Reference
Microsoft
Set up Microsoft OAuth for Office 365, Outlook, OneDrive, and Azure services
Overview
Section titled “Overview”Connect your users to Microsoft for Office 365, Outlook email, OneDrive files, Teams, Calendar, and Azure services.
| Property | Value |
|---|---|
| Provider ID | microsoft |
| Category | Productivity |
| PKCE | Supported |
| Token refresh | Automatic |
| Redirect URI | Shown in Developer Portal |
Step 1: Create a Microsoft OAuth App
Section titled “Step 1: Create a Microsoft OAuth App”Go to App registrations in the Microsoft Entra admin center
Navigate to App registrations in the Microsoft Entra admin center and sign in with your Microsoft account.
Register a new application
Click New registration. Enter an application name and select Accounts in any organizational directory and personal Microsoft accounts.
Configure the redirect URI
Under Authentication, click Add a platform > Web. Add the Alter callback URL from the Developer Portal as the redirect URI.
Create a client secret
Go to Certificates & secrets > New client secret. Set an expiry and copy the Value immediately — it’s only shown once.
Get credentials
Copy the Application (client) ID from the Overview page. The secret you copied is your Client Secret.
Step 2: Add to Alter Vault
Section titled “Step 2: Add to Alter Vault”Open the Developer Portal
Go to portal.alterauth.com and navigate to the application.
Add Microsoft provider
Go to OAuth Providers > Add Provider > Microsoft.
Enter credentials
- Client ID: Paste the application (client) ID
- Client Secret: Paste your client secret Value
Select scopes
Choose the scopes the application needs.
Save
Click Save. The provider is now active.
Available Scopes
Section titled “Available Scopes”| Scope | Description |
|---|---|
openid | Sign in with OpenID Connect |
profile | Access to basic user profile |
email | Access to user email address |
offline_access | Maintain access with a refresh token |
User.Read | Read user profile |
User.ReadWrite | Read and update user profile |
Mail.Read | Read user email messages |
Mail.Send | Send email on behalf of user |
Calendars.Read | Read user calendar events |
Calendars.ReadWrite | Read and create calendar events |
Files.Read | Read user files in OneDrive |
Files.ReadWrite | Read and write user files in OneDrive |
- Always include
offline_accessto receive a refresh token for long-lived access. - Microsoft requires admin consent for certain organizational scopes.
- See the Microsoft OAuth 2.0 documentation for more details.
Policy-cataloged operations
Section titled “Policy-cataloged operations”Alter policy rules can target these attested operations and families for operation-level and parameter-aware controls.
| Operation ID | Families | Method | Provider path |
|---|---|---|---|
me/send-mail | send | POST | /v1.0/me/sendMail |
chats/messages/create | send | POST | /v1.0/chats/{chat-id}/messages |
teams/channel-messages/create | send | POST | /v1.0/teams/{team-id}/channels/{channel-id}/messages |
me/get | read | GET | /v1.0/me |
me/messages/list | read | GET | /v1.0/me/messages |
me/messages/get | read | GET | /v1.0/me/messages/{message-id} |
me/mail-folders/list | read | GET | /v1.0/me/mailFolders |
me/calendars/list | read | GET | /v1.0/me/calendars |
me/calendar-view | read | GET | /v1.0/me/calendarView |
me/events/list | read | GET | /v1.0/me/events |
me/events/create | write | POST | /v1.0/me/events |
me/contacts/list | read | GET | /v1.0/me/contacts |
me/contacts/create | write | POST | /v1.0/me/contacts |
me/chats/list | read | GET | /v1.0/me/chats |
me/joined-teams | read | GET | /v1.0/me/joinedTeams |
teams/channels/list | read | GET | /v1.0/teams/{team-id}/channels |
me/drive/root-children | read | GET | /v1.0/me/drive/root/children |
me/drive/items/download | read | GET | /v1.0/me/drive/items/{item-id}/content |
me/drive/items/upload | write | PUT | /v1.0/me/drive/items/{item-id}/content |
drives/items/get | read | GET | /v1.0/drives/{drive-id}/items/{item-id} |
me/todo/lists | read | GET | /v1.0/me/todo/lists |
me/todo/tasks/list | read | GET | /v1.0/me/todo/lists/{todoTaskList-id}/tasks |
me/todo/tasks/create | write | POST | /v1.0/me/todo/lists/{todoTaskList-id}/tasks |
users/list | read | GET | /v1.0/users |
users/get | read | GET | /v1.0/users/{user-id} |
groups/list | read | GET | /v1.0/groups |
sites/root | read | GET | /v1.0/sites/root |
sites/lists | read | GET | /v1.0/sites/{site-id}/lists |