still need to take steps to uninstall the Amazon Q Business App in your Slack Workspace.

# Using the Amazon Q Business Slack App
<a name="slack-using"></a>

The Amazon Q Business Slack app is available to all Amazon Q Business users.

**Topics**
+ [Prerequisites](#slack-using-prerequisites)
+ [Install and configure the Amazon Q Business App in Slack](#slack-using-install)
+ [Features of the Amazon Q Business Slack App](#slack-using-features)
+ [Considerations for using the Amazon Q Business App for Slack](#slack-considerations)
+ [Troubleshooting the Amazon Q Business App for Slack](#slack-troubleshooting)

## Prerequisites
<a name="slack-using-prerequisites"></a>
+ Your Amazon Q admin must connect the Amazon Q Business Slack app to your Slack workspace.

## Install and configure the Amazon Q Business App in Slack
<a name="slack-using-install"></a>

The following are instructions on how to install the Amazon Q Business App in Slack:

1. Open and login to the Slack workspace for your company.

1. Choose **More** in the left navigation, then select **Automations**.

1. Choose **Apps**.

1. Choose **\$1 Add apps**

1. Search for "Amazon Q Business" and choose **Amazon Q Business**

1. This will take you to the **About** page. Choose the 3 vertical dots (that say "more actions") to the right of the New Chat button.

1. Choose **add assistant to top bar**

1. You will now see a **Q** icon/logo on the top bar on the right where you can **access and chat with Amazon Q Business**

For more information, see [Understand AI apps in Slack](https://slack.com/help/articles/33076000248851-Understand-AI-apps-in-Slack#find-apps) in the Slack help center.

## Features of the Amazon Q Business Slack App
<a name="slack-using-features"></a>

Following are some of the features supported by the Amazon Q Slack App:
+ In direct messages (DMs) to the Amazon Q Business contact, it responds to all messages and queries.
+ In channels it responds only to @mentions, and always replies in thread.
+ Thumbs up and down buttons to track feedback and help improve performance over time.
+ Provides Source Attribution - see references to sources used by Amazon Q Business.
+ It tracks the conversation and applies context.
+ Process up to 5 attached files for contextual question answering, summaries, etc.

**Important**  
The Amazon Q Business Slack integration does not support [actions or plugins](https://docs.aws.amazon.com/amazonq/latest/qbusiness-ug/actions.html).

## Considerations for using the Amazon Q Business App for Slack
<a name="slack-considerations"></a>

1. When Amazon Q is invoked by a user in a public Slack channel, it generates responses based on the invoking user's permissions, which may include content that other channel members aren't authorized to access. To prevent unintended exposure of sensitive information, carefully evaluate the use of Amazon Q in public channels. 

1. Amazon Q Business does not use customer data for service improvement or for improving its underlying large language models (LLMs). Also, none of the data you include in your browser extension conversations will be indexed into your company's Amazon Q Business instance. For more information, see [Amazon Q Business Service improvement](https://docs.aws.amazon.com/amazonq/latest/qbusiness-ug/service-improvement.html).

1. The Amazon Q Business Slack app will have access to the same knowledge available in the corresponding Amazon Q Business web experience.

1. To reset, start new conversation, direct message as a *New chat*.

1. When you upload a file, the Amazon Q Slack app will only be able to respond from the file (and general knowledge if your Amazon Q admin has enabled it). Start a new chat if you want to return to getting answers from company knowledge.

1. Closing the Amazon Q Business Slack app side panel will end the current conversation. Users can review past conversations in Slack or all conversations from all channels (Slack, browser extensions, etc.) in your Amazon Q Business web experience. You can access all the history of previous conversations including, the names of the attachments in those conversations.

1. All conversations in Amazon Q Business are deleted after 30 days of inactivity. Slack may store conversations for longer depending on your company's Slack conversation history rules.

1. Amazon Q may provide inaccurate responses at times. For more information, see [Hallucination](https://docs.aws.amazon.com/amazonq/latest/qbusiness-ug/concepts-terms.html#hallucination) in the topic Key concepts of Amazon Q Business.

## Troubleshooting the Amazon Q Business App for Slack
<a name="slack-troubleshooting"></a>

My admin has enabled the Amazon Q Business app for Slack, but I'm unable to login.  
Try having a conversation on your Amazon Q web experience first and then try Slack again. If this doesn't work, then contact your Amazon Q admin or IT department.

I am getting a "Can't access document" error.  
This happens when a document uses an unsupported format from which Amazon Q app is unable to pull relevant data to provide a helpful response. If you encounter this error and would like your file format to be supported, please submit feedback via the feedback button in the browser extension.

Amazon Q doesn't respond helpfully or doesn't use the context of the document I added.  
Try starting a new chat and adding the document again. If it still does not work, contact your Amazon Q Business admin for further support.

# Integrating Microsoft Teams (Teams) with Amazon Q Business
<a name="msteams"></a>

Amazon Q Business can enhance your users' Microsoft Teams (Teams) experience by increasing their productivity, bringing Amazon Q's AI-powered assistance directly into their daily workflows. With the Amazon Q Assistant in Teams, users can access Amazon Q's knowledge without context switching during communications. Users can ask Amazon Q questions about its company knowledge, general knowledge (if enabled), and uploaded files using the Teams AI assistant side panel. Users can also mention *@Amazon Q Business* in Teams threads to add it as a collaborator and ask contextual questions about the thread such as "*what are the action items from this thread?*" or "*summarize this thread*".

With the Amazon Q Microsoft Teams (Teams) integration your users can do the following:
+ Mention @*Amazon Q Business* in conversations to add it as a collaborator.
+ Access Amazon Q's general knowledge.
+ Access their company's knowledge (if enabled).
+ Upload documents and other features that they have access to in the [using the Amazon Q web experience](https://docs.aws.amazon.com/amazonq/latest/qbusiness-ug/using-web-experience.html#upload-documents).

