Skip to main content

Set up the indexing connector

This section covers setup requirements, permissions, and configuration specific to the OneDrive indexing connector. For real-time access and read and write tools setup, see the overview.

Before you start

Have these ready before you configure the OneDrive indexing connector, so you don't hit mid-setup delays:

  • Global (tenant) administrator — a Microsoft 365 Global Admin must grant admin consent for all API permissions and configure the SharePoint REST API. This can't be completed with a lower-privileged role.
  • Microsoft 365 parent connector already configured — OneDrive inherits its app registration, client ID, tenant ID, and certificate from the Microsoft 365 parent connector. Complete M365 setup first.
  • API permissions approved in advance — the OneDrive-specific scope (Files.ReadWrite.All) and identity scopes shared with the M365 parent must be granted as application permissions with admin consent. Share the permissions table with your CISO or security team before starting. Files.ReadWrite.All is required only to create webhook subscriptions; Glean never writes to your files.
  • Time to allow — plan for the Azure app configuration and Glean Admin console setup, followed by the initial crawl, which takes hours to days depending on corpus size.

Required permissions

Grant all permissions as application permissions on the shared Microsoft 365 app registration. Indexing doesn't support delegated permissions.

Tell us what you need, and we’ll build the request.

The baseline permissions are always included. Select any extras below and the permission set updates instantly. Then copy it to hand to your IT or security team, so every scope is requested in one pass.

Permissions to request from IT
Microsoft Graph API Application
  • Files.ReadWrite.AllCreates and reauthorizes webhook subscriptions over OneDrive drives so changes appear in near-real-time. No files are written.
  • Sites.FullControl.AllRequired to pick up OneDrive permission changes (advanced features and granular security management); OneDrive drives are SharePoint-backed. Not enforced during setup validation — the connector still functions — but without it permissions can go stale. See the Microsoft Graph delta documentation on scanning permission hierarchies.

What gets indexed

Content typeSupportNotes
Documents — Word, Excel, PowerPoint, PDF, textFullFiles up to 64 MB are downloaded for indexing; up to 16.875 MB of converted text content is indexed. Password-protected files: metadata only.
FoldersFullAll personal folders by default. Scopeable to specific Azure AD groups.
Document metadataFullAuthor, last modified, created date, and permissions.
OneNote — Notebooks and SectionsFullIndexed as folders and documents by default.
OneNote — Pages (body content)Limited betaRequires Notes.Read.All plus OAuth for each user. See OneNote setup.
Images, videos, drawings, code filesMetadata onlyNot downloaded by default. OCR off by default. Contact Support to discuss options.
Files larger than 64 MBMetadata onlyTitle, author, and permissions are indexed; content is not.
Consumer OneDrive (personal Microsoft accounts)Not supportedOneDrive for Business (M365 tenant) only.

Known limitations

  • OneNote page indexing requires consent from each user. The OneNote beta requires each user to individually authenticate their M365 account in Glean. Admin configuration alone is not sufficient.

Setup steps

1

Set up the Microsoft 365 parent connector

Registers the shared Azure app and configures certificate authentication. Required before any child connectors. See the Microsoft 365 setup guide.

2

Grant the required API permissions

Using the app created during Microsoft 365 setup, sign into the Azure portal. Navigate to Microsoft Entra IDManageApp registrations and select the app created for the Microsoft 365 suite.

Click ManageAPI PermissionsAdd a permission, select Microsoft Graph, choose Application permissions, and add Files.ReadWrite.All.

Then click Grant admin consent.

Configure permissions

Grant admin consent

3

Configure OneDrive in the Glean Admin console

In the Glean Admin console, select OneDrive as a child connector under Microsoft 365. Credentials are inherited. Set the crawl scope and save.

To increase full crawl indexing speed, Glean recommends 1–10 additional applications with the same permission settings as the parent app. Repeat the permission setup for each additional app and paste the additional Application (client) ID into the Glean web app. You only need to upload the certificate once in Glean.

Upload keys

4

(Optional) Enable real-time access or read and write tools

Enable additional connection modes after the base connector is running. See real-time access and the Microsoft 365 read and write tools.

Permissions and security

  • Permission propagation. Glean maps document-level permissions from OneDrive one-to-one and strictly enforces search-result visibility from those mappings.
  • Security and compliance. All authentication uses secure OAuth 2.0 flows, requires admin consent, and uses no delegated user privileges for indexing.

Hide Microsoft 365 content with Purview sensitivity labels

Glean can exclude sensitive Microsoft 365 content from search results by integrating with Microsoft Purview sensitivity labels. When you enable this integration, Glean skips indexing SharePoint and OneDrive items that carry the labels you select. Because Glean never indexes these items, they don't appear in results. For more information, see Restrict O365 content via sensitivity labels.