Office 365: SharePoint Online
This section covers the following topics:
Prerequisites
Component | Description |
---|---|
Proxy Agent | Recommended Proxy Agents: • Windows Agent • Linux Agent • FreeBSD Agent |
TCP Allowed Connections | Port 443 |
Configure SharePoint Online
These steps need to be performed on Microsoft SharePoint Online.
Before you can add SharePoint Online as a target, you need to register and configure it for use with DDC. Also, grant the necessary permissions to the SharePoint Add-in to authenticate and access (scan) resources within your SharePoint Online environment.
Register the SharePoint Add-in
To register the SharePoint Add-in:
Log on to SharePoint Online.
Go to the AppRegNew form at
<site collection url>/_layouts/15/AppRegNew.aspx
. For example, https://mycompany.sharepoint.com/_layouts/15/AppRegNew.aspx.In the AppRegNew form, specify the following:
Field Description Client Id Enter a unique lowercase string. For example, 1234abcd-56ef-78gh-90ij-1234clientid
.
Alternatively, you can click Generate to generate a client ID.Client Secret Click Generate to generate a client secret. For example, abcdefghij0123456789klmnopqrst0clientsecret
.Title Enter a descriptive name for the add-in. For example, DDC SPO add-in
.App Domain The hostname of the remote component of the SharePoint Add-in. For example, www.example.com
.
This field is mandatory when registering the SharePoint Add-in. However, this field is not required for scanning the SharePoint Online Targets.Redirect URI The endpoint in the remote application or service to which Azure Access Control service (ACS) sends an authentication code. For example, https://www.example.com/default.aspx
.
This field is mandatory when registering the SharePoint Add-in. However, this field is not required for scanning the SharePoint Online Targets.Click Create. The page reloads and displays the details of the newly registered SharePoint Add-in.
Note down the Client ID and Client Secret Key. These values will be required when configuring a connection for the data store.
Grant Permissions to the SharePoint Add-in
Log on to SharePoint Online as an administrator.
Go to the tenant administration site at
<tenant>-admin.sharepoint.com/_layouts/15/appinv.aspx
. For example, https://mycompany-admin.sharepoint.com/_layouts/15/appinv.aspx.In the App ID field, enter the Client ID of the registered SharePoint Add-in. This is the Client ID you noted down in Register the SharePoint Add-in.
Click Lookup. It should fetch and populate the Title, App Domain, and Redirect URL fields.
In the Permission Request XML field, enter the following permissions:
<AppPermissionRequests AllowAppOnlyPolicy="true"> <AppPermissionRequest Scope="http://sharepoint/content/tenant" Right="FullControl"/> <AppPermissionRequest Scope="http://sharepoint/content/sitecollection" Right="Read"/> <AppPermissionRequest Scope="http://sharepoint/content/sitecollection/web" Right="Read"/> </AppPermissionRequests>
Click Create. A permission consent dialog box is displayed.
Click Trust It to grant permissions to the SharePoint Add-in.
Go to the Site App Permissions page at
<tenant>-admin.sharepoint.com/_layouts/15/appprincipals.aspx?Scope=Web
. For example, https://xyz-admin.sharepoint.com/_layouts/15/appprincipals.aspx?Scope=Web.Under the App Display Name column, look for the registered SharePoint Add-In.
Note down the value of Tenant ID from Application Identifer. This value will be required when configuring SharePoint Online as a Target.
# App Identifier format: i:0i.t|ms.sp.ext|<Client ID>@<Tenant ID> i:0i.t|ms.sp.ext|1234abcd-56ef-78gh-90ij-1234clientid@12345678-abcd-9012-efgh-ijkltenantid
Where:
Client ID =
1234abcd-56ef-78gh-90ij-1234clientid
Tenant ID =
12345678-abcd-9012-efgh-ijkltenantid
Add SharePoint Online Data Store
To add the SharePoint Online data store:
Log on to the CipherTrust Manager GUI.