**Topics**
+ [Configuring the Amazon Q Business Microsoft Teams (Teams) integration for use](msteams-configuration.md)
+ [Using the Amazon Q Business Microsoft Teams app](msteams-using.md)

# Configuring the Amazon Q Business Microsoft Teams (Teams) integration for use
<a name="msteams-configuration"></a>

**Note**  
When Amazon Q is invoked by a user in a public Teams channel, it generates responses based on the invoking user's permissions, which may include content that other channel members aren't authorized to access. To prevent unintended exposure of sensitive information, carefully evaluate the use of Amazon Q in public channels. 
The Amazon Q Business customer integrating Microsoft Teams (Teams) must have a paid Teams organization.
Amazon Q supports users who authenticate using external SAML providers through IAM Identity Center. For more information, see [Create an IAM Identity Center-integrated application](https://docs.aws.amazon.com/amazonq/latest/qbusiness-ug/create-application.html).
Amazon Q application environment created with IAM Federation do not support integrations with Teams at this time.
Access using the Amazon Q Business API is not supported at this time.
Amazon Q Business does not use your user data for service improvement or for training its underlying large language models (LLMs). For more information, see [Amazon Q Business Service improvement](https://docs.aws.amazon.com/amazonq/latest/qbusiness-ug/service-improvement.html).
Uploading documents and conversations will follow the same behavior as the web experience. For more information, see the [Chat and file uploads](https://docs.aws.amazon.com/amazonq/latest/qbusiness-ug/using-web-experience.html#upload-documents) section in the Using web experience topic.

**Topics**
+ [Prerequisites](#msteams-configuration-prerequisites)
+ [Adding an Amazon Q Business integration for Microsoft Teams](#msteams-adding)
+ [Removing Microsoft Teams as an integration](#msteams-removing)

## Prerequisites
<a name="msteams-configuration-prerequisites"></a>

As admins, before you can add the Amazon Q Business integration to your Microsoft Teams (Teams), you must complete the following steps:

1. You must have a Microsoft 365 Business subscription and be a *Global Admin* or someone with administrative permissions, specifically `AppCatalog.ReadWrite.All`.

1. [Get started with Amazon Q Business](https://docs.aws.amazon.com/amazonq/latest/qbusiness-ug/getting-started.html)

1. [Create an IAM Identity Center-integrated application environment](https://docs.aws.amazon.com/amazonq/latest/qbusiness-ug/create-application.html) environment and create your Amazon Q Business web experience.
**Note**  
[IAM federated application environment](https://docs.aws.amazon.com/amazonq/latest/qbusiness-ug/create-application-iam.html) environments do not support integrations with Teams.

1. Optionally, to enhance your end users' experience with Amazon Q in Teams, you can enable *Allow end users to send queries directly to the LLM* in your Admin controls and guardrails. For more information, see the [Response settings](https://docs.aws.amazon.com/amazonq/latest/qbusiness-ug/guardrails-global-controls.html#guardrails-global-response) topic in [Admin controls and guardrails](https://docs.aws.amazon.com/amazonq/latest/qbusiness-ug/guardrails.html) and `chatMode` if you are configuring programmatically.

1. Add the two IAM roles and trust policies for adding integrations. For more information, see [IAM roles and trust policy for your integrations](https://docs.aws.amazon.com/amazonq/latest/qbusiness-ug/amazon-q-business-integrations-iam.html)

1. Your Microsoft 365 tenant ID. For more information, see [How to find your tenant ID - Microsoft Entra](https://learn.microsoft.com/en-us/entra/fundamentals/how-to-find-tenant) in the Microsoft Learn portal.

## Adding an Amazon Q Business integration for Microsoft Teams
<a name="msteams-adding"></a>

To use the Amazon Q Business Teams integration, you must allow it to connect to your Amazon Q Business application environment and web experience. To do this, admins can use the Amazon Q Business console, API, SDK, or AWS CLI.

**Note**  
This integration can only be added using the AWS Management Console at this time.

**Topics**
+ [Using the console](#msteams-adding-console)
+ [Installing the Amazon Q Business app in your Microsoft Teams organization](#msteams-installing)

### Using the console
<a name="msteams-adding-console"></a>

1. Sign in to the Amazon Q console.

1. Choose **Applications**, then select the name of your application environment from the list.

1. Choose **Integrations** under **Enhancements**.

1. Choose **Add integration** from the **Integrations** section on the main page.

1. Choose **Microsoft Teams** as your integration.

1. On the **Add Teams integration page**, enter the **Name** of your integration. This is the display name for the integration resource in AWS.

1. Add a **description** (optional).

1. Enter your **Teams Tenant ID**. This can be found in the *Microsoft Entra Admin Center*. For more information, see [How to find your tenant ID - Microsoft Entra](https://learn.microsoft.com/en-us/entra/fundamentals/how-to-find-tenant)

1. Choose the type of **Service access** method that you want the Teams integration to use as authorization while accessing your service. You can **Create a new service role** or **Use an existing service role**. For more information, see [IAM role for allowing the integration to call Amazon Q Business on your end user's behalf](https://docs.aws.amazon.com/amazonq/latest/qbusiness-ug/amazon-q-business-integrations-iam-allow-integration-access.html).

1. Choose the **Access management access** for the Teams integration to authorize to connect to IAM Identity center. For more information, see [IAM role for allowing Amazon Q Business to monitor the resources that the integration creates in your account](https://docs.aws.amazon.com/amazonq/latest/qbusiness-ug/amazon-q-business-integrations-iam-allow-qbusiness-monitor.html).

1. Optionally, add any **Tags** that are relevant for this Teams integration.

1. Choose **Add integration**.

1. Once the integration has been successfully created, you will move to the **Integration details page**.

1. Choose **Deploy integration**.

1. Choose **Access Teams**.
**Note**  
This link will take you to the Teams domain outside of AWS.

1. You will continue this procedure within the Teams domain.

### Installing the Amazon Q Business app in your Microsoft Teams organization
<a name="msteams-installing"></a>

The following instructions show how to install the Amazon Q Business App in your Microsoft Teams (Teams) workspace using a link from the Amazon Q console as shown in the previous topic.

**Note**  
Only a Teams *Global Admin* or someone with administrative permissions can add the Amazon Q Business App to your Teams organization, specifically `AppCatalog.ReadWrite.All`.
There can be only one instance of the Amazon Q App per Teams organization. That instance will be connected to the application environment that the Teams integration was configured with in the previous topic.

