Upgrading your SharePoint and OneDrive connection in Atlassian
This article explains the upgrade to Atlassian's Microsoft-verified SharePoint and OneDrive integration and what your organization's admin needs to do.
変更内容について
Atlassian's SharePoint and OneDrive integration is moving to a Microsoft-verified app. This means:
Verified by Microsoft: The app has been reviewed and approved by Microsoft, meeting their security and compliance standards.
Same functionality: Your team's SharePoint and OneDrive experience in Confluence, Jira, and Rovo remains the same.
One-time reconnection: Users will be prompted to reconnect their account. This takes a few seconds.
What admins need to do
Before your users can reconnect, a Microsoft 365 admin in your organization needs to grant admin consent for the Atlassian app.
How to grant admin consent
Select the Grant admin consent button in the in-product prompt you received.
Sign in with your Microsoft 365 admin account.
Review the permissions and select Accept.
That's it. Once consent is granted, your users can reconnect when prompted.
Who can grant consent
You need one of these Microsoft 365 admin roles:
Global Administrator
Application Administrator
Cloud Application Administrator
If you're not the Microsoft admin
If you're an Atlassian admin but don't have Microsoft 365 admin privileges, you can share the consent request with someone who does using one of three ways:
Share the consent URL from the in-product prompt. In the SharePoint consent prompt, select the copy button to copy the admin consent URL, then share it with your Microsoft 365 admin so they can complete the consent flow. Do not copy the URL from the browser address bar after selecting Grant admin consent; that URL expires and might not work as expected.
Copy the consent URL from the SharePoint connector in Atlassian Administration. Go to Atlassian Administration, open the Connectors tab, and locate the SharePoint connector. On the first page, find the admin consent section, select Copy consent URL, and share the link with your Microsoft 365 admin. You do not need to add the connector.
Share a site-specific consent URL. In Atlassian Administration, go to Apps in the left navigation, select Sites, and open the site where you want to grant consent. Copy the site ID from the site's URL, add it to the consent URL provided here(
<https://id.atlassian.com/outboundAuth/start?containerId=5545d3c9-79a8-4ea3-aa8b-4f69ed5ebf05&serviceKey=prod-microsoft-sharepoint-lmc-admin-consent&prompt=consent&contextAri=ari:cloud:platform::site/<siteId>>), and share the resulting URL with your Microsoft 365 admin so they can complete the workflow.
After your Microsoft 365 admin completes the consent flow, users can reconnect to the Atlassian SharePoint integration.
How permissions work
Users only see content they already have access to. Granting admin consent doesn't give Atlassian access to all files in your organization. It authorizes the Atlassian app to act on behalf of each user, meaning:
If a user can view a SharePoint site or OneDrive file, they can see it through Atlassian.
If a user cannot view a file in SharePoint or OneDrive, they cannot see it through Atlassian either.
Admin consent authorizes the app. It doesn't bypass your organization's SharePoint or OneDrive access controls.
Permissions requested
When you grant admin consent, you're authorizing the Atlassian app to access SharePoint and OneDrive data on behalf of your users. Here's what we request and why:
権限 | What it allows | Why it's needed |
|---|---|---|
Sites.Read.All | Read items in SharePoint site collections that the user has access to | Enables Atlassian to display SharePoint sites and folders, power site search in Rovo, and show site context in SmartLinks. |
Files.Read.All | Read files in SharePoint and OneDrive that the user has access to | Enables rich link previews (title, thumbnail, last modified), file search in Rovo, and inline file previews in Confluence. |
その他の注意事項
Read-only: These permissions are read-only. Atlassian can’t modify, delete, or create files in SharePoint or OneDrive.
No additional data collection: Granting consent doesn't change what data Atlassian stores. We cache metadata (titles, thumbnails) to display previews. We do not store full file contents.
What happens for your users
After you grant admin consent:
Users can connect to SharePoint and OneDrive apps without any permission issues.
They select the prompt to connect, sign in with their Microsoft account, and they're done.
Their SharePoint and OneDrive links, previews, and search will be available.
If a user sees an error before you grant consent, ask them to wait while you complete the steps above.
よくあるご質問
Why is this change happening?
Microsoft requires apps that request organization-wide permissions to go through a verification process. The verified app provides your organization with stronger security assurances and is required for continued access to SharePoint data.
Will my users lose their SharePoint or OneDrive data or links?
No. Existing SharePoint and OneDrive links in Confluence pages and Jira issues are preserved. After reconnecting, they'll display as normal.
What if I don't grant consent by the cutoff date?
If your admin doesn’t grant consent, users will be blocked from connecting to the SharePoint app and won’t have the SmartLink experience.
Can I grant consent for only some users?
No. Admin consent applies to your entire Microsoft 365 tenant. However, only users who choose to connect SharePoint or OneDrive in Atlassian will use this integration.
What if I previously granted consent for the old app?
You'll need to grant consent again for the new verified app.
How do I revoke consent later?
You can revoke consent at any time in the Microsoft Entra admin center under Enterprise applications. Search for "Atlassian" and remove the app. Note that revoking consent will disable SharePoint and OneDrive features in Atlassian for all users in your organization.
お困りですか?
この内容はお役に立ちましたか?