Skip to main content

Set up the OneDrive MCP server

The OneDrive connector gives AI agents access to each user's OneDrive for Business and to the files other people shared with them, including files in colleagues' OneDrive and in Teams and SharePoint libraries. Agents can search, read (with the text of PDF and Office files), create, rename, move, copy, delete, and share files with named people.

The connector runs as a hosted connector in MintMCP and uses delegated OAuth through your organization's own Microsoft Entra app, so each user signs in with their Microsoft 365 account and every tool call runs with that user's existing permissions on each file. This guide covers registering the Entra app, installing the connector in MintMCP, and limiting it to read-only access.

Prerequisites​

  • A MintMCP admin account
  • Microsoft 365 work or school accounts with a license that includes OneDrive. Personal Microsoft accounts can't connect
  • A Microsoft Entra admin who can register an app and grant admin consent, such as a Global Administrator, Cloud Application Administrator, or Application Administrator

Register a Microsoft Entra app​

Microsoft Entra doesn't support dynamic client registration, so an admin registers an app once and MintMCP uses its client ID and secret for every user's sign-in.

  1. Go to portal.azure.com > Microsoft Entra ID > App registrations. Confirm the directory shown in the account menu is your organization's tenant.

    Azure portal Default Directory blade with Microsoft Entra ID highlighted in the left sidebar and App registrations selected under Manage
  2. Click New registration.

    Azure portal App registrations page with the New registration button highlighted in the top toolbar
  3. Enter a name, for example MintMCP OneDrive.

  4. Under Supported account types, keep the single-tenant option. The current form labels it Single tenant only followed by your directory name; older forms call it Accounts in this organizational directory only.

  5. Under Redirect URI, select Web and enter the callback for your MintMCP region:

    MintMCP regionRedirect URI
    US (app.mintmcp.com)https://app.mintmcp.com/oauth/callback
    EU (eu.mintmcp.com)https://eu.mintmcp.com/oauth/callback

    The install panel in MintMCP shows the callback for your organization. Microsoft compares the redirect URI character by character, so copy it from there.

  6. Click Register.

  7. Go to API permissions > Add a permission > Microsoft Graph > Delegated permissions, and add:

    PermissionWhy
    Files.ReadWrite.AllRead and change the files the user can access, in their own OneDrive and wherever files are shared with them
    openid, email, profileSign the user in
    offline_accessLet MintMCP refresh the token without asking the user to sign in again

    Add only delegated permissions. The connector always acts as the signed-in user, so it needs no application permissions and no Sites.* permission.

  8. Click Grant admin consent for [your organization] and confirm, so users aren't prompted to consent individually and tenants that block user consent still work.

    API permissions page with the Grant admin consent for Default Directory button and the grant admin consent confirmation dialog showing Yes and No
  9. Copy the Application (client) ID and Directory (tenant) ID from the Overview tab. The Object ID is a different value and doesn't work as a client ID.

    App registration Overview tab showing the Essentials panel with Application (client) ID and Directory (tenant) ID
  10. Go to Certificates & secrets > Client secrets > New client secret, enter a description, choose an expiry that matches your credential policy, and click Add.

    Add a client secret panel with a Description and Expires field and the Add button
  11. Copy the secret Value immediately. It's shown once, and the Secret ID column next to it isn't the value MintMCP needs.

    Client secrets table showing a secret with its Value column and copy button

Record the secret's expiry date and owner. When it expires, every user's connection stops refreshing until an admin creates a new secret and updates it in MintMCP.

Add OneDrive to MintMCP​

OneDrive runs as a hosted connector in MintMCP, and the catalog pre-fills the Microsoft endpoints, scopes, and token mapping. Microsoft's endpoints are per tenant, so {tenant-id} in the catalog is a placeholder for your Directory (tenant) ID.

  1. Generate the operation reference key the connector needs to start:

    openssl rand -base64 32

    Microsoft copies files in the background, and for a copy that takes longer than about 10 seconds it returns a progress link that anyone holding it can open without signing in. The connector never hands that link to the agent: it encrypts it with this key, together with the destination folder and the time the copy started, and returns only the encrypted reference, which the agent passes back to get_copy_status. So the link stays out of chats and logs, and the connector only checks progress links it issued itself. A reference only opens with the key that created it, so keep the key the same for the life of the connector and store it with the client secret.

    If you delete and recreate the connector, set the same key on the new one, and the references the agent already holds keep working. A new key also works, but the agent can then no longer follow copies started before the change and is told to look at the destination folder instead.

  2. In MintMCP, go to MCP store > Manage store.

  3. Find OneDrive in the catalog and click Install, then Continue. A setup page appears with the connector configuration.

  4. Set OPERATION_REF_KEY to the key from step 1, with Global scope.

  5. Set Authorization URL to https://login.microsoftonline.com/<tenant-id>/oauth2/v2.0/authorize and Token URL to https://login.microsoftonline.com/<tenant-id>/oauth2/v2.0/token, replacing <tenant-id> with the Directory (tenant) ID from the app's Overview page. Microsoft rejects the sign-in if the placeholder is left in place.

