<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Sharepoint on Sysadmin Tales</title>
    <link>https://blog.ssb-tech.net/tags/sharepoint/</link>
    <description>Recent content in Sharepoint on Sysadmin Tales</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Fri, 02 Oct 2026 21:39:10 -0400</lastBuildDate>
    <atom:link href="https://blog.ssb-tech.net/tags/sharepoint/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Connecting rclone to SharePoint Online</title>
      <link>https://blog.ssb-tech.net/posts/using-rclone-for-sharepoint-online/</link>
      <pubDate>Wed, 19 Mar 2025 15:18:48 -0400</pubDate>
      <guid>https://blog.ssb-tech.net/posts/using-rclone-for-sharepoint-online/</guid>
      <description>&lt;h1 id=&#34;connecting-rclone-to-sharepoint-online&#34;&gt;Connecting rclone to SharePoint Online&lt;/h1&gt;&#xA;&lt;p&gt;I found the &lt;a href=&#34;https://rclone.org/onedrive/&#34;&gt;official instructions&lt;/a&gt; for this extremely difficult to follow, so here&amp;rsquo;s what worked for me, with an Office 365 Business tenant.&lt;/p&gt;&#xA;&lt;p&gt;First you need to create a custom client id. The default client ID will likely end up getting throttled, and the token will expire after an hour or so, causing your operations to stall.&lt;/p&gt;&#xA;&lt;h2 id=&#34;app-registration&#34;&gt;App Registration&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Open &lt;a href=&#34;https://portal.azure.com/#blade/Microsoft_AAD_RegisteredApps/ApplicationsListBlade&#34;&gt;this link&lt;/a&gt; and log in with an administrator account that has privileges to create a new app registration for your tenant.&lt;/li&gt;&#xA;&lt;li&gt;Click &amp;ldquo;New registration&amp;rdquo;&lt;/li&gt;&#xA;&lt;li&gt;Give your app a name, I just called mine &amp;ldquo;rclone&amp;rdquo;.&lt;/li&gt;&#xA;&lt;li&gt;For Supported account types, you want the &amp;ldquo;Accounts in this organizational directory only&amp;rdquo; option.&lt;/li&gt;&#xA;&lt;li&gt;create a redirect URI of type Web. Type (don&amp;rsquo;t copy and paste) this into the URI field. &lt;code&gt;http://localhost:53682/&lt;/code&gt;. Don&amp;rsquo;t miss the trailing slash.&lt;/li&gt;&#xA;&lt;li&gt;Copy and keep the Application (client) ID under the app name for later use.&lt;/li&gt;&#xA;&lt;li&gt;Under manage select Certificates &amp;amp; secrets, click New client secret. Enter a description (can be anything) and set Expires to however long you&amp;rsquo;d like. Copy and keep that secret Value for later use (you won&amp;rsquo;t be able to see this value afterwards).&lt;/li&gt;&#xA;&lt;li&gt;Under Manage select API Permissions. Click &amp;ldquo;add a permission&amp;rdquo; and select Microsoft Graph. You want &amp;ldquo;Application Permissions&amp;rdquo;, not &amp;ldquo;Delegated permissions&amp;rdquo;.&lt;/li&gt;&#xA;&lt;li&gt;Give the API key the following permissions:&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Files.ReadWrite&lt;/li&gt;&#xA;&lt;li&gt;Files.Read.All&lt;/li&gt;&#xA;&lt;li&gt;Files.ReadWrite.All&lt;/li&gt;&#xA;&lt;li&gt;User.Read&lt;/li&gt;&#xA;&lt;li&gt;Sites.Read.All&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;Click the button for &amp;ldquo;Grant Admin consent for &lt;org name&gt;&amp;rdquo;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;h2 id=&#34;create-rclone-remote&#34;&gt;Create rclone remote&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&#xA;&lt;p&gt;&lt;code&gt;rclone config&lt;/code&gt;&lt;/p&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&#xA;&lt;p&gt;Give the remote a name&lt;/p&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&#xA;&lt;p&gt;Select &lt;code&gt;35&lt;/code&gt; for OneDrive.&lt;/p&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&#xA;&lt;p&gt;Enter your client ID and client secret when prompted.&lt;/p&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&#xA;&lt;p&gt;&lt;strong&gt;When you get to the step where it asks you to authenticate in a browser, it will likely fail no matter what you do. This is okay.&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&#xA;&lt;p&gt;Open your &lt;code&gt;rclone.conf&lt;/code&gt; in a text editor. On Linux it&amp;rsquo;s by default in &lt;code&gt;$HOME/.config/rclone&lt;/code&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;code&gt;vim $HOME/rclone/rclone.conf&lt;/code&gt;&lt;/p&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&#xA;&lt;p&gt;In the app registration you created earlier you can find the tenant ID in the overview. You can also find it in the Entra ID admin panel. Save that value.