SharePoint integration in Entra: the technical setup

This article outlines the requirements for executing a SharePoint integration with MKG, including user-level licenses, access to Entra and MKG, the setup of SharePoint sites, and security groups. This article provides step-by-step guides for creating an Entra app registration and setting up SharePoint sites.

 


 

Kan afbeelding niet inladen

Have your IT provider handle the setup
Activating an integration with Microsoft® SharePoint requires technical and functional knowledge of Microsoft® SharePoint and Microsoft® Entra. Therefore, have your IT provider handle this setup. If there are any further questions, MKG can, of course, provide support.

 

 

Requirements

 

Licenses

To use a SharePoint integration (hereafter referred to as SP) with MKG, an Entra environment (hereafter referred to as Entra) is required, equipped with the appropriate user-level licenses.

 

License Entra App Registration SP Online Storage Works with MKG
Microsoft Entra ID Free
M365 Business Basic (1 TB org + 10 GB/user)
M365 Business Standard
M365 Business Premium
Office 365 E1
Office 365 E3
Office 365 E5
SharePoint Online Plan 1 (standalone)
SharePoint Online Plan 2 (standalone)

 

Access to Entra environment

Creating an app registration in Entra requires specific rights. An administrator must have at least the 'Application Developer' role to perform an app registration. This role provides sufficient rights to create an app and add API permissions. However, to grant admin consent at the tenant level - which is necessary for certain permissions, such as Microsoft® Graph - the 'Global Administrator' role is required. Therefore, it is advisable that a Global Administrator performs the app registration or is at least available to provide the necessary consent.

 

SharePoint Site for document storage

To use the SP integration within MKG, it is necessary that an SP site is available for document storage. This site must be pre-configured with a stable structure and a clear rights configuration. The site must be accessible to users who want to store or access documents via MKG.

 

Kan afbeelding niet inladen

Please note!
Changes to the configuration of this site (such as structure or rights) should be avoided as much as possible afterward to ensure the reliability and continuity of the connection.

 

 

Security groups and user membership

Within Entra, security groups must be set up, which will eventually be linked to document categories in MKG. The document category in MKG determines which documents a user sees in the MKG interface. Actual access to the document is determined by membership in the linked security group.

A user may see a document as a record in MKG but cannot open it due to missing membership. Conversely, a user may have access to a document via SP, but it is not visible in MKG.

 

Kan afbeelding niet inladen

Please note!
Changes in group composition should be avoided as much as possible afterward to ensure the stability of document access.

 

 

 


 

 

Entra Setup User-Based App Registration

 

Follow the steps below to create an app registration that allows MKG users to store or access documents via the UI (user interface) in combination with SharePoint.

 

Step 1: Sign in

Go to the Microsoft Entra Portal and sign in with a user (it is recommended to use a user with the 'Global Administrator' role).

 

Step 2: New registration

Choose 'App registrations' in the menu and then select the action New registration.

 

Kan afbeelding niet inladen

 

 

Step 3: Enter the app registration name

For the app registration, enter "MKG ERP Sharepoint user-based" under Name. Select the (default) option 'Accounts in this organizational directory only (Single tenant)' under 'Supported account types' and choose the action Register.

 

Kan afbeelding niet inladen

 

 

Step 4: Create a client secret

In the created app registration, go to 'Certificates & secrets' and choose New client secret.

 

Kan afbeelding niet inladen

 

Then, enter "MKG ERP Sharepoint user-based" under Description, select 'Recommended: 180 days (6 months)' under Expires, and click Add.

 

Kan afbeelding niet inladen

 

Kan afbeelding niet inladen

Please note!
After creating a client secret, the 'Secret Value' is shown only once in the current session. Note this value immediately, along with the 'Secret ID' and the expiration date ('Expiration date'), so you can store it safely for further configuration. After closing the session, this newly created 'Secret Value' cannot be retrieved.

 

 

Kan afbeelding niet inladen

 

Step 5: Execute the API permissions

In the created app registration, go to 'API permissions' and choose Add a permission and add the following Microsoft Graph permissions (type 'Delegated' or 'Application').

 

Permission Description Type Admin consent required
Files.ReadWrite.AppFolder Read/write in sandbox folder per user Delegated
Group.Read.All Read Microsoft 365 groups Application
Sites.FullControl.All Full access to all SharePoint sites Application
Sites.Selected Limited access to specific SharePoint sites Application
User.Read Read profile of signed-in user Delegated

 

 

Kan afbeelding niet inladen

 

  • For the permissions 'Group.Read.All', 'Sites.FullControl.All', and 'Sites.selected', additional approval is required. Perform the action Grant admin consent for this.
  • The permission 'Sites.FullControl.All' is only needed during setup for setting rights (Sites.selected) on a specific SP site.

 

Step 6: Note the Client ID and Tenant ID

In the created app registration, go to the 'Overview' tab. Record the values of both the 'Application (client) ID' and the 'Directory (tenant) ID'. Note this information, along with the information from step 4, for the subsequent steps.

 

Kan afbeelding niet inladen

 


 

 

Sites.Selected Setup in SharePoint

 

With Sites.Selected, an app registration does not automatically gain access to all SP sites in the tenant, but only to those sites for which explicit permission has been granted by an SP administrator. This prevents sensitive or internal information from being inadvertently accessible to applications.

 

Step 1: Sign in

Go to the Microsoft 365 Admin Center and sign in with a user (it is recommended to use a user with the 'Global Administrator' role).

 

Step 2: Select the admin center

Choose 'Admin Centers' in the menu and then select 'SharePoint'. You will automatically enter the correct Admin Center for your tenant (e.g., https://contoso-admin.sharepoint.com).

 

Step 3: Note the Site ID

Select the site to be used for the integration with MKG and extract the 'siteId' from the URL in the address bar. Record this value for the next step. For example:

URL: https://contoso-admin.sharepoint.com/_layouts/15/online/AdminHome.aspx#/siteManagement/:/SiteDetails/b8df588c-ff95-44b3-bf3b-8d498c712345a

SiteID: b8df588c-ff95-44b3-bf3b-8d498c712345a

 

Step 4: Download the Sites.Selected Script

The Sites.selected item cannot be configured via a UI/web page. A template has been prepared for this, download the script 'MKG_Sites.Selected.ps1' and open it with a text editor of your choice. Fill in the previously noted values in the 'Config' section for the items tenantId, appId, clientSecret, and siteId, and save the changes.

 

Kan afbeelding niet inladen

 

 

 

 

Step 5: Execute the Sites.Selected Script

Run the script via 'Powershell' (right-click on the file and choose 'Run with Powershell'). Upon successful execution, the message "Write permission has been successfully granted to the application for the site." will be displayed.

 

Kan afbeelding niet inladen

Remove the API Permission
If step 5 was successful, it is highly recommended to remove the 'Sites.FullControl.All' permission from the app registration.