Classic SharePoint Online Access Requirements
This guide applies only to existing configurations that use OAuth2 Client Credentials Grant on the Classic Microsoft Graph connector and Oauth2 Jwt Grant on the Classic SharePoint Online connector. Use it to maintain the app permissions or credentials for those connectors. Do not use this guide to change the authentication type or create a new Classic configuration.
Create new SharePoint configurations with the SharePoint & OneDrive (Max Capacity) connector. Follow the SharePoint Online and OneDrive setup guide. If Max Capacity cannot meet a requirement for a new configuration, contact Moveworks Support.
Before You Begin
The authentication types covered by this guide use app-only authentication. The connectors may use the same Microsoft Entra app registration or separate app registrations. In Moveworks Setup, record the Client ID from the Microsoft Graph connector and the Application (client) ID from the SharePoint Online connector so you can identify each corresponding app registration.
Confirm that you have:
- Access to the existing Microsoft Entra app registration as an app owner, Application Administrator, or Cloud Application Administrator so you can manage credentials and requested API permissions.
- Access to a Privileged Role Administrator or Global Administrator who can grant tenant-wide admin consent for Microsoft Graph application permissions. For more information, see Grant tenant-wide admin consent to an application.
- Access to the existing Microsoft Graph and SharePoint Online connectors in Moveworks Setup.
- Access to your organization’s process for granting selected-site access if the app uses Sites.Selected.
- Windows PowerShell and OpenSSL, or a macOS or Linux terminal with OpenSSL.
- An approved secure location for temporary credential files.
Required Application Permissions
The Classic connectors require only application permissions. They do not use delegated permissions such as User.Read. If a shared app already has delegated permissions for another workload, do not remove them without confirming that workload no longer needs them.
The permissions you need depend on whether the existing Classic configuration ingests files, knowledge pages, or both.
Sites.Selected limits the Microsoft Graph and SharePoint Sites permissions to explicitly granted sites. It does not limit the separate Files.Read.All application permission, which grants read access to files across all site collections. Files.Read.All remains required for the driveItem change-notification subscriptions used by Classic file-ingestion webhooks, including when you use Sites.Selected.
If you use Sites.Selected, grant the app access to each approved site. Follow the Microsoft Sites.Selected setup instructions. For more information about access controls in File Search, see File Search: Respecting File Permissions.
Grant either Sites.Read.All or Sites.Selected in both the Microsoft Graph and SharePoint API groups.
Step 1: Open the Existing App Registration
- Sign in to the Microsoft Entra admin center.
- Go to Entra ID > App registrations > All applications.
- Find and open the app registration whose Application (client) ID matches the ID configured on the existing Classic connector.
- On the app’s Overview page, record the Application (client) ID and Directory (tenant) ID.
If the existing app registration cannot be used, go to Entra ID > App registrations, select New registration, and create a dedicated replacement. Under Supported account types, select the single-tenant option for your organization, leave Redirect URI empty, and select Register.
Replacing the app changes the Application (client) ID. You must create new credentials, grant and consent to the required application permissions, repeat any Sites.Selected site grants, and update the affected Classic connectors. If the connectors use separate app registrations, replace only the app associated with the affected connector. For more information, see Register an application with the Microsoft identity platform.
Step 2: Create a Microsoft Graph Client Secret
The Classic Microsoft Graph connector uses a client secret. Create a new secret when the current secret is expiring or invalid, or when you replace the app registration. If you are updating only the SharePoint certificate and the current secret remains valid, continue to Step 3.
- Go to Certificates & secrets > Client secrets and select New client secret.
- Enter a description that identifies the secret as belonging to the Classic Microsoft Graph connector.
- Select an expiration period that follows your organization’s credential policy, and then select Add.
- Copy the client secret Value immediately. Microsoft Entra displays it only once. You will use this value for the Classic Microsoft Graph connector.
Store the client secret in your organization’s approved secrets manager. Do not copy the Secret ID in place of the secret Value. Keep the previous secret active until you update the connector and validate an ingestion with the new secret.
Step 3: Generate SharePoint Certificate Credentials
The Classic SharePoint Online connector uses a certificate and private key. Generate new certificate credentials when the current certificate is expiring or invalid, or when you replace the app registration.
The following workflow creates a self-signed certificate supported by the Classic connector. If your organization requires a certificate issued by a certificate authority, use your approved process and export the certificate and private key in the formats listed below.
Generate these files in a location approved for temporary credentials:
certificate.cer: The public certificate that you upload to the Microsoft Entra app registration.privateKey.pem: The unencrypted PKCS #8 private key that you upload to the Classic SharePoint Online connector.Moveworks.pfx: A password-protected export used to produce the PEM private key on Windows.
Windows
Use Windows PowerShell with the PKI module and OpenSSL installed.
-
Create an exportable 2048-bit RSA certificate that uses SHA-256. This example uses a two-year validity period. Change
AddYears(2)to follow your organization’s certificate lifetime policy.CertStoreLocationmust be a Windows certificate-provider path. -
Export the password-protected PFX file and the public certificate. Use the certificate object returned by
New-SelfSignedCertificate. -
Convert the private key from the PFX file to an unencrypted PKCS #8 PEM file.
macOS or Linux
Use OpenSSL to generate a 2048-bit RSA private key and a SHA-256 self-signed certificate. This example uses a two-year validity period. Change -days 730 to follow your organization’s certificate lifetime policy.