&lt;/p&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&#xA;&lt;p&gt;Add the following lines to your &lt;code&gt;rclone.conf&lt;/code&gt;&lt;/p&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-bash&#34; data-lang=&#34;bash&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;auth_url &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; https://login.microsoftonline.com/YOUR_TENANT_ID/oauth2/v2.0/authorize&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;token_url &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; https://login.microsoftonline.com/YOUR_TENANT_ID/oauth2/v2.0/token&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;tenant &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; YOUR_TENANT_ID&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;client_credentials &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; true&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;h2 id=&#34;getting-the-driveid&#34;&gt;Getting the DriveId&lt;/h2&gt;&#xA;&lt;p&gt;Next, get the DriveID of the SharePoint site that you&amp;rsquo;re trying to create a remote for.&lt;/p&gt;&#xA;&lt;p&gt;We&amp;rsquo;ll be using the Microsoft Graph PowerShell module for this. You&amp;rsquo;ll want to connect to Graph with a user that has admin privileges.&lt;/p&gt;&#xA;&lt;p&gt;The &amp;ldquo;site-name&amp;rdquo; mentioned here is the same one at the end of the SharePoint link, like&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://contoso.sharepoint.com/sites/&#34;&gt;https://contoso.sharepoint.com/sites/&lt;/a&gt;&lt;strong&gt;Accounting&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;So in this case, Accounting would be the site name.&lt;/p&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-ps1&#34; data-lang=&#34;ps1&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;Connect-MgGraph -Scopes &lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;Sites.Read.All&amp;#34;&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;$site = Get-MgSite -Search &lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;Site-name&amp;#34;&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;$drive = Get-MgSiteDrive -SiteId $site.Id&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;$drive | Format-List&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;The last command here will print quite a bit of information - there may be more than one document library associated with a single SharePoint site, especially if you&amp;rsquo;ve enabled Teams for that site.&lt;/p&gt;&#xA;&lt;p&gt;Add this as a line to your configured Sharepoint remote.&lt;/p&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-bash&#34; data-lang=&#34;bash&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;drive_id &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; DRIVE_ID_HERE&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;drive_type &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; documentLibrary&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id=&#34;attempt-reconnection&#34;&gt;Attempt reconnection&lt;/h2&gt;&#xA;&lt;p&gt;Run the following command:&lt;/p&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-bash&#34; data-lang=&#34;bash&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;rclone config reconnect &amp;lt;remotename&amp;gt;:&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;At this point you should be able to follow the steps and get rclone connected.&lt;/p&gt;&#xA;&lt;p&gt;You can verify by running:&lt;/p&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-bash&#34; data-lang=&#34;bash&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;rclone ls &amp;lt;remotename&amp;gt;:&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Don&amp;rsquo;t get me wrong, I&amp;rsquo;m sure there are some unnecessary steps here, but this is what I did, and it works.&lt;/p&gt;&#xA;&lt;p&gt;It will allow you to connect rclone to SharePoint with a custom client ID and avoid it timing out after an hour or so.&lt;/p&gt;&#xA;&lt;p&gt;I used this to migrate 3TB of data from a SharePoint site to a local NAS.&lt;/p&gt;&#xA;&lt;h2 id=&#34;additional-tips&#34;&gt;Additional tips&lt;/h2&gt;&#xA;&lt;p&gt;If you still run into issues with rate limiting, you can look into the &lt;code&gt;--tpslimit&lt;/code&gt;, &lt;code&gt;--transfers&lt;/code&gt; or &lt;code&gt;--checkers&lt;/code&gt; options to limit the number of API calls rclone is making to SharePoint. I wound up using &lt;code&gt;--tpslimit 10&lt;/code&gt;. It copied at a reasonable speed without making Microsoft throttle me down to nothing.&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://rclone.org/&#34;&gt;rclone official website&lt;/a&gt;&lt;/p&gt;&#xA;</description>
    </item>
  </channel>
</rss>
