Enabling Connect in your Microsoft 365 tenant
Connect stores your clients' files inside your own Microsoft 365 tenant. Before it can do that, a Microsoft 365 administrator needs to approve SuiteFiles once.
Pease note: This article refers to the new Connect (beta) experience in the new SuiteFiles platform. A small number of customers are working with us on the beta release. We'll be notifying all customers when the new Connect experience is more widely available.
In this article
Before getting started
-
Only your organisation's Owner can see the Connect tab in Admin settings.
-
The approval itself has to be made by someone with the Global Administrator or Privileged Role Administrator role in your Microsoft 365 tenant. That's often your IT provider rather than you.
-
This is a one-time step for your whole firm. No one else will be prompted.
What you're approving
Connect keeps each client's files in a dedicated container inside your own Microsoft 365 tenant. Approving SuiteFiles lets us create and manage those containers — and nothing else.
The approval doesn't reach your existing SharePoint sites, OneDrive, Teams or email. No software is installed, and no new app registration is created in your tenant. What is created is an entry under Enterprise applications in Microsoft Entra, which is how the approval is recorded and where you can review or remove it later.
Your files stay in your own tenant and your own geography, under your own retention and compliance policies. Nothing moves into a SuiteFiles tenant.
Who can approve it
Granting this approval requires the Global Administrator or Privileged Role Administrator role in Microsoft 365. Most firms ask their Global Administrator.
Some roles sound as though they'd be enough and aren't — Application Administrator, Cloud Application Administrator and SharePoint Embedded Administrator can't grant it. If an account without the right role tries, Microsoft refuses it, shows a Need admin approval screen, and nothing is enabled at either end. Nothing is left half-done; the right person can simply try again.
Suite Tip: If you're not the Global Administrator yourself, use the Copy Link button on the Connect tab and send the link to whoever is. It's the same link, and they don't need a SuiteFiles account to use it.
How to enable Connect
- Click your user name in the top right corner of the SuiteFiles Web App
- Select Admin settings
- Click the Connect tab
- Click Enable Connect — Microsoft's approval screen opens in a new tab
- Sign in with an account holding the Global Administrator or Privileged Role Administrator role
- Check the application name and review the permissions listed (see below)
- Select Accept
Your browser then returns to SuiteFiles.
Please note: If the person approving doesn't have a SuiteFiles account of their own, they'll land on the SuiteFiles sign-in screen rather than a confirmation message. That's expected — the approval is already recorded by that point and nothing further is needed.
Suite Tip: If you administer several Microsoft 365 tenants, open the link in a private or incognito window and sign in fresh. That's the cleanest way to be certain you're approving for the right organization.
What Microsoft will show you
Microsoft lists six permissions on the approval screen:
| What Microsoft shows | What it's for |
| Access selected file storage containers | Creating and managing the containers that hold Connect's files. Applies only to Connect's own containers |
| Manage file storage container types on behalf of the signed in user | Maintaining the definition of Connect's container type. Connect works only against its own containers, so this isn't used day to day |
|
Manage file storage container type registrations on behalf of the signed in user |
As above, for the registration of that container type |
|
Sign in and read user profile |
Reading the name and email of whoever is signed in |
|
Access selected file storage containers |
Listed twice by Microsoft — see below |
|
Access selected file storage container type registrations |
Registering Connect's container type in your tenant, so those containers can exist |
Why is "Access selected file storage containers" listed twice? Microsoft shows the same friendly name for two separate entries, so it reads as a duplicate. Only one of the two is used by Connect.
Why does Microsoft say the application is unverified? You'll see the line "This application is not published by Microsoft or your organization." That's about our enrolment in Microsoft's publisher verification programme, not about this request. You can confirm the application independently: select Show details on the approval screen to see the application ID, which should read d189a91e-fb45-4a9b-9dcf-582f8e477fd2, with suitefiles.com as the homepage. Both are also visible under Enterprise applications after approval.
Checking the approval afterwards
You can confirm the approval in either place:
- Microsoft Entra admin centre → Enterprise applications — a SuiteFiles Connect entry appears, with application ID
d189a91e-fb45-4a9b-9dcf-582f8e477fd2and homepagesuitefiles.com - SharePoint admin centre → SharePoint Embedded → Apps → Installed apps — the same application ID appears
Common questions
Is there a cost? No. SuiteFiles pays for the storage Connect uses. You don't need an Azure subscription, Microsoft doesn't charge you for it, and it doesn't draw on your SharePoint storage entitlement or need extra licences.
Where do our files live? In your own Microsoft 365 tenant, in SharePoint Embedded containers, in your own geography. When you accept a document a client has sent, it moves out of the Connect container into your normal SuiteFiles storage, where your usual permissions apply.
Can SuiteFiles see the rest of our SharePoint? No. The approval is scoped to Connect's own containers.
Can we remove the approval later? Yes. Delete the SuiteFiles Connect entry under Enterprise applications in Entra, or remove its permissions. Connect stops working from that point. Documents you've already accepted have been filed into your normal SuiteFiles storage and are unaffected, but anything still sitting in an open Connect request would no longer be reachable — so it's worth closing out active requests first.
What if we'd rather not? Connect stays switched off for your firm and nothing else changes. The rest of SuiteFiles is unaffected.
If it doesn't work
"Need admin approval" — the account used doesn't hold the Global Administrator or Privileged Role Administrator role. Nothing has been enabled; ask someone with one of those roles to use the link instead.
The approval screen doesn't open — check that pop-ups are allowed for your SuiteFiles site, and that you aren't in a browser window that blocks them.
You're signed in to a different organization — sign out, or open the link in a private window and sign in with the right account.
Still stuck? Contact our support team at support@suitefiles.com.