Open the Data Discovery & Classification application.
Click Data Stores > Data Stores > Add Data Store. The Add Data Store wizard is displayed.
Complete the following steps:
Select Store Type
Under Select Data Store Category, select Cloud.
From Select Cloud Type, select Office 365: Sharepoint Online.
Click Next.
Configure Connection
Specify the credentials of the SharePoint Online domain:
Field Description Domain Name of the SharePoint Online organization. For example, if you access SharePoint Online at https://mycompany.sharepoint.com, then mycompany
is the domain.Client ID Client ID of the registered SharePoint Add-in. For example, 1234abcd-56ef-78gh-90ij-1234clientid
. Refer to Register the SharePoint Add-in for the client ID.Client Secret Key Client Secret key of the registered SharePoint Add-in. For example, abcdefghij0123456789klmnopqrst0clientsecret
. Refer to Register the SharePoint Add-in for the client secret key.Tenant ID Tenant ID of the registered SharePoint Add-in. For example, 12345678-abcd-9012-efgh-ijkltenantid
. Refer to Grant Permissions to the SharePoint Add-in for the tenant ID.(Optional) In the Add Label field, enter a label. You can also remove an existing label.
Note
DDC doesn't support selection of multiple agents for the SharePoint Online data store.
Click Next.
General Info
Specify the following details:
Name: Name for the data store.
Description (Optional): Description for the data store.
Location: Location of the data store. Refer to Managing Branch Locations for details.
Sensitivity Level (Optional): Sensitivity level for the data store. Refer to Sensitivity Levels for details.
Enable Data Store: Whether to enable the newly added data store. Select the check box to enable the data store.
Click Next.
Add Tags & Access Control
(Optional) Grant the
All groups (default)
access for reports. Alternatively, select a group.Click Save.
The data store is added to the Data stores page. If the Ready to Scan column shows Ready, then data store is properly configured.
For more information on tags and access control, expand the section below.
Tags and Access Control
The Add Tags & Access Control screen in the Add Data Store wizard allows you to grant access rights to your data store and add tags. More details below:
ACCESS - select user groups that can access the data store. Access to a data store provides ability to see reports that include scans of that data store. The available options are:
All groups: All groups of users can access the data store through reports. This is the default setting.
Selected group/s: Specified user defined groups can access the data store through reports. When this option is selected, select a group from the drop-down list. This list shows existing user defined groups. The user defined groups must already exist on CipherTrust Manager. If no user defined groups exist, ask the administrator to create a group. If needed, you can select multiple groups. Start typing the name of the desired group and select from the suggested groups.
TAGS - select a tag from the Add Tag drop-down list. Please check the list of prebuilt tags in Predefined Tags.
Tip
New tags can also be added. Start typing a new tag, and click the New: <new_tag> link that appears below the drop-down list.
Add as many tags as needed.
To remove a tag, click the close icon in the tag name.
In the General Info screen of the wizard, specify the name, description, branch location, and sensitivity level for your data store. See "Configuring a Data Store - General Information" for details.
In the Add Tags & Access Control screen of the wizard, grant access rights to your data store and add metadata. See "Configuring a Data Store – Tags and Access Control" for details.
Click Save to create the data store. At any time during the configuration you can click Back to go to any of the previous wizard screens to update the configuration. The newly created data store appears on the Data Stores page. By default, data stores are displayed in alphabetic order by name. Depending on the number of entries per page, you might need to navigate to other pages to view the newly created data store.
Add SharePoint Online Scan
To add a scan for SharePoint Online:
Open the Data Discovery & Classification application.
Click Scans > Add Scan. The Add Scan wizard is displayed.
Complete the following steps:
Refer to Scans for the description of screens of the Add Scan wizard.
General Info
Specify a Name for the scan.
(optional) Add a Description for the scan.
