MyQ X Server

Connect to OneDrive for Business

Connect MyQ to OneDrive for Business to make users' OneDrive storage available to supported MyQ workflows.

OneDrive for Business can use the same Microsoft Entra application registration as Microsoft Entra ID and SharePoint Online. You can also use a dedicated application registration.

Before configuring OneDrive for Business, synchronize the users who will use the integration from Microsoft Entra ID. MyQ uses their Microsoft Entra object IDs to associate MyQ users with their OneDrive accounts.

Users created manually or synchronized from sources other than Entra ID will not have access to the OneDrive for Business destination.

Choose the OneDrive access model

MyQ can access OneDrive for Business either using application permissions or on behalf of individual Microsoft users.

Application-wide access

With application-wide access, MyQ can access users' OneDrive storage without requiring each user to authorize the connection.

MyQ pairs each synchronized user with their OneDrive using the user's Microsoft Entra object ID. Automatic setup uses this access model. You can also configure it with a manually registered application.

Use application-wide access when users should be able to use OneDrive through MyQ without individually connecting their Microsoft accounts.

Individual user access

With individual user access, each user authorizes MyQ to access their OneDrive. MyQ then accesses OneDrive on behalf of the signed-in user using delegated Microsoft permissions.

Users connect their OneDrive account from the Cloud Storage widget in the MyQ Web Interface. Use this model when users should explicitly authorize MyQ to access their OneDrive storage.

Add the OneDrive for Business connection

Go to MyQ > Settings > Connections, click Add, and select OneDrive for Business.

Enter a Title for the connection and select:

  • Create automatically

  • Set up manually

OneDrive for Business - Create automatically option

Create the connection automatically

Select Create automatically to let MyQ create and configure the required Microsoft application.

Sign in with a Microsoft administrator account and authorize MyQ to create the connector application. This method silently uses the permissions below during configuration.

Permission

API

Type

Purpose

Application.ReadWrite.All

Microsoft Graph

Delegated

Create or update the connector application credential.

Directory.Read.All

Microsoft Graph

Delegated

Read tenant information, including the default domain name.

Complete the Microsoft authorization process and save the connection.

MyQ configures application-wide access. Users synchronized from Microsoft Entra ID are automatically associated with their OneDrive accounts and do not need to authorize OneDrive individually.

Connect a manually registered application

Select Set up manually if your organization manages Microsoft Entra application registrations directly.

You can use a dedicated application registration or the same application that you use for Microsoft Entra ID and SharePoint Online. The shared application must contain the permissions required by all integrations that use it.

This method requires the permissions below.

Permission

API

Type

Purpose

Group.Read.All

Microsoft Graph

Application

Read groups and group membership.

User.Read.All

Microsoft Graph

Application

Read users.

User.Read

Microsoft Graph

Delegated

Sign in and read the signed-in user's profile.

For the complete registration model, redirect URI, and other Microsoft-side application settings, see Microsoft Entra Application Reference.

Enter the application details in MyQ:

  • Directory (tenant) ID

  • Application (client) ID

  • Security key

Choose how MyQ should access users' OneDrive storage:

  • Enable Application has access to OneDrive for Business of all users to use application-wide access.

  • Leave it disabled to require each user to authorize access to their OneDrive.

Save the connection.

Authorize individual users

This step applies only when application-wide access is disabled.

Each user must connect their OneDrive account from the Cloud Storage widget in the MyQ Web Interface. After authorization, MyQ can access OneDrive on behalf of that user.

Re-authorizing the OneDrive Business connection

The automatic connection to OneDrive Business can be changed after it has been created. By right-clicking on the connection, the Re-authorize option will be available in the context menu.

Reauthorize option

The user will be shown the same dialogue as when the connection was created. The user can repeat all the steps to create a new secret for the existing OneDrive Business connection.

The Re-authorize option also allows you to change the type of connection from automatic to manual, and vice versa.

Next steps

After the OneDrive for Business connection is configured, it can be selected in supported MyQ workflows.