1. Open the link and login as Global Admin or or someone with administrative permissions can add the Amazon Q Business App to the Microsoft Teams admin center for your organization.

1. Choose **Teams apps** in the left navigation.

1. Choose **Amazon Q Business** from the list of available apps.

1. Review and grant admin consent by choosing the **Permissions** tab and reviewing the permissions and choose **Grant admin consent**.
**Note**  
If permissions are already granted, proceed to the end of the procedure, there is no further action required.

1. Authenticate and choose **Accept** for Amazon Q Business app.

1. Confirm that an app titled **Amazon Q Business Permissions** tab now says **Admin consent granted for all required permissions**.

All users assigned to the app from the **Teams admin center** can now find the app in the **Built for your org** section of the **Apps** page of their Teams app.

## Removing Microsoft Teams as an integration
<a name="msteams-removing"></a>

To remove the Microsoft Teams (Teams) integration, admin users can use the Amazon Q Business console.

**Note**  
This integration can only be removed using the AWS Management Console at this time.

### Using the console
<a name="msteams-removing-console"></a>

1. Sign in to the Amazon Q console.

1. Choose **Applications**, then select the name of your application environment from the list.

1. Choose **Integrations** under **Enhancements**.

1. Find and select your Teams integration from the **Integrations** section on the main page.

1. Choose **Delete** and confirm your choice.

Once you disable your Microsoft Teams (Teams) integration, your users will no longer be able to login. However you will still need to take steps to uninstall the Amazon Q Business App in your Teams organization.

# Using the Amazon Q Business Microsoft Teams app
<a name="msteams-using"></a>

**Topics**
+ [Prerequisites](#msteams-using-prerequisites)
+ [Install and configure the Amazon Q Business app in Microsoft Teams](#msteams-using-install)
+ [Features of the Amazon Q Business Microsoft Teams bot](#msteams-using-features)
+ [Considerations using the Amazon Q Business bot for Microsoft Teams (Teams)](#msteams-considerations)
+ [Troubleshooting the Amazon Q Business app for Microsoft Teams](#msteams-troubleshooting)

## Prerequisites
<a name="msteams-using-prerequisites"></a>
+ You must have an Amazon Q Business user subscription.
+ You must have a Microsoft 365 Business subscription.
+ Your Amazon Q admin must connect the Amazon Q Business App to your Microsoft Teams organization.

## Install and configure the Amazon Q Business app in Microsoft Teams
<a name="msteams-using-install"></a>

The following are instructions on how to install the Amazon Q app in Microsoft Teams (Teams):

1. Open and login to the Teams organization for your company.

1. Go to **Apps** on the left navigation and search for *Amazon Q Business*

1. Choose **Amazon Q Business**

1. You will now see a **Q** icon/logo on the top bar on the right where you can access and chat with Amazon Q Business.

For more information, see [Chat with a bot in Microsoft Teams](https://support.microsoft.com/en-us/office/chat-with-a-bot-in-microsoft-teams-9c7bab5e-b1a2-4e35-801a-80d076e26f3f) from Microsoft support.

## Features of the Amazon Q Business Microsoft Teams bot
<a name="msteams-using-features"></a>

Following are some of the features supported by the Amazon Q Microsoft Teams (Teams) App:
+ In direct messages (DMs) to the Amazon Q contact, it responds to all messages and queries.
+ In channels it responds only to @mentions, and always in replies.
+ Thumbs up and down buttons to track feedback and help improve performance over time.
+ Provides Source Attribution - see references to sources used by Amazon Q Business.
+ It tracks the conversation and applies context.
+ Process up to 5 attached files for contextual question answering, summaries, etc. JPEG/JPG image file types are not supported as file uploads in the Teams integration.

**Important**  
The Amazon Q Business Microsoft Teams integration does not support [actions or plugins](https://docs.aws.amazon.com/amazonq/latest/qbusiness-ug/actions.html).

## Considerations using the Amazon Q Business bot for Microsoft Teams (Teams)
<a name="msteams-considerations"></a>

1. When Amazon Q is invoked by a user in a public Teams channel, it generates responses based on the invoking user's permissions, which may include content that other channel members aren't authorized to access. To prevent unintended exposure of sensitive information, carefully evaluate the use of Amazon Q in public channels. 

1. Amazon Q Business does not use customer data for service improvement or for improving its underlying large language models (LLMs). Also, none of the data you include in your Teams conversations will be indexed into your company's Amazon Q Business instance. For more information, see [Amazon Q Business Service improvement](https://docs.aws.amazon.com/amazonq/latest/qbusiness-ug/service-improvement.html).

1. The Amazon Q Business Teams app will have access to the same knowledge available in the corresponding Amazon Q Business web experience.

1. To reset, start new conversation, using the */new\$1conversation* command.

1. When you upload a file, the Amazon Q bot for Teams will only be able to respond from the file (and general knowledge if your Amazon Q admin has enabled it). Start a new chat if you want to return to getting answers from company knowledge.

1. Closing the Amazon Q Business bot for Teams side panel will end the current conversation. Users can review past conversations in Teams or all conversations from all channels (Teams, browser extensions, etc.) in your Amazon Q Business web experience. You can access all the history of previous conversations including, the names of the attachments in those conversations.

1. All conversations in Amazon Q Business are deleted after 30 days of inactivity. Teams may store conversations for longer depending on your company's Teams conversation history rules.

1. Amazon Q may provide inaccurate responses at times. For more information, see [Hallucination](https://docs.aws.amazon.com/amazonq/latest/qbusiness-ug/concepts-terms.html#hallucination) in the topic Key concepts of Amazon Q Business.

## Troubleshooting the Amazon Q Business app for Microsoft Teams
<a name="msteams-troubleshooting"></a>

My admin has enabled the Amazon Q Business app for Microsoft Teams (Teams), but I'm unable to login.  
Try having a conversation on your Amazon Q web experience first and then try Teams again. If this doesn't work, then contact your Amazon Q admin or IT department.

I am getting a "Can't access document" error.  
This happens when a document uses an unsupported format from which Amazon Q app is unable to pull relevant data to provide a helpful response. If you encounter this error and would like your file format to be supported, please submit feedback via the feedback button.

