How it works
Before you begin
You need a Microsoft 365 tenant with OneDrive for Business and the roles listed in Microsoft 365 Setup. Each user must open OneDrive once before Microsoft provisions their personal drive. Personal Microsoft accounts are not supported. Complete Microsoft 365 Setup with the OneDrive rows of its permission table. Both client secret and certificate credentials support indexing and permission sync.Configure Onyx
1
Open the OneDrive connector
In Onyx, go to Admin Panel → Add Connector and select OneDrive.
2
Select or create a credential
Select an existing OneDrive credential or create one as described in Microsoft 365
Setup.
3
Choose the users
Give the connector a descriptive name.Select General to index every enabled, non-guest user with a user principal name.
Select Specific to list user principal names or primary email addresses.
4
Adjust the advanced settings
Under Advanced Options, add glob patterns to Excluded Paths if needed. For example,
*.tmp skips that file type at every depth, and Archive/* skips files under that path.Change Authority Host and Graph API Host only for a national
cloud.5
Choose the access type
Public shows every indexed file to all Onyx users. Private limits the connector to selected Onyx groups.Auto Sync Permissions mirrors OneDrive access.
It is available on the Business and Enterprise tiers on Onyx Cloud, and in the Enterprise Edition when self-hosted.
6
Set an indexing start date
Under Advanced Configuration, set an Indexing Start Date unless you need every file.
Onyx indexes files created or changed on or after that date.
See Advanced Configuration.
7
Connect and verify
Select Create Connector. Onyx checks sign-in, user listing, drive access, and change access.
With permission sync, it also checks file permissions and Entra group membership.Open Admin Panel → Existing Connectors, select the connector,
and confirm the first indexing attempt finishes with the expected document count.
Connector settings
Auto Sync Permissions
With Auto Sync Permissions, Onyx grants file access to:- The OneDrive owner
- Users with direct access
- Members of Entra groups with access
- Every Onyx user when the file has an anonymous sharing link
- Every Onyx user when the file has an organization-wide link and Treat organization links as public is on
ONEDRIVE_PERMISSION_DOC_SYNC_FREQUENCY and
ONEDRIVE_PERMISSION_GROUP_SYNC_FREQUENCY, in seconds.
With Sites.Selected, grant the app read access to every personal site in scope.
General scope can discover all users, but it can index only the personal sites granted to the app.
See Limiting the app to specific
sites.