Overview
The SharePoint connector syncs files (CSV, Excel, and other supported formats) from a specific SharePoint folder into your destination. It authenticates using delegated OAuth 2.0 against the Microsoft identity platform: you sign in with a Microsoft 365 account, and Matia reads SharePoint as that account, limited to whatever that account can access.
Because access is delegated, the connector never has tenant-wide access. It can only read the sites and folders that the account you sign in with has been granted access to.
Prerequisites
Before you begin, make sure you have:
-
A Microsoft 365 account to authenticate with. We recommend a dedicated service account (a standard, licensed M365 user) rather than a personal account, so the connection is not tied to an individual employee.
The account must be a normal user that can complete an **interactive browser sign-in** (including MFA, if your tenant enforces it). A headless Entra **app registration / service principal** will not work — Matia uses the delegated user sign-in flow, not app-only (client-credentials) access. -
Access to the target folder(s) for that account. The site or folder owner must share each SharePoint site/folder you plan to sync with the service account. The account only needs read access.
-
Microsoft admin consent (usually required once). Matia requests the
Sites.Read.Alldelegated permission, which Microsoft classifies as requiring admin consent by default. Unless your tenant already allows user consent for this permission, a Global Administrator will need to grant consent to the Matia app the first time it is authorized. This is a one-time, tenant-wide step.
Permissions requested
Matia requests the following Microsoft Graph delegated scopes:
| Scope | Purpose |
|---|---|
Sites.Read.All | Read the SharePoint sites the signed-in account can access. |
files.read | Read the files the signed-in account can access. |
offline_access | Issue a refresh token so Matia can keep the connection alive. |
All access is read-only and bounded by the signed-in account's own permissions.
Setup
- In Matia, go to Connectors → Add connector and select SharePoint.
- Click Sign in with SharePoint. You are redirected to Microsoft to sign in.
- Sign in with the service account you prepared, and approve the consent prompt.
- If you see a message that admin approval is required, have a Global Administrator grant consent to the Matia app, then sign in again.
- Back in Matia, enter the SharePoint folder URL for the folder you want to sync.
- In SharePoint, navigate to the folder, choose Copy link, and paste that link into the SharePoint folder URL field.
- The service account must have access to this folder.
- Configure your sync settings and save the connector.
Troubleshooting
- "Need admin approval" during sign-in. Your tenant requires admin consent for
Sites.Read.All. Ask a Global Administrator to grant consent to the Matia app, then retry. - Folder not found / access denied. Confirm the service account has been granted access to the specific site/folder, and that the folder URL is a valid Copy link URL to a folder (not a file).
- Connection stopped working after a while. Re-authorize the connector. Refresh tokens can be invalidated by password changes, revoked sessions, or tenant conditional-access policy changes on the service account.