Amazon Q doesn't respond helpfully or doesn't use the context of the document I added.  
Try starting a new chat and adding the document again. If it still does not work, contact your Amazon Q Business admin for further support.

# Integrating Microsoft Outlook with the Amazon Q Business Add-in
<a name="integration-msoutlook"></a>

Amazon Q Business can enhance your users' Microsoft Outlook (Outlook) experience by increasing their email productivity, bringing Amazon Q's AI-powered assistance directly into their daily email workflows. As your users use their email, the Amazon Q Add-in can answer questions, provide summaries, draft responses and get insights from emails threads it has access to or from its general knowledge right in your Outlook enhancing your users' email productivity by bringing Amazon Q's AI-powered assistance directly into their daily email workflows.

With the Amazon Q Outlook Add-in your users can:
+ Summarize your emails
+ Draft contextual responses
+ Access Amazon Q's company knowledge and general knowledge
+ Upload documents and use other features available in [the Amazon Q web experience](https://docs.aws.amazon.com/amazonq/latest/qbusiness-ug/using-web-experience.html#upload-documents).

**Topics**
+ [Configuring the Amazon Q Business Microsoft Outlook Add-in for use](configuring-integration-msoutlook.md)
+ [Removing the Amazon Q Business Add-in as a Microsoft Outlook integration](#removing-integration-msoutlook)
+ [Using the Amazon Q Business Add-in for Microsoft Outlook](using-integration-msoutlook.md)

# Configuring the Amazon Q Business Microsoft Outlook Add-in for use
<a name="configuring-integration-msoutlook"></a>

**Note**  
The Amazon Q Business customer integrating Microsoft Outlook (Outlook) must have a paid Outlook organization.
Amazon Q supports users who authenticate using external SAML providers through IAM Identity Center. For more information, see [Create an IAM Identity Center-integrated application](https://docs.aws.amazon.com/amazonq/latest/qbusiness-ug/create-application.html).
Amazon Q application environment created with IAM federation does not support the Outlook Add-in.
Access using the Amazon Q Business API is not supported at this time.
Amazon Q Business does not use user data for service improvement or for training its underlying large language models (LLMs). For more information, see [Amazon Q Business Service improvement](https://docs.aws.amazon.com/amazonq/latest/qbusiness-ug/service-improvement.html).
Uploading documents and conversations will follow the same behavior as the web experience. For more information, see the [Chat and file uploads section ](https://docs.aws.amazon.com/amazonq/latest/qbusiness-ug/using-web-experience.html#upload-documents) in the Using web experience topic.

**Topics**
+ [Prerequisites for integrating the Amazon Q Microsoft Outlook Add-in](#integration-msoutlooks-prerequisites)
+ [Integrating Microsoft Outlook with the Amazon Q Business Add-in](#integrating-integration-msoutlook)

## Prerequisites for integrating the Amazon Q Microsoft Outlook Add-in
<a name="integration-msoutlooks-prerequisites"></a>

As admins, before you can integrate the Amazon Q Business Microsoft Outlook (Outlook) Add-in, you must complete the following steps.

1. You must have a Microsoft 365 Business subscription and be a *Global Admin* or someone with administrative permissions, specifically `AppCatalog`.`ReadWrite`. `All`.

1. You need your Microsoft 365 tenant ID. For more information, see [How to find your tenant ID - Microsoft Entra](https://learn.microsoft.com/en-us/entra/fundamentals/how-to-find-tenant) in the *Microsoft Learn portal*.

1. [Get started with Amazon Q Business](https://docs.aws.amazon.com/amazonq/latest/qbusiness-ug/getting-started.html)

1. [Create an IAM Identity Center-integrated application](https://docs.aws.amazon.com/amazonq/latest/qbusiness-ug/create-application.html) and create your Amazon Q Business web experience.
**Note**  
[IAM federated application environments](https://docs.aws.amazon.com/amazonq/latest/qbusiness-ug/create-application-iam.html) do not support integrations with Outlook.

1. Add the two IAM roles and trust policies for adding integrations. For more information, see [IAM roles and trust policy for your integrations](https://docs.aws.amazon.com/amazonq/latest/qbusiness-ug/amazon-q-business-integrations-iam.html).

1. To use this feature, you must enable **Allow end users to send queries directly to the LLM** in your Admin controls and guardrails. For more information, see the [Response settings](https://docs.aws.amazon.com/amazonq/latest/qbusiness-ug/guardrails-global-controls.html#guardrails-global-response) topic in [Admin controls and guardrails](https://docs.aws.amazon.com/amazonq/latest/qbusiness-ug/guardrails.html) and [https://docs.aws.amazon.com/amazonq/latest/api-reference/API_ChatSync.html#qbusiness-ChatSync-request-chatMode](https://docs.aws.amazon.com/amazonq/latest/api-reference/API_ChatSync.html#qbusiness-ChatSync-request-chatMode) if you are configuring programmatically.

## Integrating Microsoft Outlook with the Amazon Q Business Add-in
<a name="integrating-integration-msoutlook"></a>

To use the Amazon Q Business Add-in for Microsoft Outlook, you must allow it to connect to your Amazon Q Business application environment and web experience. 

**Note**  
This integration can only be added using the Amazon Q Business console.

### Using the console
<a name="integrating-integration-msoutlook-using-console"></a>

1. Sign in to the Amazon Q Business console.

1. Choose **Applications**, then select the name of your application environment from the list.

1. Choose **Integrations** under **Enhancements**.

1. Choose **Add integration** from the **Integrations** section on the main page.

1. Choose **Microsoft Outlook** as your integration.

1. On the **Add Outlook integration page**, enter the **Name** of your integration. This is the display name for the integration resource in AWS.

1. Add a **description** (optional).

1. In the **Workspace** section, enter your Microsoft **Tenant ID**. This can be found in the *Microsoft Entra Admin Center*. For more information, see [How to find your tenant ID - Microsoft Entra](https://learn.microsoft.com/en-us/entra/fundamentals/how-to-find-tenant)

1. Choose the type of **Service access** method that you want the Outlook integration to use as authorization while accessing your service. You can **Create a new service role** or **Use an existing service role**. For more information, see [IAM role for allowing the integration to call Amazon Q Business on your end user's behalf](https://docs.aws.amazon.com/amazonq/latest/qbusiness-ug/amazon-q-business-integrations-iam-allow-integration-access.html).

1. Choose the **Access management access** for the Outlook integration to authorize to connect to IAM Identity center. For more information, see [IAM role for allowing Amazon Q Business to monitor the resources that the integration creates in your account](https://docs.aws.amazon.com/amazonq/latest/qbusiness-ug/amazon-q-business-integrations-iam-allow-qbusiness-monitor.html).

1. Optionally, add any **Tags** that are relevant for this Teams integration.

1. Choose **Add integration**.

1. Once you have added the integration, Amazon Q will deploy your integration. You will see that update on the **Integration details page**.

   Once the integration is *deployed*, choose the name of your Outlook integration from the list of integrations in the **Integrations** section.

1. Copy the **Manifest URL** in the **Integration details** section.
**Note**  
You will now continue the remainder of this procedure within the *Microsoft 365 admin center*.

1. In the Microsoft 365 admin center, choose **Integrated apps** from the left navigation and choose **Upload custom apps** This will open the **Deploy New App** page.

1. Choose **Office Add-in** as your App type.

1. Paste the manifest URL link you copied in the **Provide link to manifest file** and choose **Validate**.

1. Choose the users you want to add in the **Add users** section.

1. Choose **Accept permissions** in the **Accept permissions requests** section and deploy the Add-in. Once deployment is completed, you users will be able to install the Amazon Q Business Add-in in their Microsoft Outlook.
**Note**  
Authentication may be required.

## Removing the Amazon Q Business Add-in as a Microsoft Outlook integration
<a name="removing-integration-msoutlook"></a>

To remove the Microsoft Outlook (Outlook) integration, Admin users can use the Amazon Q Business console.

**Note**  
This integration can only be added using the Amazon Q Business console.

### Using the console
<a name="removing-using-console"></a>

1. Sign in to the Amazon Q Business console.

1. Choose **Applications**, then select the name of your application environment from the list.

1. Choose **Integrations** under **Enhancements**.

1. Choose your integration from the list in the **Integrations** section and choose **Delete**. Confirm your choice and choose **Delete**.
**Note**  
You will now continue the remainder of this procedure within the *Microsoft 365 admin center*.

1. Once your integration has been deleted, login to the Microsoft 365 admin center and choose **Integrated apps** from the left navigation.

1. Choose Amazon Q Business **Office Add-in** as your App and choose **Remove app** from the Amazon Q Business property details section that pops up. **Confirm** your choice.
**Note**  
Once you remove your Microsoft Outlook (Outlook) Add-in from here, the Add-in will no longer appear as an Add-in to use or add in their Outlook.

# Using the Amazon Q Business Add-in for Microsoft Outlook
<a name="using-integration-msoutlook"></a>

**Topics**
+ [Prerequisites](#integration-msoutlook-user-prerequisites)
+ [Install the Amazon Q Business Add-in to your Microsoft OutlookInstall the Add-in](#install-configure-integration-msoutlook)
+ [Common use cases for using the Amazon Q Business Add-in for Microsoft Outlook](#integration-msoutlook-common-use-cases)
+ [Considerations for using the Amazon Q Business Add-in for Microsoft Outlook](#integration-msoutlook-considerations)
+ [Troubleshooting the Amazon Q Business Add-in for Microsoft Outlook](#integration-msoutlook-troubleshooting)

## Prerequisites
<a name="integration-msoutlook-user-prerequisites"></a>
+ You must have an Amazon Q Business user subscription.
+ You must have a Microsoft 365 Business subscription.
+ Your Amazon Q admin must add the Amazon Q Business Add-in to your Microsoft 365 organization.

## Install the Amazon Q Business Add-in to your Microsoft Outlook


## Install the Add-in
<a name="install-configure-integration-msoutlook"></a>

The following are instructions on how to install the Amazon Q app in Microsoft Outlook (Outlook):

1. Open your Microsoft Outlook.

1. Go to **Add-Ins** and search for *Amazon Q Business* and choose **Amazon Q Business**

1. You will now see a **Q** icon/logo on the top bar on the right where you can access the Amazon Q Business chat assistant.

1. Once you have successfully logged on, you can use your Amazon Q Business Add-In.

## Common use cases for using the Amazon Q Business Add-in for Microsoft Outlook
<a name="integration-msoutlook-common-use-cases"></a>

The following are some of the common use cases that will help you make the best use of your Amazon Q Business Add-in for Microsoft Outlook (Outlook):

1. **Analyze email threads**: Get summaries of long email discussions and identify key points, decisions, and action items. 

1. **Draft email responses**: Select an email thread and ask Amazon Q to help draft appropriate responses based on the conversation context.

1. **Ask questions about email content**: Select any portion of an email thread and add it to the context, then ask your question. You can include multiple emails to provide more context.

1. **Ask a question about Amazon Q's company knowledge and general** (if enabled).

1. **Generate email content**: Describe what you need, and Amazon Q will generate suggested email content that matches the conversation's tone and context.

1. **Analyze up to 4 files that you want to send or have received for (collective) analysis**.

## Considerations for using the Amazon Q Business Add-in for Microsoft Outlook
<a name="integration-msoutlook-considerations"></a>

1. Amazon Q Business does not use customer data for service improvement or for improving its underlying large language models (LLMs). Also, none of the data you include in your Microsoft Outlook (Outlook) conversations will be indexed into your company's Amazon Q Business instance. For more information, see [Amazon Q Business Service improvement](https://docs.aws.amazon.com/amazonq/latest/qbusiness-ug/service-improvement.html).

1. To reset your conversation context, choose *new chat*. If you close the Amazon Q Business chat panel it will end the conversation and will start a new conversation the next time you reopen it.

1. All conversations with Amazon Q including uploaded web page snapshots and files from the Outlook will be deleted after 30 days of inactivity.

1. You can access all history of previous conversations (including attachments to those conversations) that have not been deleted from the Amazon Q web experience conversation history.