Expand Advanced Configuration and specify advanced configurations such Scan Priority, Memory Usage Limit, and Amount of Data Object Volume. Refer to Advanced Configuration for details.
Click Next.
Select Data Stores
Under Data Store Name, select the desired data store that is Ready for scanning. You can select multiple data stores, if required.
Click Next.
Add Targets
To add a scan target, do one of the following:
Under the Add Target field, specify the correct target path and click Apply.
If no specific target is added, the entire data store will be scanned. Full data store or selected paths will be remediated only if selected.
The following table lists target paths and syntax to specify them with examples.
Target Path to Scan Syntax Example Scan all site collections, sites, lists, list items, folders and files. <Empty_Path> Scan a site collection. Includes all sites, lists, list items, folders, and files for the site collection. <organization>.sharepoint.com/sites/<site_collection> https://example.sharepoint.com/sites/operations Scan a site in a site collection. <organization>.sharepoint.com/sites/<site_collection>/<site> https://example.sharepoint.com/sites/operations/my-site Scan all lists in a site collection. <organization>.sharepoint.com/sites/<site_collection>/:site/:list https://example.sharepoint.com/sites/operations/:site/:list Scan a specific list in a site collection. <organization>.sharepoint.com/sites/<site_collection>/:site/:list/<list> https://example.sharepoint.com/sites/operations/:site/:list/my-list Scan all folders and files in a site collection. <organization>.sharepoint.com/sites/<site_collection>/:site/:file https://example.sharepoint.com/sites/operations/:site/:file Scan a specific folder in a site collection. <organization>.sharepoint.com/sites/<site_collection>/:site/:file/<folder> https://example.sharepoint.com/sites/operations/:site/:file/Shared Documents/documents Scan a specific file in a site collection. <organization>.sharepoint.com/sites/<site_collection>/:site/:file/<file> https://example.sharepoint.com/sites/operations/:site/:file/Shared Documents/my-file.txt Scan a specific file within a folder in a site collection. <organization>.sharepoint.com/sites/<site_collection>/:site/:file/<folder>/<file> https://example.sharepoint.com/sites/operations/:site/:file/Shared Documents/documents/my-file.txt Navigate and add target paths.
Click Browse to navigate target paths from the root level.
Alternatively, provide an initial path in the Add Target Path field and click Browse to navigate targets from that point onward.
In the left pane, select the desired target path.
To view subfolders within the folder hierarchy, select the desired folder and click List.
Click Add Path to add the target path to the right pane. Similarly, add other target paths.
Click Add.
Tip
Either navigate the target paths from the root level (without specifying any path in the Add Target Path field) or make sure you provide the correct path to navigate further locations within it.
Click Next.
Select Profiles
Under Classification Profile Name, select the desired classification profiles to search for in the data store. You can select multiple data stores, if required. Refer to Classification Profiles for details on classification profiles.
Click Next.
Add Filters
This step is optional.
Select the desired filter from the Select Filter drop-down list.
To filter the locations to scan an Office365 SharePoint Online data store, consider the following syntax.
Note
Exclude locations by prefix, suffix, and expression filters support wildcard characters. See Using Wildcard Characters to learn how wildcards work.
Exclude locations by prefix
Excludes search locations and nested locations with paths that begin with a given string. It can be used to exclude entire directory trees. Specify
<string>
.Filter Item Syntax Site collection <organization>.sharepoint.com/sites/<site_collection> Site <organization>.sharepoint.com/sites/<site_collection>/<site> List <organization>.sharepoint.com/sites/<site_collection>/<site>/<list> File <organization>.sharepoint.com/sites/<site_collection>/<site>/<list>/<file> Folder <organization>.sharepoint.com/sites/<site_collection>/<site>/<list>/<folder> Exclude locations by suffix
Excludes search locations and nested locations with paths that end with a given string. Specify
<string>
.Exclude locations by expression
This filter is majorly used with wildcard characters.
