---
title: "Setting up OneDrive in Microsoft Entra ID"
description: "Register the Microsoft application the OneDrive file picker needs (a multi-tenant Entra ID app with a single-page-application redirect, the implicit grant, and the right Graph permissions), then hand its Client ID to Talkspirit."
category: integrations
section: native-integrations
tags: [admin]
type: Tutorial
lastUpdated: 2026-08-27
locale: en
canonical: https://support.talkspirit.com/en/integrations/set-up-onedrive-in-microsoft-entra
---

# Setting up OneDrive in Microsoft Entra ID


The OneDrive file picker lets members attach files from their OneDrive to Talkspirit items such as task attachments. The file stays in OneDrive, and Talkspirit saves a sharing link to it. Before the picker will open, an administrator registers an application in **Microsoft Entra ID** (formerly Azure Active Directory) and saves its Client ID in Talkspirit. This article covers the Microsoft side. Enabling the picker itself is in [Enabling a cloud file picker](/en/integrations/enable-a-cloud-file-picker).

> **In summary:** create a **multi-tenant** app registration in Entra ID, add a **Single-page application** redirect URI matching the one shown on Talkspirit's OneDrive card exactly, enable both implicit-grant token types, then paste the **Application (client) ID** into Talkspirit's OneDrive card.

> **Role prerequisite:** administrator rights in Talkspirit, plus permission to create app registrations in your organisation's Microsoft Entra ID tenant (or an IT contact who can).

> **Note:** the steps below happen in Microsoft's own portal, whose layout and wording Microsoft changes independently of Talkspirit. Where a name has moved, look for the nearest equivalent.

## Why the picker needs a specific registration

Talkspirit uses Microsoft's OneDrive file-picker SDK. Its sign-in has three hard requirements, and each maps to one setting below:

- It signs in through Microsoft's shared endpoint, so the registration must be **multi-tenant**. A single-tenant registration is rejected with the error `AADSTS50194`, even when everyone uses your own organisation's OneDrive.
- It completes sign-in on a dedicated callback page in your Talkspirit workspace, so that page's URL must be whitelisted as a **Single-page application** redirect URI.
- It uses the OAuth implicit flow, so **both** implicit-grant token types must be enabled.

## Step 1: Create the app registration

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) and open **App registrations**.
2. Click **New registration**.
3. Give it a recognisable name, for example `Talkspirit OneDrive picker`.
4. Under **Supported account types**, choose **Accounts in any organizational directory (Multitenant)**. Choose the multitenant-plus-personal option instead only if members also attach files from personal OneDrive accounts.
5. Leave the redirect URI empty and click **Register**.

> **Security note:** the multi-tenant setting only governs which directories can sign in. The picker uses delegated permissions, so a signed-in member reaches only their own OneDrive files. It exposes nothing else in your tenant.

### Already registered as single tenant?

Open the app registration, go to **Authentication**, and change **Supported account types** to the multi-tenant option. The change takes effect within a few minutes, and the redirect URI and API permissions stay unchanged.

The portal's newer **Authentication (Preview)** experience names the same choice **Multiple Entra ID tenants**, with two variants: **Allow all tenants** (the standard multi-tenant behaviour) and **Allow only certain tenants (Preview)**, which restricts sign-in to listed directories while still satisfying the picker's multi-tenant requirement. That allowlist needs at least one entry, so add your own tenant ID. If sign-in still fails with `AADSTS50194` afterwards, the preview restriction is the likely cause: switch to **Allow all tenants**.

## Step 2: Add the redirect URI (as a single-page application)

1. In Talkspirit, open **Administration → Integrations** and find the **OneDrive** card. It shows the exact redirect URI to register, with a copy button. It ends in `/onedrive-picker.html`, and pointing Microsoft at your workspace root instead silently breaks the picker.
2. In the Entra registration, open **Authentication** and click **Add a platform → Single-page application**.
3. Paste the redirect URI from Talkspirit. It must match exactly on protocol, domain and path.
4. Click **Configure**.

If your workspace answers on more than one domain, add one redirect URI per domain: the picker signs in through whichever domain the member is browsing.

## Step 3: Enable the implicit grant

1. Still on **Authentication**, go to **Implicit grant and hybrid flows**.
2. Tick **both** boxes: **Access tokens** and **ID tokens**.
3. Click **Save**.

If either box is left unticked, sign-in fails with `unsupported_response_type` and the picker window closes without opening.

## Step 4: Grant the Graph permissions (if your tenant requires consent)

The picker requests the delegated Microsoft Graph permissions **User.Read** and **Files.ReadWrite.All**, and asks members to consent on first use. If your organisation blocks user consent, add these under **API permissions** and click **Grant admin consent**, so members are not stopped by a prompt they cannot approve.

## Step 5: Hand the Client ID to Talkspirit

1. Copy the **Application (client) ID** from the registration's **Overview** page.
2. In Talkspirit, paste it into the **Client ID** field of the OneDrive card and save, then switch the card on. The full enable step, with its confirmation, is in [Enabling a cloud file picker](/en/integrations/enable-a-cloud-file-picker).

Members then see a **OneDrive** entry in the **Add file** menu. After a one-time Microsoft sign-in, the OneDrive browser opens and the chosen files attach as links.

## How sharing works

When a member picks a file, OneDrive creates a sharing link for it. Who can open that link is governed by your Microsoft 365 sharing policies, not by Talkspirit: a colleague clicking the attachment still needs access to the file in OneDrive. If attachments should be readable by everyone in the workspace, review your organisation's default sharing-link settings in Microsoft 365.

## Troubleshooting

| Symptom | Likely cause | Fix |
| --- | --- | --- |
| The OneDrive option does not appear in the **Add file** menu | Integration off, or no Client ID saved | On the OneDrive card at **Administration → Integrations**, save a Client ID (the toggle stays greyed out until you do), then switch it on |
| The picker window closes right after sign-in and nothing attaches | Implicit grant not enabled | Tick both **Access tokens** and **ID tokens** under **Authentication → Implicit grant and hybrid flows**, then save |
| Microsoft shows `AADSTS50011` (redirect URI mismatch) | The redirect URI is missing or differs from the registered one | Register the exact URI shown on the OneDrive card (ending `/onedrive-picker.html`) as a **Single-page application** entry |
| Microsoft shows `AADSTS50194` (not multi-tenant) | The app registration is single tenant | Change **Supported account types** to the multi-tenant option under **Authentication** (Step 1), then retry after a few minutes |
| Microsoft shows `unsupported_response_type` | Implicit grant not enabled | Same fix as the closing window: enable both implicit-grant boxes |
| A member cannot sign in with a personal Microsoft account | Supported account types limited to organisational directories | Use organisational accounts, or change the registration to include personal Microsoft accounts |
| Sign-in works but a consent error appears | User consent restricted by tenant policy | Grant admin consent for **User.Read** and **Files.ReadWrite.All** (Step 4) |

## Next steps

- [Enabling a cloud file picker](/en/integrations/enable-a-cloud-file-picker)
- [Talkspirit Drive](/en/collaboration/talkspirit-drive)