1. Amazon Q's responses aren't always 100% accurate. For more information, see [Hallucination](https://docs.aws.amazon.com/amazonq/latest/qbusiness-ug/concepts-terms.html#hallucination) in the topic Key concepts of Amazon Q Business.

## Troubleshooting the Amazon Q Business Add-in for Microsoft Outlook
<a name="integration-msoutlook-troubleshooting"></a>
+ **My admin has enabled the Microsoft Outlook (Outlook), but I'm unable to login.**

  Try having a conversation on your Amazon Q web experience first and then try the Microsoft Outlook (Outlook) again. If this doesn't work, then contact your Amazon Q admin or IT department.
+ **Amazon Q doesn't respond helpfully or doesn't use the context of my email or document.**

  Try starting a new chat. If it still does not work, submit feedback using the feedback button and include any non-confidential details about the type of web page where the extension failed.
+ **I get the error, 'To use the Amazon Q Business Add-in your administrator needs to enable "Allow end users to send queries directly to the LLM" in the Amazon Q Business console'**.

  Contact your Admin or IT department with the error.
+ **Amazon Q doesn't recognize updated information when my thread updates.**

  Amazon Q only has access to your email thread right at the point you are viewing it. Similar to a photograph, this is all the information in the email thread is from the point it is viewed. To refresh the snapshot of your thread, go to the latest message in the thread.

# Integrating Microsoft Word with the Amazon Q Business Add-in
<a name="integration-msword"></a>

Amazon Q Business can enhance your users' Microsoft Word (Word) experience by increasing their productivity, bringing Amazon Q's AI-powered assistance directly into their daily document workflows. As your users work on their documents, the Amazon Q Add-in can answer questions, review documents, suggest revisions and get insights from documents it has access to or from its general knowledge enhancing your users' productivity by bringing Amazon Q's AI-powered assistance directly into their document workflows.

With the Amazon Q Word Add-in your users can:
+ Review, draft, and revise documents
+ Summarize documents and get insights
+ Simplify and improve your writing
+ Access Amazon Q's company knowledge and general knowledge
+ Upload documents and use other features available in [the Amazon Q web experience](https://docs.aws.amazon.com/amazonq/latest/qbusiness-ug/using-web-experience.html#upload-documents).

**Topics**
+ [Configuring the Amazon Q Business Microsoft Word Add-in for use](configuring-integration-msword.md)
+ [Removing the Amazon Q Business Add-in as a Microsoft Word integration](#removing-integration-msword)
+ [Using the Amazon Q Business Add-in for Microsoft Word](using-integration-msword.md)

# Configuring the Amazon Q Business Microsoft Word Add-in for use
<a name="configuring-integration-msword"></a>

**Note**  
The Amazon Q Business customer integrating Microsoft Word (Word) must have a paid Word organization.
Amazon Q supports users who authenticate using external SAML providers through IAM Identity Center. For more information, see [Create an IAM Identity Center-integrated application](https://docs.aws.amazon.com/amazonq/latest/qbusiness-ug/create-application.html).
Amazon Q application environment created with IAM federation does not support the Word Add-in.
Access using the Amazon Q Business API is not supported at this time.
Amazon Q Business does not use user data for service improvement or for training its underlying large language models (LLMs). For more information, see [Amazon Q Business Service improvement](https://docs.aws.amazon.com/amazonq/latest/qbusiness-ug/service-improvement.html).
Uploading documents and conversations will follow the same behavior as the web experience. For more information, see the [Chat and file uploads section ](https://docs.aws.amazon.com/amazonq/latest/qbusiness-ug/using-web-experience.html#upload-documents) in the Using web experience topic.

**Topics**
+ [Prerequisites for integrating the Amazon Q Microsoft Word Add-in](#integration-mswords-prerequisites)
+ [Integrating Microsoft Word with theAmazon Q Business Add-in](#integrating-integration-msword)

## Prerequisites for integrating the Amazon Q Microsoft Word Add-in
<a name="integration-mswords-prerequisites"></a>

As admins, before you can integrate the Amazon Q Business Microsoft Word (Word) Add-in, you must complete the following steps.

1. You must have a Microsoft 365 Business subscription and be a *Global Admin* or someone with administrative permissions, specifically `AppCatalog`.`ReadWrite`. `All`.

1. You need your Microsoft 365 tenant ID. For more information, see [How to find your tenant ID - Microsoft Entra](https://learn.microsoft.com/en-us/entra/fundamentals/how-to-find-tenant) in the *Microsoft Learn portal*.

1. [Get started with Amazon Q Business](https://docs.aws.amazon.com/amazonq/latest/qbusiness-ug/getting-started.html)

1. [Create an IAM Identity Center-integrated application](https://docs.aws.amazon.com/amazonq/latest/qbusiness-ug/create-application.html) and create your Amazon Q Business web experience.
**Note**  
[IAM federated application environments](https://docs.aws.amazon.com/amazonq/latest/qbusiness-ug/create-application-iam.html) do not support integrations with Word.

1. Add the two IAM roles and trust policies for adding integrations. For more information, see [IAM roles and trust policy for your integrations](https://docs.aws.amazon.com/amazonq/latest/qbusiness-ug/amazon-q-business-integrations-iam.html).

1. To use this feature, you must enable **Allow end users to send queries directly to the LLM** in your Admin controls and guardrails. For more information, see the [Response settings](https://docs.aws.amazon.com/amazonq/latest/qbusiness-ug/guardrails-global-controls.html#guardrails-global-response) topic in [Admin controls and guardrails](https://docs.aws.amazon.com/amazonq/latest/qbusiness-ug/guardrails.html) and [https://docs.aws.amazon.com/amazonq/latest/api-reference/API_ChatSync.html#qbusiness-ChatSync-request-chatMode](https://docs.aws.amazon.com/amazonq/latest/api-reference/API_ChatSync.html#qbusiness-ChatSync-request-chatMode) if you are configuring programmatically.

## Integrating Microsoft Word with theAmazon Q Business Add-in
<a name="integrating-integration-msword"></a>

To use the Amazon Q Business Add-in for Microsoft Word, you must allow it to connect to your Amazon Q Business application environment and web experience. 

