Skip to main content

Overview

The SharePoint connector syncs files (CSV, Excel, and other supported formats) from a specific SharePoint folder into your destination. It authenticates using delegated OAuth 2.0 against the Microsoft identity platform: you sign in with a Microsoft 365 account, and Matia reads SharePoint as that account, limited to whatever that account can access.

Because access is delegated, the connector never has tenant-wide access. It can only read the sites and folders that the account you sign in with has been granted access to.

Prerequisites

Before you begin, make sure you have:

  • A Microsoft 365 account to authenticate with. We recommend a dedicated service account (a standard, licensed M365 user) rather than a personal account, so the connection is not tied to an individual employee.

    The account must be a normal user that can complete an **interactive browser sign-in** (including MFA, if your tenant enforces it). A headless Entra **app registration / service principal** will not work — Matia uses the delegated user sign-in flow, not app-only (client-credentials) access.
  • Access to the target folder(s) for that account. The site or folder owner must share each SharePoint site/folder you plan to sync with the service account. The account only needs read access.

  • Microsoft admin consent (usually required once). Matia requests the Sites.Read.All delegated permission, which Microsoft classifies as requiring admin consent by default. Unless your tenant already allows user consent for this permission, a Global Administrator will need to grant consent to the Matia app the first time it is authorized. This is a one-time, tenant-wide step.

Permissions requested

Matia requests the following Microsoft Graph delegated scopes:

ScopePurpose
Sites.Read.AllRead the SharePoint sites the signed-in account can access.
files.readRead the files the signed-in account can access.
offline_accessIssue a refresh token so Matia can keep the connection alive.

All access is read-only and bounded by the signed-in account's own permissions.

Setup

  1. In Matia, go to Connectors → Add connector and select SharePoint.
  2. Click Sign in with SharePoint. You are redirected to Microsoft to sign in.
  3. Sign in with the service account you prepared, and approve the consent prompt.
    • If you see a message that admin approval is required, have a Global Administrator grant consent to the Matia app, then sign in again.
  4. Back in Matia, enter the SharePoint folder URL for the folder you want to sync.
    • In SharePoint, navigate to the folder, choose Copy link, and paste that link into the SharePoint folder URL field.
    • The service account must have access to this folder.
  5. Configure your sync settings and save the connector.
Each SharePoint connector syncs a **single folder** (and its contents). To sync multiple folders or sites, create one connector per folder URL, and make sure the service account has access to each.

Troubleshooting

  • "Need admin approval" during sign-in. Your tenant requires admin consent for Sites.Read.All. Ask a Global Administrator to grant consent to the Matia app, then retry.
  • Folder not found / access denied. Confirm the service account has been granted access to the specific site/folder, and that the folder URL is a valid Copy link URL to a folder (not a file).
  • Connection stopped working after a while. Re-authorize the connector. Refresh tokens can be invalidated by password changes, revoked sessions, or tenant conditional-access policy changes on the service account.

ON THIS PAGE

Need Help?

Get help and support on all things Matia.

Contact Us