Overview
The Microsoft SharePoint integration lets agents search sites, browse document libraries, and read files through Microsoft Graph. Aster supports two authentication modes so each organization can match its Microsoft 365 access model.- Each member connects (recommended): every Aster member authorizes their own Microsoft account. SharePoint tools inherit that person’s delegated permissions and cannot use another member’s credential.
- Shared Microsoft account: one Aster admin authorizes a Microsoft account for the organization. Every member using a SharePoint-enabled agent accesses SharePoint as that shared account.
Setup Guide
1
Choose an authentication mode
An Aster admin opens Control Hub > Integrations, selects Microsoft SharePoint, and chooses Each member connects or Shared Microsoft account.
2
Authorize Microsoft 365 access
Sign in with a Microsoft 365 work or school account and approve delegated access to sites and files. Some Microsoft tenants require an Entra administrator to grant tenant-wide consent before members can connect.
3
Add SharePoint tools to an agent
Edit an agent and select the SharePoint tools it needs. SharePoint tools are read-only.
4
Connect each member when using per-user mode
The admin’s successful authorization enables SharePoint for the organization and connects that admin. Other members are prompted to authorize their own Microsoft account when they use a SharePoint-enabled agent.
Available Tools
sharepoint_list_sites— List SharePoint sites visible to the acting or shared Microsoft account.sharepoint_search— Search SharePoint and OneDrive content available through Microsoft Graph.sharepoint_list_drive_items— Browse folders and document-library items.sharepoint_read_file— Read supported text files or download a binary file up to 5 MB into the Aster conversation.
Choosing a Mode
Use Each member connects when SharePoint permissions differ by person, access must be attributable to the acting member, or the Microsoft tenant does not permit a broadly accessible service account. Use Shared Microsoft account when the organization deliberately maintains a Microsoft account whose SharePoint access should be available to everyone using the Aster integration. The shared account’s SharePoint permissions become the effective permissions for all those users, so keep its access narrowly scoped. Changing modes does not remove the active connection when the OAuth flow starts. Aster switches the organization only after the replacement authorization succeeds. Canceling the flow or being blocked by a Microsoft security policy leaves the current connection active.Security
- Delegated Microsoft Graph access: Aster requests
Sites.Read.AllandFiles.Read.All; SharePoint tools do not write to Microsoft 365. - Mode-enforced credential selection: per-user mode uses only the acting Aster member’s credential; shared mode uses only the organization’s credential.
- Server-side tokens: access and refresh tokens are never returned to the browser or agent.
- Legacy-safe rollout: connections created before per-user mode remain organization-shared unless an admin completes a mode change.
- Bounded requests: Graph calls have timeouts, limited throttling retries, and a 5 MB limit for binary file downloads.
- Untrusted content: agents should treat SharePoint file contents as data, never as instructions.
Troubleshooting
Microsoft says admin approval is required
Microsoft says admin approval is required
The Microsoft tenant may block end-user consent. Ask a Microsoft Entra administrator to approve the Aster application and its delegated SharePoint permissions for the tenant, then retry the connection.
A member cannot see a site that someone else can see
A member cannot see a site that someone else can see
In per-user mode, this is expected when Microsoft permissions differ between those accounts. Grant the member access in Microsoft 365, or intentionally switch the Aster integration to a suitably restricted shared account.
A mode change was canceled or blocked
A mode change was canceled or blocked
Aster keeps the previous SharePoint connection and mode until the replacement OAuth flow completes successfully. No rollback is necessary.