Use the Microsoft Client Secret Value — Not the Secret ID — in QCSB
This article clarifies the common Microsoft Entra setup mistake: QCSB needs the generated secret Value together with the Application ID; the portal Secret ID is not the credential value.
What you need to know
- OneDrive OAuth uses the Joomla-routed callback, PKCE, encrypted one-time state, tenant normalization, token refresh, and connection/owner binding. Use the Microsoft Client Secret Value, not the Secret ID.
How to do it
- In Microsoft Entra, open the App registration and create or view the app’s client secrets.
- Use the secret Value displayed when the secret is created. Do not paste the Secret ID into QCSB.
- If the Value is no longer available, create a new secret rather than guessing from the ID.
- Paste the new Value into the OneDrive connection, save, then reconnect the Microsoft account and run Test Connection.
- If authorization still fails, verify the redirect URI and tenant/account type separately; a correct secret cannot compensate for a mismatched callback or audience.
Troubleshooting
- Keep passwords, OAuth secrets/tokens, private keys, and unrestricted private paths out of public screenshots and support posts.
Community Discussion
For practical QCSB workflows and discussion with other Joomla site owners, visit the QC Storage Bridge Community. For private support, bug reports, account-specific entitlement issues, or feature requests, use the QuantaCade support system.