Integrations
How-to

Connect SharePoint

Connect Microsoft SharePoint to an Agent Barn Agent via the Microsoft Teams app registration using delegated OAuth PKCE public client flows.

For
Microsoft 365 administrators, Agent operators, and Organization administrators
On this page
  1. 1. Prerequisites
  2. 2. Configure Azure App Registration
  3. 3. Sign in from Agent Barn
  4. Runtime access and aai-cli commands
  5. API endpoints
  • Integrations
  • SharePoint & Microsoft 365
  • PKCE public client sign-in

Connect Microsoft SharePoint to an Agent by signing in through the Agent's Microsoft Teams connection app using OAuth PKCE public client flows.

Prerequisites

SharePoint integration uses delegated Microsoft Graph permissions via the Agent's existing Microsoft Teams app registration. Before connecting SharePoint, ensure:

  • The Agent has an enabled Microsoft Teams Communication Connection.
  • You have access to the Azure / Microsoft Entra admin center for the Microsoft 365 tenant.
  • You hold an Agent Access role with Secret management authority (Agent Owner or Organization Owner/Admin).

Configure Azure App Registration

Open the Microsoft Entra portal for the Teams bot application:

  1. Under Authentication > Platform configurations, select Add a platform > Mobile and desktop applications (do not select Web).
  2. Set the redirect URI to https://<your-agentbarn-domain>/api/v1/integrations/microsoft/callback.
  3. Under Advanced settings, enable Allow public client flows: Yes.
  4. Under API permissions, add delegated Microsoft Graph permissions:
    • Sites.Read.All (for read-only access) or Sites.ReadWrite.All (for read-write access)
    • offline_access (for automatic refresh token rotation)
  5. If tenant policy restricts user consent, click Grant admin consent.

Sign in from Agent Barn

Navigate to the Agent's detail page, select Integrations, and choose Connect SharePoint.

Select the Teams Connection, pick either Read-only or Read/Write access level, and complete the sign-in prompt. Agent Barn will verify tenant identity, negotiate tokens via PKCE, and store the encrypted credentials with an automatic refresh token rotation cycle.

Runtime access and aai-cli commands

Once connected, the bundled aai-microsoft Skill is mounted to the Agent runtime with the microsoft-work profile configured automatically. The Agent can search sites, inspect document libraries, and interact with files:

SharePoint commands
aai-cli --profile microsoft-work sharepoint sites list
aai-cli --profile microsoft-work sharepoint files search --query "quarterly-report"

The refresh token is stored in the Agent's persistent volume store and safely excluded from backup restore points. Unused tokens remain valid for 90 days before requiring re-authentication.

API endpoints

The setup metadata and OAuth authorization parameters can be retrieved through the REST API:

Setup endpoint
GET /api/v1/organizations/{organization_id}/agents/{agent_id}/integrations/sharepoint/setup?connection_id={connection_id}
Setup response
{
  "app_id": "00000000-0000-0000-0000-000000000000",
  "tenant_id": "11111111-1111-1111-1111-111111111111",
  "redirect_uri": "https://agentbarn.example.com/api/v1/integrations/microsoft/callback",
  "admin_consent_url": "https://login.microsoftonline.com/11111111-1111-1111-1111-111111111111/v2.0/adminconsent?...",
  "supported_access_levels": ["READ_ONLY", "READ_WRITE"]
}
Documentation