The SharePoint knowledge connector requires permissions in both Applaud and Microsoft Entra ID. Together, these permissions determine who can manage the connector, authorize access, discover SharePoint sites, and synchronize content.
Permission layers
The SharePoint knowledge connector relies on two permission layers.
| Layer | Controls |
| Applaud | Who can manage the SharePoint knowledge connector, connect SharePoint sites, and run synchronizations. |
| Microsoft Entra ID and SharePoint | Who can authorize Applaud, discover SharePoint sites, and access SharePoint content. |
Both permission layers must be configured. Applaud permissions alone don't grant access to SharePoint content.
Applaud permissions
You need Tenant Administrator permissions in Applaud to manage the SharePoint knowledge connector.
A Tenant Administrator can:
- Configure the SharePoint connection.
- Connect and disconnect SharePoint sites.
- Start manual synchronizations.
- Monitor synchronization status.
Users without Tenant Administrator permissions can't manage the SharePoint knowledge connector or connected SharePoint sites.
Microsoft Graph permissions
Applaud uses Microsoft Graph permissions to discover SharePoint sites and read content during synchronization.
The connector requires the following permission:
| Permission | Purpose |
| Sites.Read.All | Allows Applaud to read SharePoint site content to synchronize knowledge. |
A Microsoft Entra administrator must grant administrator consent before Applaud can access SharePoint content.
For more information, see Prepare Microsoft authentication for the SharePoint knowledge connector.
Microsoft Entra roles
The following Microsoft Entra roles can grant organization-wide administrator consent for the Applaud application:
- Global Administrator
- Privileged Role Administrator
These roles are required only to grant or restore administrator consent. They aren't required for day-to-day SharePoint synchronization.
Roles and responsibilities
| Role | Responsibility |
| Applaud Tenant Administrator | Configure and manage the SharePoint knowledge connector, connect SharePoint sites, and run synchronizations. |
| Microsoft Entra Global Administrator or Privileged Role Administrator | Grant and manage organization-wide administrator consent. |
| SharePoint owner or content owner | Identify and maintain approved SharePoint sites for knowledge synchronization. |
| SharePoint owner or content owner | Identify and maintain approved SharePoint sites for knowledge synchronization. |
| Microsoft user connecting SharePoint sites | Sign in and connect SharePoint sites they have permission to access. |
SharePoint access requirements
Microsoft Graph permissions and SharePoint permissions work together.
The Microsoft account used to connect SharePoint sites must:
- Have access to the SharePoint sites you want to connect.
- Be able to open those sites directly in SharePoint.
- Maintain permission to read the content that Applaud synchronizes.
If the account can't access a SharePoint site directly, Applaud can't discover or synchronize that site.