  6. Keep the pre-filled Scopes:

    openid,email,profile,offline_access,https://graph.microsoft.com/Files.ReadWrite.All
  7. Enter the Client ID (the Application (client) ID) and the Client Secret (the secret Value) from the app registration.

  8. Confirm the Redirect URL shown on the setup page matches the Web redirect URI on the app registration (https://app.mintmcp.com/oauth/callback or https://eu.mintmcp.com/oauth/callback). Microsoft compares them character by character.

  9. Save the connector.

Each user signs in with their Microsoft 365 account on first use. With admin consent granted, they see the Microsoft sign-in page and land back in MintMCP without a consent prompt.

Verify the connection​

  1. Open the server in MintMCP and go to the Tools tab to confirm the tools are listed.
  2. Use the Installation tab to connect an MCP client such as Claude or Cursor to the gateway.
  3. Run a small read-only prompt, such as Show my OneDrive storage quota or List the files in the root of my OneDrive, and compare the result with OneDrive in the browser.

Limit OneDrive to read-only access​

Files.ReadWrite.All covers reading and writing, and every tool runs with the user's own permissions on each file. To let users read files but not change or share them, turn off the write tools with tool customization:

  • create_file
  • create_folder
  • update_file
  • delete_file
  • copy_file
  • share_file
  • remove_file_permission

The read tools (get_drive_info, list_folder, search_files, get_file, get_copy_status, list_file_permissions) stay available.

OneDrive behavior and limits​

The connector reaches files through each user's own access, so its answers reflect what that user can see in Microsoft 365.

  • Shared files: there's no list of everything shared with a user, because Microsoft retires the Graph endpoints for "shared with me" and "recent" files. Agents find shared files with search_files across the organization, by a sharing link the user pastes, or by the drive and item IDs from an earlier result. Search depends on Microsoft's index and your tenant's search settings, and it also finds SharePoint and Teams files; for browsing sites and libraries, use the SharePoint connector.
  • Sharing links: get_file opens a link only if the user already has access through it; it never accepts an invitation on the user's behalf, so a user without access opens the link once in the browser first. share_file shares with named people who must sign in, and never creates anonymous links. Sharing with people outside your organization follows your tenant's sharing policy.
  • Permissions: list_file_permissions shows every permission to the item's owner and only the permissions that apply to anyone else. It doesn't show whether a permission comes from a parent folder, and a permission set on a parent folder has to be removed on that folder.
  • Copies: Microsoft copies in the background. When a copy takes longer than about 10 seconds, the agent gets a reference to check its status; the reference is valid for 24 hours and works for anyone who holds it and can open the destination folder.
  • Document reading: the connector reads files up to 10 MB and returns up to 100,000 characters per call, page by page for PDF and Office files, with a way to continue. Scanned pages and images aren't read. When the connector is busy reading other documents it answers that it's busy, and the agent retries shortly. Uploads are limited to 4 MB per file.
  • Accounts: users need a license that includes OneDrive. Guests and users without OneDrive get a clear message, and can still reach files in other drives they have access to.
  • Protected files: files protected by sensitivity labels, rights management, or conditional access return an access error instead of their content.

Security considerations​

  • Every tool call runs as the signed-in user through delegated OAuth, so the connector reaches only the files that user can already access in Microsoft 365, and Microsoft 365 audit logs attribute each action to that user.
  • Files.ReadWrite.All lets each user read and change those files, so turn off the write tools if your organization only needs reading.
  • The client secret and the operation reference key are stored in MintMCP and never reach the MCP client. Rotate the secret in Entra and update it in MintMCP before it expires.
  • share_file never creates anonymous or password links, and recipients always have to sign in.
  • Users can revoke their own consent at myapps.microsoft.com, and admins can review or remove the app under Enterprise applications in the Entra admin center.

Troubleshooting​

SymptomCause and fix
Microsoft error about a redirect URI mismatch (AADSTS50011)The app's Web redirect URI doesn't match MintMCP's callback. Compare it with the callback shown in the install panel, including the region (app versus eu)
Microsoft error that the app isn't multi-tenant or the endpoint is unsupported (AADSTS50194)The URLs still use organizations, common, or the {tenant-id} placeholder. Replace them with the Directory (tenant) ID
The connector doesn't start, or its tools never loadOPERATION_REF_KEY is missing or isn't 32 bytes in base64. Generate a new one with openssl rand -base64 32 and set it on the connector
get_copy_status says a reference is no longer validThe reference is older than 24 hours, or OPERATION_REF_KEY changed after it was issued. Look at the destination folder with list_folder
Invalid client secret (AADSTS7000215)The Secret ID was pasted instead of the Value, or the secret expired. Create a new secret and update the connector
User sees Approval required instead of the sign-in completingAdmin consent wasn't granted and the tenant blocks user consent. Grant admin consent on the app's API permissions page
Tools say the user has no OneDrive it can useThe account has no license that includes OneDrive, isn't allowed a personal site, or is a guest. Assign a license; files in other drives stay reachable meanwhile
A tool says the user isn't authenticatedThe user's token was revoked or can't be refreshed. Have the user reconnect the connector in MintMCP

Next steps​