Who can do this
Section titled “Who can do this”- Company Admins and Company Owners with access to Settings & Apps, on the Elite plan.
- Setting up the prerequisites in Microsoft Azure usually requires a Microsoft 365 / Azure AD administrator at your firm. If you do not have access to your company’s Azure portal, ask your IT contact to complete the Azure steps and share the four values with you.
What gets connected
Section titled “What gets connected”Once SharePoint is connected through the Documents app, Uku creates per-client folders inside a main folder you choose on a SharePoint site, and syncs files from tasks, emails, and the Client Portal there. The connection uses the Microsoft Graph API with an Azure AD app registration — Uku authenticates as the registered application using a client secret, not as an individual user.
Prerequisites in Microsoft Azure
Section titled “Prerequisites in Microsoft Azure”You will need four values to complete the connection. Three of them come from registering an application in Azure Active Directory; the fourth is the URL of the SharePoint site you want to use.
1. Register an application in Azure AD
Section titled “1. Register an application in Azure AD”- Sign in to the Microsoft Azure portal with an account that has permission to register apps.
- Open Azure Active Directory (now also called Microsoft Entra ID).
- Go to App registrations and click New registration.
- Give the app a name (for example,
Uku Documents) and complete the registration.
2. Copy the Application (client) ID and the Tenant ID
Section titled “2. Copy the Application (client) ID and the Tenant ID”- Open the registered app’s overview.
- Copy Application (client) ID — this is your Client ID in Uku.
- Copy Directory (tenant) ID — this is your Tenant ID in Uku.
3. Create a Client Secret
Section titled “3. Create a Client Secret”- In the app’s left menu, open Certificates & secrets.
- Click New client secret, give it a description and an expiry.
- Copy the Value of the secret immediately — Azure only shows it once. This is your Client secret in Uku.
4. Grant API permissions
Section titled “4. Grant API permissions”- In the app’s left menu, open API permissions.
- Add a permission for Microsoft Graph → Application permissions.
- Add at minimum Sites.Read.All for read-only access. To allow Uku to upload files, create folders, and download files (which is what the Documents app actually does), grant Sites.ReadWrite.All instead.
- Click Grant admin consent for your tenant.
5. Find the Site URL
Section titled “5. Find the Site URL”Open the SharePoint site you want Uku to use and copy the URL from the address bar. It looks like https://yourcompany.sharepoint.com/sites/yoursite.
Connect SharePoint in Uku
Section titled “Connect SharePoint in Uku”Path: Settings & Apps → Documents → Connectors
- Open the Documents app and switch to the Connectors tab. If the Documents app is not active yet, activate it from the Overview tab first.
- In the list of supported services, find SharePoint and click Connect.
- Paste the four values into the Setup your SharePoint connection dialog:
- Site URL — the SharePoint site URL from step 5.
- Client ID — the Application (client) ID.
- Tenant ID — the Directory (tenant) ID.
- Client secret — the secret value you copied in Azure.
- Click Connect. Uku tests the connection. When the details are right, Uku shows Connection successful! When something is wrong, Uku shows an error and saves nothing.
After a successful test, SharePoint shows Active on the Connectors tab. Click Choose folder to pick the Main folder for the client folders, then click Save. The other settings work the same as for every drive. See Connect your document storage for the Connectors tab, and Folder structure templates for the folders themselves.
How documents flow once connected
Section titled “How documents flow once connected”Each client gets the folders your firm designs once as a folder structure template. Uku mirrors them into SharePoint under your chosen Main folder. Files attached to tasks, notes and e-mails are filed into it automatically. Files your clients upload wait in New files, and Uku files them one to two hours later. In a client’s Documents, a file’s menu has Open SharePoint, which opens the file in SharePoint.
Your team browses the result on the client’s Documents tab. See Browse and manage a client’s documents.
Switching providers or disconnecting
Section titled “Switching providers or disconnecting”You can have one drive connected at a time. To switch from SharePoint to another drive, open the Connectors tab, click Disconnect on SharePoint, and click Confirm. Then connect the new drive. Disconnecting deletes nothing in SharePoint. After you disconnect, Uku can no longer open the files stored there, unless Uku keeps a backup copy.
Troubleshooting
Section titled “Troubleshooting”The connection test fails immediately
Section titled “The connection test fails immediately”Check each of the four values:
- Site URL must be a full
https://...sharepoint.com/sites/<name>URL, not just the hostname. - Tenant ID is the Directory (tenant) ID from the Azure AD overview, not the friendly tenant name.
- Client secret is the Value of the secret, not the Secret ID. If you forgot to copy it when it was created, generate a new one in Azure — the value is shown only once.
If all four look correct, verify in Azure that the app registration has Microsoft Graph → Sites.Read.All (or Sites.ReadWrite.All) under Application permissions and that admin consent has been granted for your tenant.
File uploads from tasks or the Client Portal fail
Section titled “File uploads from tasks or the Client Portal fail”Uploads need write access. If you only granted Sites.Read.All, Uku can list folders and confirm the connection but cannot upload. Add Sites.ReadWrite.All in Azure under API permissions, click Grant admin consent, and try again.
The connection worked yesterday and now fails
Section titled “The connection worked yesterday and now fails”Most often the Azure client secret has expired. Uku then shows Storage connection has expired. Open the Azure app registration, go to Certificates & secrets, and create a New client secret. In Uku, click Reconnect and enter the new Client secret. Plan the next rotation before that expiry date.
I cannot find App registrations or grant admin consent
Section titled “I cannot find App registrations or grant admin consent”These actions require Azure AD administrator privileges in your tenant. Most users at a company do not have this by default. Ask your IT or Microsoft 365 administrator to register the app and grant consent, then share the four values with you for the Uku side.
A client has no folder in SharePoint
Section titled “A client has no folder in SharePoint”With Create client folders set to When the first file is added, a client’s folders appear with its first file. Upload one file for that client, or open Maintenance and use Create missing client folders.
The list of folders inside SharePoint is empty in Uku
Section titled “The list of folders inside SharePoint is empty in Uku”Uku reads the default document library (drive) of the SharePoint site you point at. If the site has multiple document libraries and you want a non-default one, contact Uku support — selecting a specific drive is not exposed in the connection dialog.