---
title: Connect SharePoint
canonical: "https://agentbarn.dev/guides/integrations/sharepoint"
pubDate: "2026-08-29T00:00:00.000Z"
updatedDate: "2026-09-28T08:10:29.000Z"
author: Agent Barn
description: "Connect Microsoft SharePoint to an Agent Barn Agent with delegated OAuth PKCE public client flows via Microsoft Teams, the bundled aai-microsoft Skill, and aai-cli access."
tags: [Integrations, How-to, "Microsoft 365 administrators, Agent operators, and Organization administrators", SharePoint, Microsoft 365, Microsoft Teams, OAuth, PKCE, Sites.Read.All, Sites.ReadWrite.All, aai-cli, aai-microsoft, microsoft-work, files, sites]
categories: [Guides, Integrations]
---

-   Integrations
-   SharePoint & Microsoft 365
-   PKCE public client sign-in

Connect Microsoft SharePoint to an Agent by signing in through the Agent's Microsoft Teams connection app using OAuth PKCE public client flows.

## Prerequisites

SharePoint integration uses delegated Microsoft Graph permissions via the Agent's existing Microsoft Teams app registration. Before connecting SharePoint, ensure:

-   The Agent has an enabled **Microsoft Teams** Communication Connection.
-   You have access to the Azure / Microsoft Entra admin center for the Microsoft 365 tenant.
-   You hold an Agent Access role with Secret management authority (Agent Owner or Organization Owner/Admin).

**No client secret required**

SharePoint integration operates strictly as an OAuth 2.0 public client with Proof Key for Code Exchange (PKCE). It never requires, stores, or transmits the Teams bot client secret.

## Configure Azure App Registration

Open the Microsoft Entra portal for the Teams bot application:

1.  Under **Authentication** > **Platform configurations**, select **Add a platform** > **Mobile and desktop applications** (do not select Web).
2.  Set the redirect URI to `https://<your-agentbarn-domain>/api/v1/integrations/microsoft/callback`.
3.  Under **Advanced settings**, enable **Allow public client flows: Yes**.
4.  Under **API permissions**, add delegated Microsoft Graph permissions:
    -   `Sites.Read.All` (for read-only access) or `Sites.ReadWrite.All` (for read-write access)
    -   `offline_access` (for automatic refresh token rotation)
5.  If tenant policy restricts user consent, click **Grant admin consent**.

## Sign in from Agent Barn

Navigate to the Agent's detail page, select **Integrations**, and choose **Connect SharePoint**.

Select the Teams Connection, pick either **Read-only** or **Read/Write** access level, and complete the sign-in prompt. Agent Barn will verify tenant identity, negotiate tokens via PKCE, and store the encrypted credentials with an automatic refresh token rotation cycle.

## Runtime access and aai-cli commands

Once connected, the bundled `aai-microsoft` Skill is mounted to the Agent runtime with the `microsoft-work` profile configured automatically. The Agent can search sites, inspect document libraries, and interact with files:

```
aai-cli --profile microsoft-work sharepoint sites list
aai-cli --profile microsoft-work sharepoint files search --query "quarterly-report"
```

The refresh token is stored in the Agent's persistent volume store and safely excluded from backup restore points. Unused tokens remain valid for 90 days before requiring re-authentication.

## API endpoints

The setup metadata and OAuth authorization parameters can be retrieved through the REST API:

```
GET /api/v1/organizations/{organization_id}/agents/{agent_id}/integrations/sharepoint/setup?connection_id={connection_id}
```

```
{
  "app_id": "00000000-0000-0000-0000-000000000000",
  "tenant_id": "11111111-1111-1111-1111-111111111111",
  "redirect_uri": "https://agentbarn.example.com/api/v1/integrations/microsoft/callback",
  "admin_consent_url": "https://login.microsoftonline.com/11111111-1111-1111-1111-111111111111/v2.0/adminconsent?...",
  "supported_access_levels": ["READ_ONLY", "READ_WRITE"]
}
```
