What you create
You need two files, and both come from the same certificate:- A public certificate (
.cer,.pem, or.crt) that you upload to Entra ID - A
.pfxfile, protected by a password, that you upload to Onyx
Register the application
Open App registrations
Create the registration
Onyx SharePoint Connector.
Leave the supported account types and redirect URI at their defaults. Select Register.Record the two IDs
Create the certificate
Either get a certificate from your organization’s certificate authority, or create a self-signed one.Generate the private key and certificate
Package the private key as a .pfx
Check what you have
.pfx and its password securely..pfx only,
extract the public half for Entra with openssl pkcs12 -in yourcert.pfx -clcerts -nokeys -out yourcert.crt.Upload the public certificate to Entra
Open Certificates & secrets
Upload the certificate
onyx-sharepoint.crt, add a description, and select Add.Grant permissions
The permissions come from two places in the portal, Microsoft Graph and SharePoint. Add them all first, then grant consent once at the end.Add the Microsoft Graph application permissions
Sites.Read.All. The rest are for permission sync.
Add them now if you expect to turn it on later, or come back and add them when you do.Add the SharePoint application permissions
Sites.FullControl.All. It never writes to SharePoint.
If the grant is too broad for your organization,
use Sites.Selected and give the app full control of named sites only.
See Limiting the app to specific
sites.Grant admin consent
User.Read permission. The connector never uses it,
since it signs in as an application rather than as a person. Leave it or remove it, as you prefer.Add the credential to Onyx
Open the SharePoint connector
Create a certificate credential
- Application (client) ID and Directory (tenant) ID, from the app registration Overview page
- Certificate File: upload
onyx-sharepoint.pfx - Certificate Password: the export password you set
Save and continue
Enable permission sync
On the connector form, set the access type to Auto Sync Permissions. Each document then keeps the access it has in SharePoint, and an Onyx user finds it in search only if they can open it in SharePoint.Troubleshooting
Upload a certificate (public key) with one of the following file types
Upload a certificate (public key) with one of the following file types
.pfx to Entra. Upload the .crt, .cer, or .pem instead, and keep the .pfx for Onyx.Failed to load certificate
Failed to load certificate
.pfx, usually because the password is wrong or the file is not a .pfx at all.
Repeat Create the certificate.Unsupported app only token
Unsupported app only token
invalid_client
invalid_client
.pfx and the uploaded public certificate came from different certificates.Indexing worked, then stopped on a fixed date
Indexing worked, then stopped on a fixed date
.pfx and its password.
Delete the expired certificate in Entra once an indexing attempt has succeeded.