Search anything...
Checking connections

Administration

SharePoint job folder builder

Choose how SharePoint folders should be made when ProductionOps360 creates a job.

Microsoft connection

Link Microsoft Graph so ProductionOps360 can create SharePoint job folders.

Checking connection

Admin setting. Connect with a restricted Microsoft user so ProductionOps360 can only see the SharePoint areas that user can access.

Microsoft setup guide

App registration, redirect URI, and restricted SharePoint access steps.

Show guide

Connection setup

Use these steps once for each customer tenant, then the Connect button handles sign-in.

Open Entra
  1. 1Open Microsoft Entra admin center, then App registrations.
  2. 2Create a new app registration for this ProductionOps360 instance.
  3. 3Copy the Application client ID into Client ID.
  4. 4Copy the Directory tenant ID into Tenant ID.
  5. 5Add a Web redirect URI using the exact Redirect URI below.
  6. 6Create a client secret under Certificates & secrets, then paste the secret value here once.
  7. 7Add Microsoft Graph delegated permissions for User.Read and Sites.ReadWrite.All.
  8. 8Do not worry if offline_access is not listed there; ProductionOps360 requests it in the connection link.
  9. 9Grant admin consent if Microsoft shows the consent warning.
Redirect URI to addSave/load settings to generate the redirect URI.
Tenant IDEntra admin center, Overview, Directory tenant ID.
Client IDApp registration, Overview, Application client ID. This is a GUID, not the secret value.
Client SecretApp registration, Certificates & secrets, new client secret value.
SharePoint URLMicrosoft 365 admin center, SharePoint admin center, Active sites.

Limit what ProductionOps360 can see

This connection uses the permissions of the Microsoft user who clicks Allow. Use a dedicated user and group so ProductionOps360 cannot browse the whole tenant.

  1. 1Create a dedicated Microsoft 365 user for ProductionOps360, such as po360-sharepoint@yourdomain.
  2. 2Create a security group such as ProductionOps360 SharePoint Access.
  3. 3Add only that dedicated user to the security group.
  4. 4In SharePoint, grant that group access only to the site, document library, and folders ProductionOps360 should use.
  5. 5Remove that user or group from broad company-wide SharePoint access and avoid making it a site owner unless absolutely required.
  6. 6Click Connect to SharePoint while signed in as the dedicated user, so the delegated token can only reach the folders that user can reach.

Future app-only access can be locked down even further with selected-site application permissions, but this delegated setup should be restricted through the Microsoft user and SharePoint group.

Location

SiteNot resolved
Library
Documents
Jobs stored in folder
Jobs

Job filing folders

Choose whether new job folders sit directly in the jobs root, or are grouped into year and month folders using the job start date.

Job folder method

Base folder path
Jobs/_Base Job Folder

Current RMS document filing

Choose the folder inside every job’s base structure where generated Current RMS documents belong. The saved path is relative to the job folder, so documents cannot be filed elsewhere in SharePoint.

Destination inside each job folder

Example: JOB-REF - Job Name/Quotes

Preview

Copy Jobs/_Base Job Folder
Paste into Jobs/JOB-REF - Job Name