Knowledge Management
Microsoft SharePoint
Microsoft SharePoint
Microsoft SharePoint: Permissions and setup
This is an article about setting up the integration. To find out how you can train the Assistant on SharePoint documents, please go here.
Permissions
To connect your Atomicwork and Microsoft SharePoint accounts, you need:
- Atomicwork admin access: You need org admin access in Atomicwork.
- Microsoft Entra access.
| Permission | Description | Usecase |
|---|---|---|
| Group.Read.All | Read all groups | Required to know which groups have access to which sites and files |
| GroupMember.Read.All | Read all group memberships | Required to know which groups have access to which sites and files |
| Sites.FullControl.All | Have full control of all site applications | Required to make sure the Assistant can read from all SharePoint sites, regardless of group type. |
| Sites.Read.All | Read items in site collections | Required to access content |
| Sites.ReadWrite.All | Read and write items in all site collections | [OPTIONAL] Required for a WIP capability where the Assistant can make updates to content, based on user suggestions. This permission can be removed after installation. |
| User.Read | Sign in and read user profile | Required to understand user access permissions |
| User.Read.All | Read all users' profiles | Required for fine-grained access based on user profiles |
Setup
We recommend connecting with a service account — a non-human Microsoft 365 account used by integrations and automated processes to access resources like SharePoint, rather than being tied to an individual person. Using one keeps the connection stable even as people join or leave.
- As an Atomicwork admin, navigate to Settings > App Store > Microsoft SharePoint, and click on Connect.
- Click on Enable to access a page that displays the permissions Atomicwork needs to successfully leverage the integration.
- Click on Accept.
