Skip to content
Get startedRequest a demo
Document repositories

Microsoft SharePoint

SharePoint Online (M365) and SharePoint Server (on-premises)

Access mode: Read-only (typically)

Required information

FieldDetails
SharePoint site URL(s)Full URLs of sites containing target document libraries (e.g., https://<tenant>.sharepoint.com/sites/<site>).
Document library namesSpecific libraries, or “all libraries” in specified sites.
Azure AD tenant IDM365 tenant identifier.
App registrationAzure AD app registration with SharePoint API permissions.
API permissionsRead-only: Sites.Read.All (application permission). For specific sites only: Sites.Selected.

Network considerations

SharePoint Online: HTTPS over 443 to <tenant>.sharepoint.com. No VPN needed.

SharePoint Server (on-prem): VPN or reverse proxy required. Must reach the SharePoint web application URL.

Conditional Access: If Azure AD tenant enforces Conditional Access, the app registration must meet policy requirements (e.g., compliant device, named location).

Credential and auth management

Preferred: Azure AD app registration (client credentials). Register app in Azure AD, grant Sites.Read.All or Sites.Selected, admin consent required. Flume authenticates with client ID + client secret or certificate.

Certificate-based auth preferred over client secret: More secure, no secret rotation needed (just cert renewal).

Sites.Selected: More restrictive than Sites.Read.All. Requires individual site permissions to be granted via Graph API or PowerShell. More work upfront but tighter security.

Token refresh: OAuth tokens expire in 60 to 90 min. Flume handles refresh automatically.

Validation checks

CheckMethodExpected result
AuthenticationGET https://graph.microsoft.com/v1.0/sites/<site-id>200 with site metadata
Library accessGET https://graph.microsoft.com/v1.0/sites/<site-id>/drivesLists document libraries
File listingGET https://graph.microsoft.com/v1.0/drives/<drive-id>/root/childrenLists files/folders
File readGET https://graph.microsoft.com/v1.0/drives/<drive-id>/items/<item-id>/contentDownloads file content
Search testPOST https://graph.microsoft.com/v1.0/search/queryReturns search results

Every connection starts from the pre-engagement checklist and goes through the universal validation protocol before production sign-off.