> AI agents: this is one page from Mammoth Analytics documentation. The index of all pages as Markdown is https://docs.mammoth.io/llms.txt. Append `.md` to any docs URL, or send `Accept: text/markdown`, to get Markdown.

# Set up SharePoint client credentials

> Register an app in Microsoft Entra ID and get the client credentials Mammoth needs to download files from SharePoint.

This guide is for Microsoft 365 administrators. It walks you through registering an app in Microsoft Entra ID (formerly Azure AD) from the Microsoft 365 admin center at `https://admin.microsoft.com`, and obtaining the client credentials Mammoth needs to download files from SharePoint using the Microsoft Graph API.

## What the app does and the permissions it needs

- The app will get secure access tokens via [**<u>MSAL</u>**](https://learn.microsoft.com/en-us/entra/identity-platform/msal-overview) to list and download files from SharePoint document libraries.
- **Recommended permissions** (Application type):
  - `Sites.Read.All`
- These are **Application permissions** (not Delegated), so they require **admin consent**.

## Prerequisites

- You must sign in with a **Global Administrator** or **Application Administrator** account in your Microsoft 365 tenant.

---

## Step 1: Sign in to the Microsoft 365 admin center

1. Go to [**https://admin.microsoft.com**](https://admin.microsoft.com/) and sign in with your admin account.
2. In the left navigation pane, click **All admin centers** (near the bottom).
3. Select **Microsoft Entra**.
4. Click **Go to Microsoft Entra ID** (or **Go to Entra admin center**).

You are now in the **Microsoft Entra admin center** (https://entra.microsoft.com).

---

## Step 2: Register a new application

1. In the left menu, expand **Entra ID** → click **App registrations**.

2. Click **+ New registration** at the top.

3. Fill in the form:

   - **Name**: Enter something clear, e.g., `SharePoint-File-Downloader`.
   - **Supported account types**: Select the appropriate account type.
   - **Redirect URI**: Leave blank (not needed for app-only/daemon apps).

4. Click **Register**.

---

## Step 3: Note your app credentials (client ID and tenant ID)

After registration, you land on the app **Overview** page.

- Copy and save securely:
  - **Application (client) ID** → This is your `client_id`.
  - **Directory (tenant) ID** → This is your `tenant_id`.

> Tip: Store the IDs securely\
Paste these into a secure note or a password manager. You need them when you connect SharePoint in Mammoth.

---

## Step 4: Add Microsoft Graph API permissions (`Sites.Read.All`)

1. In the left menu (under **Manage**), click **API permissions**.
2. Click **+ Add a permission**.
3. Select **Microsoft Graph**.
4. Choose **Application permissions** (important for app-only access).
5. In the search box, type:
   - `Sites.Read.All` → select it.
6. Click **Add permissions**.

You should now see the permissions listed under **Configured permissions**.

---

## Step 5: Grant admin consent

1. Still on the **API permissions** page, click **Grant admin consent for [Your Tenant Name]**.
2. Review the permissions in the pop-up.
3. Click **Accept** / **Yes**.

**Status** should now show “Granted for [Your Tenant]” for each permission.

---

## Step 6: Create a client secret

1. In the left menu (under **Manage**), click **Certificates & secrets**.
2. Under **Client secrets**, click **+ New client secret**.
3. Enter a **Description** (e.g., “SharePoint downloader secret”).
4. Choose an **expiration** period (for example, 6 or 12 months; shorter is more secure).
5. Click **Add**.

> Warning: The secret value appears only once\
The **Value** of the secret appears **only once**. Copy it immediately and store it securely with your client_id and tenant_id. This is your `client_secret`.

---

## Step 7: Verify the registration (optional)

- Go back to **Overview** → confirm Client ID and Tenant ID.
- Go to **API permissions** → confirm consent is granted.
- Go to **Certificates & secrets** → confirm the secret is listed (Value is hidden).

---

## Step 8: Get the SharePoint site URL

The most straightforward method is to navigate to the SharePoint site and check the URL in your browser's address bar.

- **The Format:** This usually appears as `https://[your-domain].sharepoint.com/sites/[site-name]` or simply `https://[your-domain].sharepoint.com` for the default site.

- **Common mistake:** Make sure you are not copying the URL of a specific file or a deep sub-folder.

  - **Correct:** `.../sites/Marketing`

  - **Too Deep:** `.../sites/Marketing/Shared%20Documents/Forms/AllItems.aspx`

---

With the client ID, tenant ID, client secret, and site URL ready, you can connect your Mammoth workspace to SharePoint using the [SharePoint connector](https://docs.mammoth.io/learn/connectors/sharepoint-connector/).

---
Source: https://docs.mammoth.io/guides/integrations/sharepoint-client-credentials.md · Updated: 2026-10-03