SharePoint and OneDrive¶
mScan files finished documents in your Microsoft 365 — in a OneDrive or in a SharePoint library. This page describes how a folder is connected, what mScan does there, and how you take the access back.
What mScan does in Microsoft 365¶
- mScan writes files — a document's processed PDF, its receipt sheet or its original — into the folder connected for a destination, and into subfolders there as the destination names them.
- A file of the same name already in the folder is replaced — that is how a document filed again replaces its earlier version. You set the file names yourself.
- mScan adds rows to an Excel workbook, e.g. one row per receipt for the expense list. If the workbook or the sheet is missing, mScan creates it, with a bold header row of the column names. mScan writes through Excel itself, so the workbook may be open. It behaves exactly as in eb8-cloud: mScan reads the rows on that sheet, adds the new ones, leaves out duplicates and sorts if set, and writes the sheet anew, with columns as wide as their content. Formulas and your own formatting on that sheet are therefore not kept — calculate on another sheet of the same workbook; mScan leaves other sheets as they are (it only puts them in alphabetical order).
- mScan does not read, search or copy any other content: no other files, no email, no calendars, no contacts. Only while connecting does mScan show the person connecting the names of the sites, libraries and folders they can open themselves, so they can pick the folder.
Connecting a folder¶
This is how you set up a destination in OneDrive or SharePoint without anyone at Earlybyte needing access to your Microsoft 365:
- Earlybyte creates a Microsoft 365 destination in mScan, with the name and email address of the person who should connect the folder. Tell us who that is.
- That person gets a link by email. It works once, for 7 days.
- They open the link and sign in with Microsoft — with their own account or a service account of your company. mScan can then write only where that account can write.
- They choose My OneDrive or a SharePoint site, then the library and the folder (or create one), and click Connect this folder.
- mScan writes a small test file there and removes it again. If that works, the destination is connected — mScan then shows the account, the place and when.
Tip: connect with a service account if the destination should keep working after a person leaves the company.
When Microsoft asks for an administrator's approval¶
Many companies only let their IT approve apps like mScan that store files. Microsoft then shows "Approval required" at sign-in. Your IT approves mScan once for the whole company with this link (it is also in the invitation email):
https://login.microsoftonline.com/organizations/adminconsent?client_id=<mScan's ID>
mScan then appears in Microsoft Entra ID under Enterprise applications, and everyone at your company can connect folders. Your IT can also decide there who may use mScan.
The connection stays¶
mScan keeps the sign-in alive by itself; nobody has to sign in again every few weeks. The connection ends when the account's password is changed, the account is disabled, or mScan's access is withdrawn. Then:
- mScan shows the destination as broken,
- your company's managers get an email, and the person who connected it a new link,
- documents keep being processed; filing them there waits. After reconnecting, file them again with File again on the document's page.
Changing the folder or reconnecting (managers)¶
Your company's managers see every destination under Targets. For a Microsoft 365 destination they can themselves — with the icons on its row (hovering one says what it does):
- Change folder — pick another folder, with the same account and no new sign-in.
- Send a link — send a new link, to the same or another person, e.g. to connect it with a different account.
- Reconnect — connect it again themselves: sign in with Microsoft right there and pick the folder.
- Test — check that mScan can write there.
Creating, renaming and deleting destinations is done by Earlybyte.
SharePoint with a site grant¶
For companies whose IT wants a destination without a personal account, mScan can also sign in as
an application (with a certificate, no password) and use the permission
Sites.Selected:
- Your administrator consents to the application once.
Sites.Selectedalone gives no access to any site. mScan reaches only the SharePoint sites your administrator grants it one by one, explicitly.
Earlybyte sets this up together with your IT. It files documents but not Excel rows: Excel only allows those with a person's sign-in. For rows in SharePoint, connect the folder as above.
What mScan stores for this¶
- For each destination: the place (site or OneDrive, library, folder) and the account that connected it.
- For a connected destination: a Microsoft sign-in (a token), encrypted with your company's key. It is deleted when the destination is deleted or connected again.
- For each filed document: where it was filed and when.
- mScan keeps no copies of other content from your Microsoft 365. Data from Microsoft 365 is used for nothing but filing, not passed on, and not used to train AI models.
More in the privacy statement (German).
Taking the access back¶
- One connected destination: Earlybyte deletes it when you ask — its sign-in goes with it. Or the person who connected it removes mScan at myapps.microsoft.com or in their account settings.
- Entirely: your administrator deletes mScan in Microsoft Entra ID under Enterprise applications.
- A granted site: your administrator removes the grant for that site.
Questions: support@earlybyte.ch.