Introduction
Connect SharePoint document libraries so their content becomes searchable knowledge in Docebo.
This connector syncs files stored in SharePoint document libraries into Docebo Knowledge, so their content becomes searchable and usable by AI assistants and agents. It only covers files — not site pages, lists, or other site content.
1. Basic information
What content gets synced
| Content type | Status | Note |
|---|---|---|
| Files in document libraries | Synced | |
| Site pages, news posts, and lists | Not synced | Out of scope for this connector — see note below |
| OneNote notebooks | Not synced | |
| Files in the Recycle Bin | Not synced |
What content gets extracted
| Content | Status | Note |
|---|---|---|
| Metadata (title, file path, author, last modified date) | Extracted | Synced for every file, regardless of type or size |
| Body text content | Extracted | Only for supported file types under 50 MB — see below |
| Comments and tracked changes | Not extracted | |
| Version history | Not extracted | |
| Macros and embedded objects | Not extracted |
Supported file types for content extraction
| File type | Extensions |
|---|---|
| Word | .doc, .docx |
| PowerPoint | .ppt, .pptx |
| Tables | .xls, .xlsx, .csv |
| Text | .txt, .md, .json |
Files larger than 50 MB sync with metadata only — their content isn't analyzed.
A separate SharePoint Sites connector, covering site pages and other site content rather than files, is planned. This connector is Files-only.
2. Prerequisites in the source system
Required role
You need one of these Microsoft Entra ID (Azure AD) roles to complete setup:
- Global Administrator, or
- Application Administrator or Cloud Application Administrator, combined with a role that can grant admin consent (e.g. Privileged Role Administrator)
You also need Site Owner or SharePoint Administrator access on every site you want to sync.
Required settings
The document libraries you want to sync must not be protected by a Microsoft Purview sensitivity label or Information Rights Management (IRM) policy that blocks API-based content extraction.
Conditional access policies must not block the app's service principal from reaching Microsoft Graph.
3. Preparation in the source system
Create the app registration
Sign in to the Azure portal, go to Microsoft Entra ID → App registrations → New registration. Name the app (for example, "Docebo Knowledge connector"), keep Supported account types set to single tenant, and set the Redirect URI now — choose Web and enter the callback URL. Doing this at registration saves you a step later. The URL always follows this pattern: https://[YOUR-DOCEBO-PLATFORM-URL]/knowledge/v1/integrations/connections/callback — for example, https://demo.docebosaas.com/knowledge/v1/integrations/connections/callback. Select Register.
Register an application, with the redirect URI already entered.
Assign API permissions
Open the app → API permissions → Add a permission, and add the permissions below from both Microsoft Graph and SharePoint. Once they're all added, select Grant admin consent to approve them in one go.
Microsoft Graph
| Permission | Type | Description |
|---|---|---|
| Files.Read.All | Application | Read files in all site collections |
| Files.Read.All | Delegated | Read all files that user can access |
| Group.Read.All | Application | Read all groups |
| Group.Read.All | Delegated | Read all groups |
| GroupMember.Read.All | Delegated | Read group memberships |
| GroupMember.Read.All | Application | Read all group memberships |
| openid | Delegated | Sign users in |
| Sites.Read.All | Delegated | Read items in all site collections |
| Sites.Read.All | Application | Read items in all site collections |
| User.Read | Delegated | Sign in and read user profile |
| User.Read.All | Delegated | Read all users' full profiles |
| User.Read.All | Application | Read all users' full profiles |
SharePoint
| Permission | Type | Description |
|---|---|---|
| Sites.Read.All | Application | Read items in all site collections |
Configured permissions — Microsoft Graph and SharePoint permissions, all granted.
Add a client secret
Go to Certificates & secrets → New client secret. Give it a description and an expiry, then select Add. Once it's created, copy the value shown in the Value column — not the Secret ID column, which looks similar but won't work for authentication. You won't be able to see the value again once you leave this page.
Client secrets expire on the schedule you set here. If a secret expires and isn't replaced beforehand, the SharePoint connection stops working — set a reminder before the expiry date.
Add a client secret, with a description and expiry set.
Add a certificate
Direct SharePoint API access needs a certificate as well as a secret. Generate a self-signed certificate and private key with OpenSSL:
openssl req -x509 -newkey rsa:2048 -keyout sharepoint-key.pem -out sharepoint-cert.pem -days 180 -nodes -subj "/CN=my-custom-cn"
cat sharepoint-key.pem | pbcopy
You can also use the built-in functionality to have the certificate and private key created for you.
This creates sharepoint-cert.pem (the certificate) and sharepoint-key.pem (the private key), and copies the private key to your clipboard. Go to Certificates & secrets → Certificates → Upload certificate, and upload sharepoint-cert.pem. Once it's uploaded, note the Thumbprint shown in the list — you'll need it in Docebo, along with the private key you just copied.
Certificates tab showing the uploaded certificate and its thumbprint.
4. Required actions in Docebo
| Information to enter | Where to find it |
|---|---|
| Directory (tenant) ID | Azure app registration → Overview |
| SharePoint site URL | Your SharePoint site address, without the https:// prefix or a trailing slash — e.g. yourcompany.sharepoint.com |
| Client ID | Azure app registration → Overview |
| Client secret | Azure app registration → Certificates & secrets → Client secrets — copy the Value column, not the Secret ID, at creation time |
| Certificate thumbprint | Azure app registration → Certificates & secrets → Certificates, after uploading your certificate |
| Private key | The private key file you generated alongside your certificate — keep it somewhere safe, Azure doesn't store or display it again |
Authorizing the connector
- Go to Add-ons and integrations → Knowledge Connectors → Create → SharePoint - Files. This menu is only visible to Superadmins.
- Enter the Directory (tenant) ID and your SharePoint site URL — without the https:// prefix or a trailing slash.
Connect SharePoint - Files, with the Tenant ID and SharePoint URL fields.
- Enter the Client ID, Client secret, Certificate thumbprint, and Private key from your Azure app, then select Connect.
Connect SharePoint - Files, with the Client ID, Client secret, Certificate thumbprint, and Private key fields.
- Grant consent in the Microsoft pop-up.
- On the scope screen, select which sites you want files to be available from, to add to Knowledge collections later, then save your selection.
Scope selection — choosing which sites' files to sync.