Skip to content
Agentic Workflowdocs
v0.8.2Install free

use the app / connections

Connect Microsoft 365

Register a Microsoft app once, then sign in to Outlook mail, OneDrive, Calendar and To Do. No client secret is needed.

≈ 6 min Extension OAuth2
  • A Microsoft account (personal, work or school).
  • Access to the Azure portal to register an app (free). Work accounts may need an admin to approve the permissions.
  • The AWFlow browser extension. These steps run in the extension (the web app hands them to it).

This is the only method. Microsoft 365 uses a public client: only the Application (client) ID is stored, never a secret.

  1. Register an app in the Azure portal’s App registrations: New registration, any name, Accounts in any organizational directory and personal Microsoft accounts.

  2. Add the redirect URI as a Single-page application. Copy it from the credential form in AWFlow (step 4 shows where), then click Register.

  3. Add permissions. In API permissions › Add a permission › Microsoft Graph › Delegated permissions, add offline_access, Mail.ReadWrite, Mail.Send, Files.ReadWrite, Calendars.ReadWrite and Tasks.ReadWrite.

  4. Fill the credential in AWFlow. Open Credentials and click Add Credential, then fill the New Credential form. In the browser side panel the form comes in two steps: tap Microsoft 365 in the list, then fill the rest.

    The New Credential dialog with Microsoft 365 picked under Integration App / Service: Name and Description fields, a collapsed Create your Microsoft OAuth client guide, a Client ID field (no Client Secret: Microsoft 365 is a public client) and a Check connection button, disabled until a Client ID is filled, a note that the secret is saved locally and encrypted in this browser, and the Cancel and Create Credential buttons. The New Credential dialog with Microsoft 365 picked under Integration App / Service: Name and Description fields, a collapsed Create your Microsoft OAuth client guide, a Client ID field (no Client Secret: Microsoft 365 is a public client) and a Check connection button, disabled until a Client ID is filled, a note that the secret is saved locally and encrypted in this browser, and the Cancel and Create Credential buttons.

    Numbered areas in the screenshot: 1. Integration App / Service: Microsoft 365; 2. Name; 3. Create your Microsoft OAuth client guide; 4. Client ID; 5. Check connection (sign in); 6. Where the secret is stored (here, locally in this browser); 7. Create Credential.

Operation Delegated permission
Mail · Send Mail.Send
Mail · List, Get, Draft Mail.ReadWrite
File · Upload, List, Get link (OneDrive) Files.ReadWrite
Calendar · Create event, List Calendars.ReadWrite
To Do · Create task, List Tasks.ReadWrite
Stay signed in (refresh token) offline_access
  • AADSTS50011 (redirect URI mismatch). The URI isn’t registered, or it was added as Web instead of Single-page application. Copy it again from the credential form.
  • “Need admin approval”. Your organization lets only admins grant these permissions. Ask an admin to grant consent for the app, or use a personal account.
  • 403 on one operation. A permission is missing in API permissions. Add it, then click Check connection again.
  • The run is blocked in the web app. Microsoft 365 runs through the browser extension. Install the extension and allow Microsoft 365 for this workflow when asked, or run the workflow from the extension. See Extension-only integrations in the web app.
Ask Aria