Connect Microsoft SharePoint to an Agent by signing in through the Agent's Microsoft Teams connection app using OAuth PKCE public client flows.
Prerequisites
SharePoint integration uses delegated Microsoft Graph permissions via the Agent's existing Microsoft Teams app registration. Before connecting SharePoint, ensure:
- The Agent has an enabled Microsoft Teams Communication Connection.
- You have access to the Azure / Microsoft Entra admin center for the Microsoft 365 tenant.
- You hold an Agent Access role with Secret management authority (Agent Owner or Organization Owner/Admin).
Configure Azure App Registration
Open the Microsoft Entra portal for the Teams bot application:
- Under Authentication > Platform configurations, select Add a platform > Mobile and desktop applications (do not select Web).
- Set the redirect URI to
https://<your-agentbarn-domain>/api/v1/integrations/microsoft/callback. - Under Advanced settings, enable Allow public client flows: Yes.
- Under API permissions, add delegated Microsoft Graph permissions:
Sites.Read.All(for read-only access) orSites.ReadWrite.All(for read-write access)offline_access(for automatic refresh token rotation)
- If tenant policy restricts user consent, click Grant admin consent.
Sign in from Agent Barn
Navigate to the Agent's detail page, select Integrations, and choose Connect SharePoint.
Select the Teams Connection, pick either Read-only or Read/Write access level, and complete the sign-in prompt. Agent Barn will verify tenant identity, negotiate tokens via PKCE, and store the encrypted credentials with an automatic refresh token rotation cycle.
Runtime access and aai-cli commands
Once connected, the bundled aai-microsoft Skill is mounted to the Agent runtime with the microsoft-work profile configured automatically. The Agent can search sites, inspect document libraries, and interact with files:
aai-cli --profile microsoft-work sharepoint sites list
aai-cli --profile microsoft-work sharepoint files search --query "quarterly-report"The refresh token is stored in the Agent's persistent volume store and safely excluded from backup restore points. Unused tokens remain valid for 90 days before requiring re-authentication.
API endpoints
The setup metadata and OAuth authorization parameters can be retrieved through the REST API:
GET /api/v1/organizations/{organization_id}/agents/{agent_id}/integrations/sharepoint/setup?connection_id={connection_id}{
"app_id": "00000000-0000-0000-0000-000000000000",
"tenant_id": "11111111-1111-1111-1111-111111111111",
"redirect_uri": "https://agentbarn.example.com/api/v1/integrations/microsoft/callback",
"admin_consent_url": "https://login.microsoftonline.com/11111111-1111-1111-1111-111111111111/v2.0/adminconsent?...",
"supported_access_levels": ["READ_ONLY", "READ_WRITE"]
}