SharePoint Online integration: resolving "document library not found" and "Access denied" errors

Applies to: MetaDefender Managed File Transfer — SPO (SharePoint Online) storage integration

Related: MetaDefender Storage Security™ (for comparison; see Notes) 

Before troubleshooting document library or permission errors, confirm the integration's Environment Type matches your tenant, Azure Commercial or Azure Government. Picking the wrong type causes the connection test to fail earlier, before the integration ever reaches the document library check.  

Summary 

When configuring a SharePoint Online integration in MetaDefender Managed File Transfer, the connection test can fail in two distinct, unrelated ways: 

  • The document library is reported as not found, even though it exists 

  • The credentials connect, but the test fails with "Access denied" while creating the integration's metadata column 

This article covers a prerequisite check (the Environment Type selector) and then explains both causes and how to resolve them. The most commonly missed item is the Sites.Manage.All application permission, which is required for the metadata-column step and is not covered by the usual read/write permissions. 

Prerequisite — confirm the Environment Type 

The SharePoint Online integration setup includes an Environment Type selector with two options: 

  • Azure Commercial (Commercial / GCC) 

  • Azure Government (GCC High / DoD) 

These point to two completely separate Microsoft cloud environments, each with its own sign-in and Microsoft Graph endpoints: the commercial cloud uses login.microsoftonline.com and graph.microsoft.com, while the U.S. Government cloud uses login.microsoftonline.us with graph.microsoft.us for GCC High tenants or dod-graph.microsoft.us for DoD (Department of Defense) tenants. GCC (Government Community Cloud) tenants run on the commercial endpoints, which is why the selector groups them under Azure Commercial. 

Before troubleshooting document library or permission errors, confirm the integration's Environment Type matches your tenant — Azure Commercial or Azure Government. Selecting the wrong type causes the connection test to fail earlier, before the integration ever reaches the document library check, typically with a general connection or authentication error rather than the messages covered in this article. 

Symptoms 

One or more of the following appears during the SharePoint Online connection test. (If the test instead fails with a general connection or authentication error before either message appears, check the Environment Type first — see the prerequisite above.) 

Document library not found: 

Document library 'Documents' not found in https://<tenant>.sharepoint.com/sites/<site> 
Document library 'Shared%20Documents' not found in https://<tenant>.sharepoint.com/sites/<site> 

Access denied while creating the metadata column: 

Pull - Test Failed 
These credentials do not have permission to pull files. Please double-check if 
your credential includes: Sites.Read.All. 
Error: Error creating MFT metadata column: Access denied

Cause 

1. "Document library not found" 

The SharePoint Online integration matches the document library by its display name — the title shown in the SharePoint web interface — not by its internal/URL name. The display name is localized to the site's language, and the value is matched literally (it is not URL-decoded). As a result: 

  • On a non-English site, the default library's display name is the localized term (for example, "Dokumenty" on a Polish-language site), so entering "Documents" fails 

  • Entering the internal/URL form "Shared%20Documents" fails, because the integration searches for a library whose title literally contains "%20" rather than a space 

2. "Access denied" while creating the metadata column 

To track transfers, the integration creates a metadata column in the target library. Creating a column changes the library's structure (its schema); it is not a change to the library's content. 

Application permissions such as Sites.ReadWrite.All and Files.ReadWrite.All grant read and write access to items and files, but they do not grant permission to modify a library's structure. Creating a column therefore fails with "Access denied" even when those content permissions are present, correctly set to Application type, and admin-consented. A management-level permission — Sites.Manage.All — is required for this step. 

The error hint that suggests "Sites.Read.All" is misleading. The operation that fails is a write (creating a column), not a read, so adding read permission does not resolve it. 

Resolution 

Step 1 — Enter the document library name correctly 

Enter the library's display name exactly as it appears in SharePoint for that specific site, in plain text (not URL-encoded): 

  • Use the localized title shown in the SharePoint interface — for example, "Dokumenty" on a Polish-language site 

  • Enter spaces as literal spaces, never as "%20" 

  • For names containing accented or special characters, type them exactly as displayed 

The most reliable method is to copy the name directly from Site Contents on the site, or from the name field returned by the Microsoft Graph /sites/{site-id}/drives endpoint. The match is exact, so a stray space, casing difference, or hidden character is reported as not found. 

Step 2 — Grant the required Microsoft Graph permissions 

On the Microsoft Entra (formerly Azure AD) app registration used by the integration, grant the following application permissions, then grant admin consent: 

Permission 

Type 

Purpose 

Files.ReadWrite.All 

Application 

Pull and push files 

Sites.ReadWrite.All 

Application 

Read and write list items and file metadata 

Sites.Manage.All 

Application 

Create the integration's metadata column (a list-schema change) — required 

Notes on the permissions: 

  • Sites.FullControl.All may be used in place of Sites.Manage.All, as it includes it, but Sites.Manage.All is sufficient and follows the principle of least privilege 

  • Sites.Read.All and Group.ReadWrite.All are not required for this integration step 

  • The integration authenticates app-only (client ID and client secret), so the permissions must be Application type — Delegated permissions of the same name are not used 

Step 3 — Verify the configuration 

Before re-testing, confirm: 

  • The integration's Environment Type matches your tenant's cloud — Azure Commercial or Azure Government (see the prerequisite above) 

  • Each permission's Type column shows "Application," not "Delegated" 

  • Admin consent is granted (the status shows "Granted for <tenant>") 

  • The permissions are on the same app registration whose client ID is configured in the integration 

Then re-run the connection test with the document library set to its correct display name. The metadata column is created and the test passes. 

Background 

Display name vs. internal name, and localization 

Every SharePoint document library has two names: 

  • An internal/URL name that is fixed at creation and never translated — for the default library this is always "Shared Documents" (shown in the URL as /Shared Documents/) 

  • A display name (title) that the SharePoint multilingual interface presents in the site's language — "Documents" in English, "Dokumenty" in Polish, and so on 

The SharePoint Online integration in MetaDefender Managed File Transfer matches on the display name, which is why the correct value depends on the site's language and must be entered as plain text. 

Content permissions vs. management permissions 

Microsoft Graph separates permission to change content from permission to change structure: 

  • Sites.ReadWrite.All and Files.ReadWrite.All — add, edit, and remove items and files 

  • Sites.Manage.All — create and manage lists, columns, and content types 

  • Sites.FullControl.All — full control, including permissions 

Creating a column is a structural (schema) change, so it requires Sites.Manage.All even when the integration already has read/write access to content. 

Notes 

Comparison with MetaDefender Storage Security. The equivalent storage integration in MetaDefender Storage Security resolves the library by its internal/URL name (for example, Shared%20Documents) and then displays the localized title for reference. It is therefore unaffected by the display-name behavior described above, and this difference between the two products is expected. 

Always confirm the exact, current permission requirements against the official MetaDefender Managed File Transfer SharePoint Online integration documentation, as requirements can change between releases. 

References 

  • Microsoft Graph documentation on creating list columns (column creation requires Sites.Manage.All) 

  • MetaDefender Managed File Transfer — SharePoint Online integration documentation (OPSWAT product documentation)