Excludes search locations and nested locations that matches the given expression. Specify
<string>
.For example, to exclude locations that contain 'blob' in their path, use expression *blob*.
Filter Item Syntax Site collection <organization>.sharepoint.com/<site_collection>* or *<site_collection>* Site <organization>.sharepoint.com/<site_collection>/<site>* or *<site>* List <organization>.sharepoint.com/<site_collection>/<site>/<list>* or *<list>* File <organization>.sharepoint.com/<site_collection>/<site>/<list>/<file>* or *<file>* Folder <organization>.sharepoint.com/<site_collection>/<site>/<list>/<folder>* or *<folder>* Include locations modified recently
Includes search locations modified within N number of days from the current date, where the value of N ranges from 1 to 99 days. After selecting this filter, specify Days from current date.
Exclude locations greater than file size
Excludes files that are larger than a given file size (in MB). After selecting this filter, specify the file size in MB.
Include locations within modification date
Includes search locations modified within a given range of dates. After selecting this filter, specify Start and End dates.
Click Apply.
Repeat the above steps to apply multiple filters. Click Remove to remove any applied filter.
Click Next.
Schedule Run
Specify the scan run frequency. The two options are:
Manual: This is the default option. Select this option to run the scan manually. Select the Run Now check box to start the scan run after you save the changes.
Scheduled: Select this option to configure the scan to run automatically at the specified time.
Refer to Schedule Scan for more details on scheduling scan runs.
Click Save.
Note
API request default quota for SharePoint Online is 600 per minute. If this limit is exceeded, API request will fail and scan run may encounter different issues.
Deleted SharePoint Online Sites
In SharePoint Online, deleted sites or site collections are retained for 93 days in the site Recycle Bin, unless deleted permanently. However, if you try to scan a deleted site, it will result in following error when attempting to scan them:
The target <targetname> for Data Store Sharepoint Online has not been found
Troubleshooting
While adding the SharePoint Online data store to DDC, you might encounter the following error:
The target for Data Store SharePoint scan for sites does not have access permissions
Cause
This error occurs because the grant app permission
is disabled by default on SharePoint Online.
Solution
For the SharePoint Add-In to work, the DisableCustomAuthenticationApp
setting for the tenants needs to be set to false
, as described below:
Open PowerShell.
Run
Install-Module -Name Microsoft.Online.SharePoint.PowerShell
.Run
$adminUPN="<full email address of a SharePoint administrator account>"
.For example:
$adminUPN="example@democompany.onmicrosoft.com"
Run
$orgName="<name of your Office 365 organization>”
.For example:
$orgName="democompany"
Run
$userCredential = Get-Credential -UserName $adminUPN -Message "<password>"
.For example:
$userCredential = Get-Credential -UserName $adminUPN -Message "demopassword@123"
Run
Connect-SPOService -Url https://$<orgName>-admin.sharepoint.com -Credential $userCredential
.For example:
Connect-SPOService -Url https://$democompany-admin.sharepoint.com -Credential $userCredential
Note
The
Connect-SPOService -Url https://$<orgName>-admin.sharepoint.com -Credential $userCredential
command might return the following error. This error occurs when Multifactor Authentication (MFA) is enabled.Connect-SPOService : Identity Client Runtime Library (IDCRL) did not get a response from the Login server. At line:1 char:1 + Connect-SPOService -Url https://trial8349-admin.sharepoint.com -Crede ... + CategoryInfo : NotSpecified: ([Connect-SPOService], IdcrlException + FullyQualifiedErrorId : Microsoft.SharePoint.Client.IdcrlException,Microsoft.Online.SharePoint.PowerShell.ConnectSPOService
To work around this issue:
Rerun
Connect-SPOService -Url https://$<orgName>-admin.sharepoint.com
(without-Credential $userCredential
). You will be prompted for the Office 365 authentication.Enter the Office 365 credentials.
Run
set-spotenant -DisableCustomAppAuthentication $false
.