Microsoft SharePoint
SharePoint Online (M365) and SharePoint Server (on-premises)
Access mode: Read-only (typically)
Required information
| Field | Details |
|---|---|
| SharePoint site URL(s) | Full URLs of sites containing target document libraries (e.g., https://<tenant>.sharepoint.com/sites/<site>). |
| Document library names | Specific libraries, or “all libraries” in specified sites. |
| Azure AD tenant ID | M365 tenant identifier. |
| App registration | Azure AD app registration with SharePoint API permissions. |
| API permissions | Read-only: Sites.Read.All (application permission). For specific sites only: Sites.Selected. |
Network considerations
SharePoint Online: HTTPS over 443 to <tenant>.sharepoint.com. No VPN needed.
SharePoint Server (on-prem): VPN or reverse proxy required. Must reach the SharePoint web application URL.
Conditional Access: If Azure AD tenant enforces Conditional Access, the app registration must meet policy requirements (e.g., compliant device, named location).
Credential and auth management
Preferred: Azure AD app registration (client credentials). Register app in Azure AD, grant Sites.Read.All or Sites.Selected, admin consent required. Flume authenticates with client ID + client secret or certificate.
Certificate-based auth preferred over client secret: More secure, no secret rotation needed (just cert renewal).
Sites.Selected: More restrictive than Sites.Read.All. Requires individual site permissions to be granted via Graph API or PowerShell. More work upfront but tighter security.
Token refresh: OAuth tokens expire in 60 to 90 min. Flume handles refresh automatically.
Validation checks
| Check | Method | Expected result |
|---|---|---|
| Authentication | GET https://graph.microsoft.com/v1.0/sites/<site-id> | 200 with site metadata |
| Library access | GET https://graph.microsoft.com/v1.0/sites/<site-id>/drives | Lists document libraries |
| File listing | GET https://graph.microsoft.com/v1.0/drives/<drive-id>/root/children | Lists files/folders |
| File read | GET https://graph.microsoft.com/v1.0/drives/<drive-id>/items/<item-id>/content | Downloads file content |
| Search test | POST https://graph.microsoft.com/v1.0/search/query | Returns search results |
Every connection starts from the pre-engagement checklist and goes through the universal validation protocol before production sign-off.