**Note**  
This integration can only be added using the Amazon Q Business console.

### Using the console
<a name="integrating-integration-msword-using-console"></a>

1. Sign in to the Amazon Q Business console.

1. Choose **Applications**, then select the name of your application environment from the list.

1. Choose **Integrations** under **Enhancements**.

1. Choose **Add integration** from the **Integrations** section on the main page.

1. Choose **Word** as your integration.

1. On the **Add Word integration page**, enter the **Name** of your integration. This is the display name for the integration resource in AWS.

1. Add a **description** (optional).

1. In the **Workspace** section, enter your Microsoft **Tenant ID**. This can be found in the *Microsoft Entra Admin Center*. For more information, see [How to find your tenant ID - Microsoft Entra](https://learn.microsoft.com/en-us/entra/fundamentals/how-to-find-tenant)

1. Choose the type of **Service access** method that you want the Word integration to use as authorization while accessing your service. You can **Create a new service role** or **Use an existing service role**. For more information, see [IAM role for allowing the integration to call Amazon Q Business on your end user's behalf](https://docs.aws.amazon.com/amazonq/latest/qbusiness-ug/amazon-q-business-integrations-iam-allow-integration-access.html).

1. Choose the **Access management access** for the Word integration to authorize to connect to IAM Identity center. For more information, see [IAM role for allowing Amazon Q Business to monitor the resources that the integration creates in your account](https://docs.aws.amazon.com/amazonq/latest/qbusiness-ug/amazon-q-business-integrations-iam-allow-qbusiness-monitor.html).

1. Optionally, add any **Tags** that are relevant for this Teams integration.

1. Choose **Add integration**.

1. Once you have added the integration, Amazon Q will deploy your integration. You will see that update on the **Integration details page**.

   Once the integration is *deployed*, choose the name of your Word integration from the list of integrations in the **Integrations** section.

1. Copy the **Manifest URL** in the **Integration details** section.
**Note**  
You will now continue the remainder of this procedure within the *Microsoft 365 admin center*.

1. In the Microsoft 365 admin center, choose **Integrated apps** from the left navigation and choose **Upload custom apps** This will open the **Deploy New App** page.

1. Choose **Office Add-in** as your App type.

1. Paste the manifest URL link you copied in the **Provide link to manifest file** and choose **Validate**.

1. Choose the users you want to add in the **Add users** section.

1. Choose **Accept permissions** in the **Accept permissions requests** section and deploy the Add-in. Once deployment is completed, you users will be able to install the Amazon Q Business Add-in in their Microsoft Word.
**Note**  
Authentication may be required.

## Removing the Amazon Q Business Add-in as a Microsoft Word integration
<a name="removing-integration-msword"></a>

To remove the Microsoft Word (Word) integration, Admin users can use the Amazon Q Business console.

**Note**  
This integration can only be added using the Amazon Q Business console.

### Using the console
<a name="removing-using-console"></a>

1. Sign in to the Amazon Q Business console.

1. Choose **Applications**, then select the name of your application environment from the list.

1. Choose **Integrations** under **Enhancements**.

1. Choose your integration from the list in the **Integrations** section and choose **Delete**. Confirm your choice and choose **Delete**.
**Note**  
You will now continue the remainder of this procedure within the *Microsoft 365 admin center*.

1. Once your integration has been deleted, login to the Microsoft 365 admin center and choose **Integrated apps** from the left navigation.

1. Choose Amazon Q Business **Office Add-in** as your App and choose **Remove app** from the Amazon Q Business property details section that pops up. **Confirm** your choice.
**Note**  
Once you remove your Microsoft Word (Word) Add-in from here, the Add-in will no longer appear as an Add-in to use or add in their Word.

# Using the Amazon Q Business Add-in for Microsoft Word
<a name="using-integration-msword"></a>

**Topics**
+ [Prerequisites](#integration-msword-user-prerequisites)
+ [Install the Amazon Q Business Add-in to your Microsoft WordInstall the Add-in](#install-configure-integration-msword)
+ [Common use cases for using the Amazon Q Business Add-in for Microsoft Word](#integration-msword-common-use-cases)
+ [Considerations for using the Amazon Q Business Add-in for Microsoft Word](#integration-msword-considerations)
+ [Troubleshooting the Amazon Q Business Add-in for Microsoft Word](#integration-msword-troubleshooting)

## Prerequisites
<a name="integration-msword-user-prerequisites"></a>
+ You must have an Amazon Q Business user subscription.
+ You must have a Microsoft 365 Business subscription.
+ Your Amazon Q admin must add the Amazon Q Business Add-in to your Microsoft 365 organization.

## Install the Amazon Q Business Add-in to your Microsoft Word


## Install the Add-in
<a name="install-configure-integration-msword"></a>

The following are instructions on how to install the Amazon Q app in Microsoft Word (Word):

1. Open your Microsoft Word.

1. Go to **Add-Ins** and search for *Amazon Q Business* and choose **Amazon Q Business**

1. You will now see a **Q** icon/logo on the top bar on the right where you can access the Amazon Q Business chat assistant.

1. Once you have successfully logged on, you can use your Amazon Q Business Add-In.

## Common use cases for using the Amazon Q Business Add-in for Microsoft Word
<a name="integration-msword-common-use-cases"></a>

The following are some of the common use cases that will help you make the best use of your Amazon Q Business Add-in for Microsoft Word (Word):

1. **Review your document**: Select the text you want to review and get suggestions for improving clarity, grammar, and style. 

1. **Summarize the document/generate content**: Open the Amazon Q Business add-in when reviewing a document and click on the **executive summary**, or **generate conclusion** quick prompts

1. **Ask questions about your content**: Select any portion of your document and add it as context, and ask your question. You can select multiple sections to provide more context or use quick prompts such as **explain in simple terms**.

1. **Simplify your content**: Select any portion of your document and ask your question. You can select multiple sections to provide more context or use quick prompts such as **simplify writing**.

1. **Generate content suggestions**: Select where you want to add content, describe what you need, and Amazon Q will generate suggestions that match your document's style and context.

1. **Draft your document or improve sections of your document:** Describe what you need, and Amazon Q will generate suggested draft content that matches the context.

