Cloud Connector: How do I set up Cloud Connector to transfer Microsoft 365 Data into CloudNine Review?
Microsoft 365 & Purview Integration Guide: Cloud Connector Configuration
A downloadable PDF version of this article is available here.
About CloudNine’s Cloud Connector
CloudNine’s Cloud Connector securely transfers Microsoft 365 and Microsoft Purview Email and OneDrive data directly into CloudNine Review. Instead of downloading content and creating manual mail stores (such as PST files), data is transferred and processed seamlessly within CloudNine Review.
To establish this connection, an administrator must register an application within Microsoft Entra ID to grant secure programmatic access to your organization's tenant.
Create the Connection in Microsoft Entra ID
This guide provides a high-level overview of how to register an application in Microsoft Entra ID. Your organization is responsible for determining how to securely connect Microsoft Entra ID—and your data—to third-party applications in accordance with your security and compliance requirements.
Prerequisites & Required Roles
Before beginning the configuration, ensure your account possesses the necessary administrative roles:
- Active Subscriptions: An active Microsoft 365 subscription or Microsoft Purview eDiscovery (Premium) account.
- Microsoft Entra ID Role: Global Administrator, Application Administrator, or Application Developer (required to register the application).
- Microsoft Purview Role: Data Governance Administrator or Compliance Administrator (required to map permissions and view audit logs).
Helpful Links
- Register an Application: The foundational guide for creating an app identity in Entra ID.
- Configure API Permissions: Detailed steps on how to add and authorize permissions for your registered app.
- Add a Redirect URI: Security feature for Microsoft Entra ID authentication is sent to the intended recipient.
- Microsoft Graph Permissions Reference: A complete list of all scopes for emails (Mail.*) and files (Files.*).
- Granting Admin Consent: Instructions for administrators to approve high-privilege permissions tenant-wide.
- Restrict App to Users: Provides information on restricting users that can access the app.
Microsoft Entra ID Application Registration Requirements
To establish the third-party connection, an application must be registered within your Microsoft Entra ID tenant with the following parameters.
Configuration Requirements
- Supported Account Types: Single Tenant only.
- Redirect URI: Must be configured as a Public client/native (mobile/desktop) platform with the URI: http://Localhost:5000.
- Add a Redirect URI (required): The Redirect URI is necessary for the desktop application, CloudNine Discovery Portal and Cloud Connector to send data to CloudNine Review.
- Under Manage, select Authentication.
- Under Platform Configurations, select Add a platform.
- Choose Mobile and desktop applications.
- In the Redirect URI field, enter http://LocalHost:5000.
- Select Configure to complete.
- Add a Redirect URI (required): The Redirect URI is necessary for the desktop application, CloudNine Discovery Portal and Cloud Connector to send data to CloudNine Review.
- Application (client) ID
- Directory (tenant) ID
- Client Secret Value (Note: This value must be copied immediately upon generation as it is permanently obscured once you navigate away from the page).
- Note: When a client secret expires, delete the existing connector, then recreate as a new connector.
Required Permissions
1. Microsoft 365 API Permissions (Microsoft Graph API)
To allow the Cloud Connector to securely access email, calendar, and OneDrive data, the registered application requires the following Microsoft Graph API scopes:
|
API / Permission Name |
Type |
Admin Consent Required |
|
Calendars.Read |
Application |
Yes |
|
Files.Read.All |
Application |
Yes |
|
Mail.Read |
Application |
Yes |
|
User.Read.All |
Delegated |
Yes |
Optional Access Control: Once registered, access can be restricted by enabling "Assignment Required" in the application properties, limiting data exposure only to specified users and groups.
2. Microsoft Purview Permissions (Data Governance & eDiscovery)
To allow interaction with your Purview tenant, the application's Service Principal must be mapped and authorized with compliance and eDiscovery permissions.
Required API Scopes
|
API / Permission Name |
Type |
Admin Consent Required |
|
Microsoft Graph |
||
|
eDiscovery.Read.All |
Delegated |
Yes |
|
eDiscovery.Read.All |
Application |
Yes |
|
Goals-Export.Read.All |
Delegated |
Yes |
|
Microsoft Purview |
||
|
Purview.ApplicationAccess |
Application |
Yes |
|
Microsoft Purview eDiscovery |
||
|
eDiscovery.Download.Read |
Application |
Yes |
|
Office 365 Exchange Online |
||
|
User.Read.All |
Delegated |
Yes |
Compliance Role Group Mapping
The application’s Service Principal must be added directly as a member of one of the following active Role Groups within the Microsoft Purview portal:
- eDiscovery Manager (Required for processing data for review)
- Compliance Administrator
Multiple Connectors can be added to CloudNine Review, allowing your IT administrator to register apps in Microsoft Entra ID to better control user access to specific data. For example, you may wish to have connectors created by location or department.
Configuring Cloud Connector in CloudNine Review
Transferring data to CloudNine Review