OneDrive Requirements and Microsoft Entra Application Setup
This article shows how to prepare a Max/All Access Microsoft application for OneDrive, understand Application ID, Client Secret Value, tenant/account-type selection, redirect configuration, and per-connection OAuth isolation.
What you need to know
- OneDrive OAuth uses the Joomla-routed callback, PKCE, encrypted one-time state, tenant normalization, token refresh, and connection/owner binding. Use the Microsoft Client Secret Value, not the Secret ID.
How to do it
- Open Microsoft Entra and create or choose an App registration.
- Choose the supported account audience that matches the users who will authorize the connection.
- Create a Client Secret and immediately copy its Value; Microsoft also shows a Secret ID, but that is not the credential QCSB needs.
- Begin the OneDrive connection in QCSB and copy the exact read-only Authorized redirect URI.
- In the Entra app open Authentication → Add a platform → Web, paste the QCSB URI under Redirect URIs, and save.
- Return to QCSB with the Application (client) ID, Client Secret Value, and tenant/account-type setting.
Verify the result
- Test Connection succeeds.
- The displayed/usable root is exactly the intended root and no parent folder is reachable.
- A normal authorized user can perform only the operations intended for that connection/Workspace role.
Troubleshooting
- If the provider is unreachable, test the connection in Administrator before troubleshooting the Workspace UI.
- Keep passwords, OAuth secrets/tokens, private keys, and unrestricted private paths out of public screenshots and support posts.
Community Discussion
For practical QCSB workflows and discussion with other Joomla site owners, visit the QC Storage Bridge Community. For private support, bug reports, account-specific entitlement issues, or feature requests, use the QuantaCade support system.