1. **Ask a question about Amazon Q's company knowledge and general knowledge** (if enabled).

1. **Analyze up to 4 files that you want to review, summarize, or get insights from for (collective) analysis**.

## Considerations for using the Amazon Q Business Add-in for Microsoft Word
<a name="integration-msword-considerations"></a>

1. Amazon Q Business does not use customer data for service improvement or for improving its underlying large language models (LLMs). Also, none of the data you include in your Microsoft Word (Word) conversations will be indexed into your company's Amazon Q Business instance. For more information, see [Amazon Q Business Service improvement](https://docs.aws.amazon.com/amazonq/latest/qbusiness-ug/service-improvement.html).

1. To reset your conversation context, choose *new chat*. If you close the Amazon Q Business chat panel it will end the conversation and will start a new conversation the next time you reopen it.

1. All conversations with Amazon Q including uploaded web page snapshots and files from the Word will be deleted after 30 days of inactivity.

1. You can access all history of previous conversations (including attachments to those conversations) that have not been deleted from the Amazon Q web experience conversation history.

1. Amazon Q's responses aren't always 100% accurate. For more information, see [Hallucination](https://docs.aws.amazon.com/amazonq/latest/qbusiness-ug/concepts-terms.html#hallucination) in the topic Key concepts of Amazon Q Business.

## Troubleshooting the Amazon Q Business Add-in for Microsoft Word
<a name="integration-msword-troubleshooting"></a>
+ **My admin has enabled the Microsoft Word (Word), but I'm unable to login.**

  Try having a conversation on your Amazon Q web experience first and then try the Microsoft Word (Word) again. If this doesn't work, then contact your Amazon Q admin or IT department.
+ **Amazon Q doesn't respond helpfully or doesn't use the context of my email or document.**

  Try starting a new chat. If it still does not work, submit feedback using the feedback button and include any non-confidential details about the type of web page where the extension failed.
+ **I get the error, 'To use the Amazon Q Business Add-in your administrator needs to enable "Allow end users to send queries directly to the LLM" in the Amazon Q Business console'**.

  Contact your Admin or IT department with the error.

# IAM roles and trust policy for your integrations
<a name="amazon-q-business-integrations-iam"></a>

In order for your integrations to work, you will need to add the following two IAM roles as part of your configuration.

**Note**  
IAM roles and trust policy are not required for using browser extensions.

**Topics**
+ [IAM role for allowing the integration to call Amazon Q Business on your end user's behalf](#amazon-q-business-integrations-iam-allow-integration-access)
+ [IAM role for allowing Amazon Q Business to monitor the resources that the integration creates in your account](#amazon-q-business-integrations-iam-allow-qbusiness-monitor)
+ [IAM trust policy for your integrations](#amazon-q-business-integrations-iam-trust-policy)

## IAM role for allowing the integration to call Amazon Q Business on your end user's behalf
<a name="amazon-q-business-integrations-iam-allow-integration-access"></a>

------
#### [ JSON ]

****  

```
{
    "Version":"2012-10-17",		 	 	 
    "Statement": [
        {
            "Sid": "QBusinessConversationPermissions",
            "Effect": "Allow",
            "Action": [
                "qbusiness:Chat",
                "qbusiness:ChatSync",
                "qbusiness:PutFeedback",
                "qbusiness:DeleteConversation",
                "qbusiness:ListAttachments",
                "qbusiness:DeleteAttachment"
            ],
            "Resource": "arn:aws:qbusiness:us-east-1:111122223333:application/application-id"
        },
        {
            "Sid": "QBusinessKMSDecryptPermissions",
            "Effect": "Allow",
            "Action": [
                "kms:Decrypt"
            ],
            "Resource": [
                "arn:aws:kms:us-east-1:111122223333:key/[[key_id]]"
            ],
            "Condition": {
                "StringLike": {
                    "kms:ViaService": [
                        "qbusiness.us-east-1.amazonaws.com"
                    ]
                }
            }
        },
        {
            "Sid": "QBusinessSetContextPermissions",
            "Effect": "Allow",
            "Action": [
                "sts:SetContext"
            ],
            "Resource": [
                "arn:aws:sts::*:self"
            ],
            "Condition": {
                "StringLike": {
                    "aws:CalledViaLast": [
                        "qbusiness.amazonaws.com"
                    ]
                }
            }
        }
    ]
}
```

------

## IAM role for allowing Amazon Q Business to monitor the resources that the integration creates in your account
<a name="amazon-q-business-integrations-iam-allow-qbusiness-monitor"></a>

------
#### [ JSON ]

****  

```
{
    "Version":"2012-10-17",		 	 	 
    "Statement": [
        {
            "Sid": "QBusinessIdCInstanceReadOnlyPermissions",
            "Effect": "Allow",
            "Action": [
                "sso:ListApplications"
            ],
            "Resource": "arn:aws:sso:::instance/idc-instance-id"
        },
        {
            "Sid": "QBusinessIdCInstanceApplicationReadOnlyPermissions",
            "Effect": "Allow",
            "Action": [
                "sso:ListApplicationAccessScopes",
                "sso:GetApplicationAssignmentConfiguration",
                "sso:GetApplicationGrant",
                "sso:GetApplicationAuthenticationMethod"
            ],
            "Resource": "arn:aws:sso::111122223333:application/idc-instance-id/*"
        }
    ]
}
```

------

## IAM trust policy for your integrations
<a name="amazon-q-business-integrations-iam-trust-policy"></a>

------
#### [ JSON ]

****  

```
{
    "Version":"2012-10-17",		 	 	 
    "Statement": [
        {
            "Sid": "QBusinessTrustPolicy",
            "Effect": "Allow",
            "Principal": {
                "Service": "integrations.qbusiness.amazonaws.com"
            },
            "Action": [
                "sts:AssumeRole",
                "sts:SetContext"
            ],
            "Condition": {
                "StringEquals": {
                    "aws:SourceAccount": "111122223333"
                },
                "ArnLike": {
                    "aws:SourceArn": "arn:aws:qbusiness:us-east-1:111122223333:application/application-id"
                }
            }
        }
    ]
}
```

------