Skip to main content
The OneDrive connector indexes files from users’ OneDrive for Business accounts in your Microsoft 365 tenant. It preserves the folder hierarchy, reads changes after the first run, and can mirror each file’s access with Auto Sync Permissions. The connector signs in as an app registration set up in Microsoft 365 Setup.

How it works

Before you begin

You need a Microsoft 365 tenant with OneDrive for Business and the roles listed in Microsoft 365 Setup. Each user must open OneDrive once before Microsoft provisions their personal drive. Personal Microsoft accounts are not supported. Complete Microsoft 365 Setup with the OneDrive rows of its permission table. Both client secret and certificate credentials support indexing and permission sync.

Configure Onyx

1

Open the OneDrive connector

In Onyx, go to Admin Panel → Add Connector and select OneDrive.
2

Select or create a credential

Select an existing OneDrive credential or create one as described in Microsoft 365 Setup.
3

Choose the users

Give the connector a descriptive name.Select General to index every enabled, non-guest user with a user principal name. Select Specific to list user principal names or primary email addresses.
4

Adjust the advanced settings

Under Advanced Options, add glob patterns to Excluded Paths if needed. For example, *.tmp skips that file type at every depth, and Archive/* skips files under that path.Change Authority Host and Graph API Host only for a national cloud.
5

Choose the access type

Public shows every indexed file to all Onyx users. Private limits the connector to selected Onyx groups.Auto Sync Permissions mirrors OneDrive access. It is available on the Business and Enterprise tiers on Onyx Cloud, and in the Enterprise Edition when self-hosted.
6

Set an indexing start date

Under Advanced Configuration, set an Indexing Start Date unless you need every file. Onyx indexes files created or changed on or after that date. See Advanced Configuration.
7

Connect and verify

Select Create Connector. Onyx checks sign-in, user listing, drive access, and change access. With permission sync, it also checks file permissions and Entra group membership.Open Admin Panel → Existing Connectors, select the connector, and confirm the first indexing attempt finishes with the expected document count.

Connector settings

Auto Sync Permissions

With Auto Sync Permissions, Onyx grants file access to:
  • The OneDrive owner
  • Users with direct access
  • Members of Entra groups with access
  • Every Onyx user when the file has an anonymous sharing link
  • Every Onyx user when the file has an organization-wide link and Treat organization links as public is on
A Microsoft 365 email address or user principal name must match the user’s email in Onyx. Onyx expands nested Entra groups. Grant Member.Read.Hidden if your tenant uses groups with hidden membership. The document sync runs every 30 minutes. The group sync runs every 5 minutes. Self-hosted deployments can change the intervals with ONEDRIVE_PERMISSION_DOC_SYNC_FREQUENCY and ONEDRIVE_PERMISSION_GROUP_SYNC_FREQUENCY, in seconds. With Sites.Selected, grant the app read access to every personal site in scope. General scope can discover all users, but it can index only the personal sites granted to the app. See Limiting the app to specific sites.

Limits

SharePoint overlap

A personal OneDrive is backed by a SharePoint personal site. If both connectors index the same file, Onyx keeps one document with both source types when Microsoft Graph returns the same drive item ID. Avoid listing personal-site URLs in a new SharePoint connector unless you need this overlap. Microsoft can assign different item IDs to copies in different drives, and Onyx indexes those copies separately.

Troubleshooting

See Microsoft 365 Setup for credential, consent, certificate, and national-cloud problems.