Upgrading your SharePoint and OneDrive connection in Atlassian

 

This article explains the upgrade to Atlassian's Microsoft-verified SharePoint and OneDrive integration and what your organization's admin needs to do.

変更内容について

Atlassian's SharePoint and OneDrive integration is moving to a Microsoft-verified app. This means:

  • Verified by Microsoft: The app has been reviewed and approved by Microsoft, meeting their security and compliance standards.

  • Same functionality: Your team's SharePoint and OneDrive experience in Confluence, Jira, and Rovo remains the same.

  • One-time reconnection: Users will be prompted to reconnect their account. This takes a few seconds.

What admins need to do

Before your users can reconnect, a Microsoft 365 admin in your organization needs to grant admin consent for the Atlassian app.

  1. Select the Grant admin consent button in the in-product prompt you received.

  2. Sign in with your Microsoft 365 admin account.

  3. Review the permissions and select Accept.

That's it. Once consent is granted, your users can reconnect when prompted.

You need one of these Microsoft 365 admin roles:

  • Global Administrator

  • Application Administrator

  • Cloud Application Administrator

If you're not the Microsoft admin

If you're an Atlassian admin but don't have Microsoft 365 admin privileges, you can share the consent request with someone who does using one of three ways:

  1. Share the consent URL from the in-product prompt. In the SharePoint consent prompt, select the copy button to copy the admin consent URL, then share it with your Microsoft 365 admin so they can complete the consent flow. Do not copy the URL from the browser address bar after selecting Grant admin consent; that URL expires and might not work as expected.

  2. Copy the consent URL from the SharePoint connector in Atlassian Administration. Go to Atlassian Administration, open the Connectors tab, and locate the SharePoint connector. On the first page, find the admin consent section, select Copy consent URL, and share the link with your Microsoft 365 admin. You do not need to add the connector.

  3. Share a site-specific consent URL. In Atlassian Administration, go to Apps in the left navigation, select Sites, and open the site where you want to grant consent. Copy the site ID from the site's URL, add it to the consent URL provided here(<https://id.atlassian.com/outboundAuth/start?containerId=5545d3c9-79a8-4ea3-aa8b-4f69ed5ebf05&serviceKey=prod-microsoft-sharepoint-lmc-admin-consent&prompt=consent&contextAri=ari:cloud:platform::site/<siteId>>), and share the resulting URL with your Microsoft 365 admin so they can complete the workflow.

After your Microsoft 365 admin completes the consent flow, users can reconnect to the Atlassian SharePoint integration.

How permissions work

Users only see content they already have access to. Granting admin consent doesn't give Atlassian access to all files in your organization. It authorizes the Atlassian app to act on behalf of each user, meaning:

  • If a user can view a SharePoint site or OneDrive file, they can see it through Atlassian.

  • If a user cannot view a file in SharePoint or OneDrive, they cannot see it through Atlassian either.

Admin consent authorizes the app. It doesn't bypass your organization's SharePoint or OneDrive access controls.

Permissions requested

When you grant admin consent, you're authorizing the Atlassian app to access SharePoint and OneDrive data on behalf of your users. Here's what we request and why:

権限

What it allows

Why it's needed

Sites.Read.All

Read items in SharePoint site collections that the user has access to

Enables Atlassian to display SharePoint sites and folders, power site search in Rovo, and show site context in SmartLinks.

Files.Read.All

Read files in SharePoint and OneDrive that the user has access to

Enables rich link previews (title, thumbnail, last modified), file search in Rovo, and inline file previews in Confluence.

その他の注意事項

  • Read-only: These permissions are read-only. Atlassian can’t modify, delete, or create files in SharePoint or OneDrive.

  • No additional data collection: Granting consent doesn't change what data Atlassian stores. We cache metadata (titles, thumbnails) to display previews. We do not store full file contents.

What happens for your users

After you grant admin consent:

  1. Users can connect to SharePoint and OneDrive apps without any permission issues.

  2. They select the prompt to connect, sign in with their Microsoft account, and they're done.

  3. Their SharePoint and OneDrive links, previews, and search will be available.

If a user sees an error before you grant consent, ask them to wait while you complete the steps above.

よくあるご質問

Why is this change happening?

Microsoft requires apps that request organization-wide permissions to go through a verification process. The verified app provides your organization with stronger security assurances and is required for continued access to SharePoint data.

No. Existing SharePoint and OneDrive links in Confluence pages and Jira issues are preserved. After reconnecting, they'll display as normal.

If your admin doesn’t grant consent, users will be blocked from connecting to the SharePoint app and won’t have the SmartLink experience.

No. Admin consent applies to your entire Microsoft 365 tenant. However, only users who choose to connect SharePoint or OneDrive in Atlassian will use this integration.

You'll need to grant consent again for the new verified app.

You can revoke consent at any time in the Microsoft Entra admin center under Enterprise applications. Search for "Atlassian" and remove the app. Note that revoking consent will disable SharePoint and OneDrive features in Atlassian for all users in your organization.

お困りですか?

さらにヘルプが必要ですか?

アトラシアン コミュニティをご利用ください。