Verify the Certificate and Private Key
-
Confirm the certificate validity dates.
Windows
macOS or Linux
-
Confirm that the certificate and private key belong to the same key pair. The following two commands must return the same SHA-256 digest.
Windows
macOS or Linux
-
Confirm that
privateKey.pemstarts with-----BEGIN PRIVATE KEY-----and ends with-----END PRIVATE KEY-----. The header must not containRSAorENCRYPTED. -
On macOS or Linux, confirm that
certificate.cerstarts with-----BEGIN CERTIFICATE-----and ends with-----END CERTIFICATE-----. The WindowsExport-Certificatecommand creates a DER-encoded.cerfile, so the Windows certificate does not contain PEM headers.
The private key is unencrypted because the Classic connector requires this format. Store privateKey.pem and Moveworks.pfx in approved secure storage, restrict access, and follow your organization’s credential-retention policy. Upload only certificate.cer to Microsoft Entra.
Step 4: Upload the Public Certificate
- Open the app registration in Microsoft Entra.
- Go to Certificates & secrets > Certificates and select Upload certificate.
- Select the same
certificate.cerfile that you will use to calculate the x5t value, enter an optional description, and select Add. - Confirm that the certificate appears with the expected start and expiration dates.
Step 5: Generate the SHA-256 x5t Value
The x5t value is the unpadded Base64URL-encoded SHA-256 digest of the certificate’s DER bytes. It is not the hexadecimal certificate thumbprint displayed in Microsoft Entra. For more information, see the Microsoft identity platform certificate credential format.
Windows
macOS or Linux
A SHA-256 x5t value contains 43 letters, numbers, hyphens, or underscores. It has no spaces, colons, or = padding. Recalculate it whenever you rotate the certificate.
Generate an x5t value for a legacy SHA-1 connector
Use this section only when Use SHA-256 Algorithm is currently cleared on the existing Classic connector. Keep the setting cleared when you save this SHA-1 value.
Windows
macOS or Linux
A SHA-1 x5t value contains 27 letters, numbers, hyphens, or underscores and has no = padding.
Credential Reference
Step 6: Review and Grant Application Permissions
Review the permissions on the app registration and add any required application permissions that are missing. Creating a new secret or certificate on the existing app does not require you to grant unchanged permissions again. If the connectors use separate app registrations, review the Microsoft Graph permissions on the app used by the Microsoft Graph connector and the SharePoint permissions on the app used by the SharePoint Online connector.
- In the Microsoft Entra admin center, go to Entra ID > App registrations > All applications and open the selected app registration.
- Go to API permissions and compare the configured permissions with Required Application Permissions. If the configuration supports both file and knowledge ingestion, include every permission marked as required for either use case.
- If a required Microsoft Graph permission is missing:
- Select Add a permission > Microsoft Graph > Application permissions.
- Select each missing permission and then select Add permissions.
- If the required SharePoint Sites permission is missing:
- Select Add a permission > SharePoint > Application permissions.
- Select Sites.Read.All or Sites.Selected, matching the choice made for Microsoft Graph, and then select Add permissions. Sites.FullControl.All is not required on the Moveworks app.
- If you added a permission or a required permission does not show a granted status, ask a Privileged Role Administrator or Global Administrator to select Grant admin consent for {organization} and confirm the prompt.
- Verify that every required permission shows a granted status.
- If you replaced the app registration or an approved site grant is missing for Sites.Selected, ask a Global Administrator or use a separate grantor app with Sites.FullControl.All to follow the Microsoft Sites.Selected setup instructions and assign the Moveworks app the Read role for each approved site. Complete this step after admin consent. Do not add Sites.FullControl.All to the Moveworks app.
In a GCCH tenant, select Office 365 SharePoint Online when SharePoint is not available in the API list.
For each SharePoint group used in file or page permissions, set Who can view the membership of the group? to Everyone so Moveworks can read the group members. If you cannot change this setting, use a Microsoft Entra group or another SharePoint group whose membership is visible to the app.
The app registration now has the required application permissions and credentials.
Step 7: Update the Existing Classic Connectors
In Moveworks Setup, go to Connectors > Built-in Connectors.
Microsoft Graph Connector
Open the existing Microsoft Graph connector. Update the fields whose corresponding values changed and leave the other fields unchanged.
SharePoint Online Connector
Open the existing SharePoint Online connector. Update the fields whose corresponding values changed and leave the other fields unchanged.
Validate the Credential Update
- Save each connector that you changed.
- Run every existing file and knowledge ingestion that uses a changed connector.
- Confirm that each ingestion completes without authentication or authorization errors and that representative permission-restricted content remains available only to the intended users.
- If the file ingestion uses webhooks, confirm that an incremental content change is processed successfully after the credential update.
- Confirm that no other workload uses the previous client secret or certificate. After every affected path has been validated, retire the previous credential and delete temporary credential files according to your organization’s change-management and retention policies.
- For File Search, open the existing configuration under Search > Configure Search > Classic Ingestion > Files.
- For knowledge ingestion, continue with How to Configure SharePoint Knowledge Ingestion.
If you do not have access to Moveworks Setup or the ingestion reports an authentication error, contact your Customer Success team.