Skip to main content
An administrator sets up Microsoft 365 once in OpenWork Cloud. Each member then signs in with their own work account, and their agent uses that account’s permissions.

Before you start

You need administrator access in OpenWork and permission to manage an app registration in your company’s Microsoft Entra tenant. Organization-wide consent also requires an authorized Entra administrator, such as a Cloud Application Administrator or Global Administrator. Azure subscription Owner access alone does not grant that authority. Use your existing company tenant and sign-in configuration. Connecting Microsoft 365 does not require changing your domain federation or SSO setup.

1. Open the connection settings

In OpenWork Cloud, open Manage › Connectors › Microsoft 365 › Settings. If Microsoft 365 is not listed, choose Add connector and select it. Copy the Redirect URI shown by OpenWork. Hosted OpenWork uses:
For a self-hosted deployment, use the address displayed by that deployment.

2. Find or register your Microsoft app

Open the Microsoft Entra admin center, select your company directory, and go to Entra ID › App registrations › All applications. Select your existing OpenWork Microsoft 365 app. For a new setup, choose New registration, name it OpenWork Microsoft 365 Connector, and select Accounts in this organizational directory only. Add the OpenWork callback as a Web redirect URI.
Microsoft Entra application registration form showing the application name, account types, and redirect URI

Microsoft's example registration form. Use your own tenant and the callback shown by OpenWork.

On the app’s Overview page, copy these values: Object ID is a different identifier. Do not use it as the Client ID. See Microsoft’s registration instructions.

3. Create and save a client secret

In the same app registration:
  1. Open Certificates & secrets › Client secrets.
  2. Choose New client secret.
  3. Add a description and select an expiry consistent with your company’s policy.
  4. Choose Add and immediately copy the complete Value.
  5. Return to OpenWork’s Microsoft 365 settings. Enter the tenant ID, client ID, and secret Value. For an existing connection, choose Replace credentials to reveal these fields.
  6. Save the credentials using the button shown by OpenWork.
Copy the secret Value, not its Secret ID. Microsoft only shows the Value immediately after creation. If you leave without saving it, retrieve it from your approved secret manager or create another secret in the same app.
Keep the Value out of screenshots, chat, and support tickets. Record its expiry so you can replace it before it expires. Microsoft’s credential guide explains the available credential options and secret lifetimes.

4. Choose what your agent can do

Under What your AI can do, enable the capabilities your organization needs and choose Save permissions. Draft access requires mailbox read/write permission. It does not enable the separate Send Outlook email option. File permissions that mention “all files” can include shared files the member can access beyond their own drive. Review Microsoft’s permission descriptions before consenting. They can cover more than one OpenWork action. An authorized Entra administrator chooses Sign in on the OpenWork connection and reviews the permissions requested for the exact app. To approve them for the organization, select Consent on behalf of your organisation and Accept. Members still sign in separately. OpenWork uses delegated access through each member’s account. You can review the saved consent in Entra ID › Enterprise apps › your app › Permissions.
Microsoft Entra enterprise application Permissions page with the Grant admin consent action

Microsoft's example of the enterprise application Permissions page. Review your app's actual permissions before approving them.

If you grant consent through App registrations › API permissions, first check that the declared permissions match OpenWork’s enabled features. Approving only the default User.Read permission does not cover mail, calendar, file, or chat access. See Microsoft’s admin consent guide.

6. Connect and test a member account

Each person opens Your Connections › Microsoft 365 › Connect in OpenWork Cloud, selects their company account, and completes sign-in. In the desktop app, use Settings › Library, choose the Connectors filter, and select Sign in for Microsoft 365. Confirm the account shows as connected, then try a read-only request for an enabled service:
Show my upcoming Outlook calendar events for tomorrow. Do not change anything.
A successful calendar read verifies calendar access. Other services can require their own Microsoft 365 license, provisioning, and enabled permissions.

Troubleshooting

Replace an expiring secret

Create another secret in the same app and save its Value through Replace credentials in OpenWork. Test a fresh connection before retiring the old secret, and check whether another service still uses it. Routine secret replacement keeps the same client ID and tenant ID.