Set up the Microsoft side so Sasha can sign in to OneDrive or a SharePoint library

The steps in Microsoft Entra that give you the client ID, secret value and directory ID that a OneDrive or SharePoint connection in Settings → Shared Drives needs.

Where
The Microsoft Entra admin portal (entra.microsoft.com) first, then Settings → Shared Drives in Sasha.
Who
A Sasha admin, with a Microsoft 365 account that can register apps. A Microsoft 365 administrator must give admin consent.
Needs
A Microsoft 365 business account, an app registration with the redirect address from the Sasha connection card, a client secret, and admin consent. SharePoint also needs the Drive ID of the library.

What this page is for

A OneDrive or SharePoint connection in Settings → Shared Drives asks for a Client ID, a Client secret and a directory ID. Microsoft gives you these when you register Sasha as an app in Microsoft Entra (the new name for Azure Active Directory). This page tells you how. For the Sasha screen itself, see Let Sasha read files that live in OneDrive, SharePoint or Google Drive without uploading them.

You do the steps once for each Sasha. They take about 15 minutes, and more if you must wait for an administrator to give consent.

Before you start

  1. In Sasha, open Settings → Shared Drives.
  2. Click Add Connection. Choose Microsoft 365 OneDrive or Microsoft SharePoint Library, type a display name and click Save Connection. For SharePoint, you need the Drive ID first (see "Find the Drive ID of a SharePoint library" below).
  3. On the new connection card, find Redirect URI and click Copy. Keep this address. It looks like https://your-sasha.example.com/api/auth/m365/callback.

The address comes from the address your browser uses for Sasha. Open Sasha at its public address before you copy it.

Step 1: register the app

  1. Go to the Microsoft Entra admin portal and sign in with your work account. The same screens are in the Azure portal under Microsoft Entra ID.
  2. Open Identity → Applications → App registrations and click New registration.
  3. Name: type "Sasha Drive".
  4. Supported account types: choose the first option, "Accounts in this organisational directory only".
  5. Redirect URI: choose the platform Web and paste the Redirect URI from the Sasha card.
  6. Click Register.
  7. On the Overview page, copy the Application (client) ID and the Directory (tenant) ID. Sasha calls these Client ID and the directory ID.

Step 2: make a client secret

  1. In the app registration, open Certificates & secrets.
  2. Under Client secrets, click New client secret.
  3. Type a description, for example "Sasha", and choose when it expires. Write the date down.
  4. Click Add.
  5. Copy the Value now. Microsoft shows it only once. Do not copy the Secret ID: Sasha needs the Value.

Step 3: add the permissions

  1. Open API permissions and click Add a permission.
  2. Choose Microsoft Graph, then Delegated permissions.
  3. Select the permissions for the scope you will choose in Sasha:
Sasha scope Permissions to add
Read & write Files.ReadWrite.All, Sites.ReadWrite.All
Read-only Files.Read.All, Sites.Read.All
Both User.Read, offline_access, openid, profile
  1. Click Add permissions.

offline_access lets Sasha keep its sign-in after the first hour. Without it, Sasha shows "Provider did not return a refresh token. Ensure consent is granted."

Step 4: give admin consent

The file permissions need consent from a Microsoft 365 administrator.

  1. In API permissions, click Grant admin consent for and your organisation's name.
  2. Click Yes.
  3. Each permission shows a green tick and "Granted".

If the button is grey, you are not an administrator. Send the app registration's name to your Microsoft 365 administrator and ask them to do this step.

Step 5: connect in Sasha

  1. Go back to Settings → Shared Drives and find your connection card.
  2. Paste the Client ID, the Client secret (Value, not Secret ID) and the directory ID.
  3. Click Connect.
  4. Sign in to Microsoft with the account whose files Sasha should read, and accept.
  5. Microsoft sends you back to Sasha. A message says "Microsoft 365 authorized successfully." The card shows Connected and the account.

Find the Drive ID of a SharePoint library

A SharePoint connection needs the Drive ID of one document library. One way is Microsoft Graph Explorer:

  1. Open Graph Explorer and sign in with your work account.
  2. Find the site. Run this request, with your SharePoint host name and the site's path from its web address: GET https://graph.microsoft.com/v1.0/sites/yourcompany.sharepoint.com:/sites/Finance
  3. Copy the id from the answer.
  4. List the libraries of the site: GET https://graph.microsoft.com/v1.0/sites/{site-id}/drives
  5. Find the library by its name (the library "Documents" is often called "Documents" or "Shared Documents"), and copy its id. This is the Drive ID. It starts with b!.

If Graph Explorer asks for permission, consent to Sites.Read.All. The Sasha form shows two other ways to find the Drive ID.

Keep it safe

  • Paste the client secret only into Sasha. Do not send it by email or chat.
  • Sasha stores the client secret and Microsoft's sign-in encrypted on your Sasha server. The secret never goes back to the browser.
  • The account that signs in decides what Sasha can see. Files.ReadWrite.All and Sites.ReadWrite.All reach every file that the account can open, not only one library. Choose Read-only in Sasha and add only the read permissions if people do not need to change files.
  • Put the secret's expiry date in your calendar. When it expires, the drive stops working in Sasha.

Questions

Can I use a personal Microsoft account?

No. Sasha supports only Microsoft 365 business accounts. Personal (consumer) OneDrive accounts are not supported.

Do I need to be a Microsoft 365 administrator?

To register the app, often not. To give admin consent for the file permissions, yes. If you are not an administrator, ask one to do step 4.

Connect fails with AADSTS50011. Why?

The redirect address in the app registration does not match the one on the Sasha connection card exactly. Copy it again from the card and paste it under Authentication. Check http and https, the host name and the end of the path.

Connect fails with AADSTS65001 or "Need admin approval". Why?

Nobody has given admin consent for the permissions. A Microsoft 365 administrator must click Grant admin consent in the app registration (step 4).

Connect fails with AADSTS7000215. Why?

The client secret is wrong. You probably pasted the Secret ID and not the Value. Make a new secret, copy its Value, and type it into Sasha again.

Why does the connection stop after some months?

The client secret has expired. Microsoft secrets last for a time that you choose, at most 24 months. Make a new secret before the old one expires, type it into Sasha and click Reconnect.

Which account should sign in when I click Connect?

For OneDrive, the account whose files you want people to see in Sasha. For SharePoint, an account that can open the library. Sasha sees what that account can open.

How do I cancel Sasha's access at Microsoft?

Delete the app registration, or delete its client secret. You can also remove the app under Enterprise applications. Remove in Sasha alone does not cancel the access at Microsoft.

made with bernard

Cookie settings