Most people treat SharePoint like a fortress with one gate: the Microsoft web UI. But if you want an AI agent, a custom REST client, or any external tool to actually do something inside Office 365 β read files, write files, later maybe emails or Copilot actions β you first have to build it a key. That key is an Entra app registration.
This video is a straight-through walkthrough: open the Microsoft Admin Center, create the app, copy the right IDs, generate a secret, add Graph permissions, and get a global admin to click the magic “consent” button. Once that is done, any AI you plug in can act on SharePoint on behalf of a real user, with logs and limits in place.
Why an app registration is the gateway
Office 365 does not let random scripts knock on the door. Every program that wants to talk to SharePoint, Exchange, Teams, or anything else must identify itself through Entra (formerly Azure AD). The registration gives the app:
- A Tenant ID β which Microsoft 365 tenant it belongs to.
- An Application ID β the appβs username.
- A Client Secret β the appβs password.
- API permissions β the list of things it is allowed to ask for.
- Admin consent β the final organizational yes/no.
Without all five, your agent is just a nicely dressed beggar outside the castle.
The walkthrough, step by step
Open the Microsoft Admin Center. Click the three-dot app launcher, find Admin, or go to More apps β Show all your apps if it is hidden. You need at least SharePoint admin rights; if you do not have them, send this video to whoever does.
Go to Microsoft Entra. Inside the Admin Center, open the left navigation, choose All admin centers, then select Microsoft Entra. Search for “app” and click App registrations.
Create a new registration. Click New registration, give the app a name, and choose Single tenant. Single tenant is correct for a specific client or internal project; multi-tenant is only when you are building something that other organizations will install.
Set the redirect URI. For a REST or web app that uses OAuth, add a redirect URI ending in
/callback. Use a domain you control or a server hostname you trust. If you only need SharePoint Graph access, the URI still has to exist, so pick something real.Copy the IDs. After registration, copy the Tenant ID and Application ID. Treat them like credentials β do not paste them into group chats.
Create a client secret. Go to Certificates and secrets β Client secrets β New client secret. Name it, pick an expiration (the default 24 months is fine for most pilots), and copy the secret value immediately. Microsoft hides it after you leave the page, and someone will have to renew it later.
Add API permissions. Open API permissions β Add a permission β Microsoft Graph β Delegated permissions. For SharePoint files, enable Files.ReadWrite. Also add offline_access so the app can keep a refresh token and run background jobs without nagging the user to log in again.
Grant admin consent. This is the part that terrifies IT. Search for the app by name, open its Enterprise application entry, go to Permissions, and click Grant admin consent for [tenant]. A global admin must authenticate and approve the permissions once. After that, the app can actually do things.
What “delegated” really means
Ariel emphasizes delegated permissions, not application permissions. The difference matters:
- Delegated β the app acts as the logged-in user. It can only do what that user already has permission to do inside SharePoint. Logs show the userβs name. If the user leaves the company, the app loses access.
- Application β the app acts as itself, with its own broad permissions, regardless of who is using it. This is powerful and dangerous, which is why global admins usually say no.
For an agent that reads and edits files on behalf of a person, delegated is almost always the right call.
Why this matters for AI agents
Once the app is registered and consented, you can hand an AI agent the four pieces of information β tenant ID, application ID, client secret, and the user scope β and tell it, “go work on SharePoint.” The agent can list sites, read documents, upload files, or later extend to email and calendar. The setup is the same for every downstream tool; only the permission checkbox changes.
The video also teases a follow-up where Ariel will show the actual code side: how the agent authenticates, handles tokens, and stays within one SharePoint site. The plumbing, however, starts here.
π₯ Roast Corner
Let us be honest: it takes more clicks to register an app in Entra than it takes to set up an entire Linux server. Microsoft has turned “let my script touch a file” into a multi-screen quest through Admin Center, Entra, Enterprise Apps, and a consent dialog that looks like it was designed to scare CIOs.
“Certificates and secrets” sounds like a Bond briefing, but it is really just a password page with a calendar. And the fact that the client secret vanishes if you do not copy it in ten seconds is peak Microsoft passive-aggression. Yes, security matters. No, making users feel like they are defusing a bomb is not good UX.
Then there is admin consent. You build the app, you add the permissions, you test everything locally, and then you hit a wall that only a global admin can move. In a small business of five people buying Office 365 from a reseller, nobody knows who the global admin is. Half the time it is a consultant who set up the tenant years ago and has not logged in since. Good luck.
π€ AI for Humans
Think of an Entra app registration like getting a new employee a key card for the office.
- The Tenant ID is the building address.
- The Application ID is the employee number on the badge.
- The Client Secret is the badge itself β and it expires, so HR has to issue a new one every couple of years.
- The API permissions are the doors the badge is allowed to open.
- Admin consent is the building manager physically walking over and activating the badge.
Delegated permissions mean the badge only works when the actual employee is present. The new hire cannot wander into rooms the employee cannot enter. If the employee quits, the badge stops working. That is exactly what you want when an AI agent connects to company files: it gets power through a person, not instead of one.
The reason this feels bureaucratic is that it is bureaucratic β on purpose. Microsoft is selling to enterprises where “who touched what file when” is a board-level question. The same process protects a one-person startup and a ten-thousand-person bank. The trick is knowing which boxes to check so your agent can get to work without turning your tenant into a free-for-all.
Published 2026-08-12 from the YouTube video by Ariel Rubinstein.

π¬ Comments