Skip to main content
Version: Latest

Microsoft OneDrive connector

The OneDrive connector exposes the Microsoft Graph OneDrive API as a set of MCP tools (list files, read, upload, share) through the PolicyArc gateway. Every tool call carries the caller's own Microsoft OAuth token, so OneDrive's per-user permissions apply naturally.

Prerequisite

You must have the Microsoft Entra ID identity provider connected first. The connector reuses the same Entra app registration — make sure it has the Microsoft Graph Files.Read, Files.Read.All, Files.ReadWrite, and Files.ReadWrite.All delegated permissions (Step 7 of the Microsoft IDP setup).


Step 1 — Open the Add Connector screen​

Open Resources → Add connector (or click Pick a connector from the environment dashboard).

In the Unlocked by your identity providers section, the Microsoft OneDrive template will show a green border once the Microsoft IDP is connected.

Connector list — OneDrive ready

Click Microsoft OneDrive.


Step 2 — Connect​

Microsoft OneDrive's setup form opens on the Authentication mode, pre-filled with entra_refresh (recommended). Two modes are available:

  • entra_refresh (default) — PolicyArc uses the refresh token obtained at sign-in to mint a per-user Graph token at call time. Works alongside any other Microsoft connector (Mail, Teams, Azure DevOps) in the same session with a single sign-in. No separate gateway app required.
  • idp_passthrough — forwards your Microsoft sign-in token straight to Graph. Use this only when every Microsoft connector you run targets Microsoft Graph (Mail, OneDrive, Teams) and the sign-in is audienced for Graph. Don't combine it with Azure DevOps or with entra_refresh connectors.

Leave it on entra_refresh unless you specifically want the direct-passthrough path, then click Connect.

OneDrive setup screen


Step 3 — Confirm the connector​

After connecting, you'll see the connector's status screen with the available OneDrive tools. The connector is policy-governed from the first request.

You can return to this view any time from the Resources menu by clicking View on the Microsoft OneDrive entry.


What's next​

The OneDrive tools are now on your gateway. Pick an MCP client to wire up: