M365
Overview
M365 is a web-based system that allows the user to access and share files and information. To integrate CAM with M365, the M365 cloud servers must be configured here. You can add and manage multiple M365 servers, define the group name rules to be applied, and the default metadata mapping. The following instructions describe how to configure M365 and CAM for team building and provisioning through the CAM and CAM Team app.
- 1 Pre-requisites
- 2 Pre-requisite Permissions
- 3 Setting up M365
- 4 CAM App Registrations
- 5 Microsoft Graph Permissions in M365
- 6 Private Channel Permissions
- 7 Service Account Permission - Use Planner in Teams
- 8 Connecting M365 with the CAM Platform
- 9 Default Property Mappings
- 10 Group Name Rules
- 11 Metadata Mapping
- 12 M365 - Add Guest Account
- 13 M365 - User Default Password
- 14 Availability of Sharepoint Sites
- 15 Troubleshooting Teams
- 16 M365 CSV Parameters Page Link
- 17 Related Topics
Pre-requisites
The M365 tenant must be set up with at least a Microsoft Entra ID P1 tier.
The user completing the initial configuration must be an M365 Administrator and have access to the Microsoft Identity Manager portal (Admin centers->Identity from admin.microsoft.com)
The service account that CAM will use should have at least a Microsoft 365 Business Basic license (for Teams, Sharepoint, Planner) and the separate Teams license group if using MS Teams, or a Planner license group if using MS Planner, or Sharepoint license group if using MS Sharepoint.
Pre-requisite Permissions
Service Account/Token User
To create teams in MS Teams, you must have a service account in M365, and this account must have permissions/roles included in the table below that describes the service account permissions and roles.
Service Account Permissions (Roles) | Reason |
Application Administrator | It needs to be assigned to generate the token. Can be removed afterwards. If the token expires or is lost, you will need to re-enable this. Our best practice is to keep this activated. |
Microsoft Team Administrator | For creating and using a team, channel, folder, tab, and planner tab |
User Administrator | This is for user administration in a team for adding or removing users. |
When a team is created, by default, the service account is the team's owner.
Planner User
The delegated / service account user must be a member of the team to create and use the Planner tab in Teams.
To create a team, you must have a team owner. Because of this requirement, you need an additional service account so that you can switch to it to create a planner. An Application Administrator role is not needed for this additional account.
Note: If you plan to create a planner, refer to Step 4: Setting Service Account Permissions for the use of Microsoft Planner in Teams.
Setting up M365
CAM Microsoft Teams app
Read the Teams page for more information on how to install CAM Teams app, required permissions and creating Teams, Channels, OneDrive, OneNote and Planner. Also how to access CAM application from Teams.
Teams and Content Mover
Read the Content Mover page for more information on how to use Content Mover to move or copy or link Teams, Channels, Tabs to a DMS system, and examples.
Teams and Template Editor
To use Template Editor to create Channels, Tabs and Teams, read here for steps.
Note: The job will not show errored if a user is missing from CAM during the Create Team/Tab or Channel process. The job inside will error in the log only.
Availability of Sharepoint Sites
While configuring M365 with CAM, there is now an option to make archived sharepoint sites read-only for Team Members.
In the Teams app, find a team you want to archive.
Click Archive button from the app menu.
The option now displays to Make the team read only if you choose to make it read only for all team members.Click Archive to complete.
Troubleshooting Teams
If you encounter any error while creating a team, check the following to ensure your team is created correctly:
Service Account/Token user and Planner user has the correct permissions. Refer to the Service Account Permissions section to verify and ensure it.
Log into Teams as the Service Account/Token User and/or Planner User and check whether you can create a team. If you are still not able to create a team, liaise with your IT or Security Team and let them check whether you have any internal policies set outside of CAM and MS Azure that are affecting this user.
Teams app has the correct Application and Delegated permissions. Refer to the Microsoft Graph Permissions in M365 section to verify and ensure it.
M365 CSV Parameters Page Link
Office 365 Provisioning Parameters
Related Topics
[M365 (CSV Parameter)] | [M365 Groups] | [M365 Users] | [CAM within M365 Team Apps]