# Sharepoint online connector content source - 403 after few days of connecting and validating

**URL:** <https://discuss.elastic.co/t/sharepoint-online-connector-content-source-403-after-few-days-of-connecting-and-validating/328287>\
**Category:** Elastic Search\
**Tags:** elastic-workplace-search\
**Created:** [March 22, 2023, 6:39pm UTC](https://discuss.elastic.co/t/sharepoint-online-connector-content-source-403-after-few-days-of-connecting-and-validating/328287 "2023-03-22T18:39:11Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![amolpathak224](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/amolpathak224/32/118493_2.png) [@amolpathak224](https://discuss.elastic.co/u/amolpathak224)\
**Post date:** [March 22, 2023, 6:39pm UTC](https://discuss.elastic.co/t/sharepoint-online-connector-content-source-403-after-few-days-of-connecting-and-validating/328287/1 "2023-03-22T18:39:11Z")

</div>

I am using Elasticsearch 8.6 and have used Sharepoint enterprise source to connect our organization sharepoint online instance.  
I was able to successfully connect and sync the contents of the desired sites using the Azure AD admin. However, after 3 days, the incremental and deletion syncs started failing with the following error in enterprise-search/app-server.log  
##################################################  
/usr/share/enterprise-search/lib/war/connectors/lib/connectors/content\_sources/office365/custom\_client.class:265:in `raise\_any\_errors': got a 403 from [https://graph.microsoft.com/v1.0/groups/338e4b86-7cfa-493a-993e-fa3132c1fa21/sites/root](https://graph.microsoft.com/v1.0/groups/338e4b86-7cfa-493a-993e-fa3132c1fa21/sites/root) with query {:$select=\>"id,name"}  
##################################################  
This error is coming now on all the sync requests. Please note that this same account and permissions as described in the document "[Connecting SharePoint Online | Workplace Search Guide [8.6] | Elastic](https://www.elastic.co/guide/en/workplace-search/8.6/workplace-search-sharepoint-online-connector.html)" were configured but later this error starts happening. Could someone please help in this issue? I can provide the logs as needed,

Thanks,  
Amol

---

<div class="post-metadata">

**Author:** ![Sean\_Story](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sean_story/32/69987_2.png) [@Sean\_Story](https://discuss.elastic.co/u/Sean_Story)\
**Post date:** [March 27, 2023, 1:41pm UTC](https://discuss.elastic.co/t/sharepoint-online-connector-content-source-403-after-few-days-of-connecting-and-validating/328287/2 "2023-03-27T13:41:45Z")

</div>

Hi @amolpathak224 ,

Is there any chance that your configured credentials for the connector have expired or were revoked? Using the same credentials and the same user, do you also get a 403 when making the same request through the [Graph API Explorer](https://developer.microsoft.com/en-us/graph/graph-explorer)?

---

<div class="post-metadata">

**Author:** ![amolpathak224](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/amolpathak224/32/118493_2.png) [@amolpathak224](https://discuss.elastic.co/u/amolpathak224)\
**Post date:** [March 28, 2023, 7:36am UTC](https://discuss.elastic.co/t/sharepoint-online-connector-content-source-403-after-few-days-of-connecting-and-validating/328287/3 "2023-03-28T07:36:57Z")

</div>

Thanks @Sean_Story Sean for your reply, it seems that there was some issue with O365 credentials temporarily which was disallowing the user login. After 2 days it automatically started to work, it seems some issue with our enterprise O365 login. Thank you again!

---

<div class="post-metadata">

**Author:** ![amolpathak224](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/amolpathak224/32/118493_2.png) [@amolpathak224](https://discuss.elastic.co/u/amolpathak224)\
**Post date:** [April 19, 2023, 2:52pm UTC](https://discuss.elastic.co/t/sharepoint-online-connector-content-source-403-after-few-days-of-connecting-and-validating/328287/4 "2023-04-19T14:52:36Z")

</div>

Hello @Sean_Story ,  
I copied this ELK instance machine and moved the image to the instance to production, as is. After making the relevant IP related changes, the applications were up and everything is working fine. However, after moving the Sharepoint Connector stopped working. I have updated the redirect URI in the Azure AD and changed the respective content details. Still after connecting the Sharepoint connector fails with  
#######################################  
Error after less than 5 seconds  
Updated 0 items  
Failure caused by: Connectors::ContentSources::Office365::CustomClient::ClientError: got a 403 from [https://graph.microsoft.com/v1.0/sites/](https://graph.microsoft.com/v1.0/sites/) with query {:$select=\>"id,name", :search=\>"", :top=\>10}  
########################################  
All required accesses are given from Azure App, and also one more thing noticeable in enterprise-search logs  
########################################  
ce365/custom\_client.class:265:in `raise_any_errors': got a 403 from https://graph.microsoft.com/v1.0/me with query (Connectors::ContentSources::Office365::CustomClient::ClientError) from /usr/share/enterprise-search/lib/war/gems/gems/actionpack-5.2.8.1/lib/action_controller/metal/mime_responds.rb:203:in `respond\_to'  
from /usr/share/enterprise-search/lib/war/gems/gems/actionpack-5.2.8.1/lib/action\_controller/metal/basic\_implicit\_render.rb:6:in `send_action' from /usr/share/enterprise-search/lib/war/gems/gems/actionpack-5.2.8.1/lib/action_controller/metal/rendering.rb:30:in `process\_action'  
from /usr/share/enterprise-search/lib/war/gems/gems/actionpack-5.2.8.1/lib/action\_controller/metal/rescue.rb:22:in `process_action' from /usr/share/enterprise-search/lib/war/gems/gems/actionpack-5.2.8.1/lib/action_controller/metal/instrumentation.rb:34:in `block in process\_action'  
from /usr/share/enterprise-search/lib/war/gems/gems/actionpack-5.2.8.1/lib/action\_controller/metal/instrumentation.rb:32:in `process\_action'  
########################################################

Due to this the error, the Configuration section in sharepoint connector is also not coming up it seems, which was visible in the older setup.

---

<div class="post-metadata">

**Author:** ![Sean\_Story](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sean_story/32/69987_2.png) [@Sean\_Story](https://discuss.elastic.co/u/Sean_Story)\
**Post date:** [April 19, 2023, 6:15pm UTC](https://discuss.elastic.co/t/sharepoint-online-connector-content-source-403-after-few-days-of-connecting-and-validating/328287/5 "2023-04-19T18:15:17Z")

</div>

> [@amolpathak224](#):
>
> I copied this ELK instance machine and moved the image to the instance to production

How did you do this?

We've seen similar issues before if you use a Snapshot/Restore, but do not keep the exact same `secret_management.encryption_keys` (configured in your enterprise-search.yml).

Because Enterprise Search encrypts your OAuth ClientId and ClientSecret, if you change the underling encryption key, those values become "garbage", and then you can't go through the OAuth flow to authenticate or refresh your token. Our UIs also sometimes fail, because they expect an object in a payload, but get a string due to the bad decryption.

---

<div class="post-metadata">

**Author:** ![amolpathak224](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/amolpathak224/32/118493_2.png) [@amolpathak224](https://discuss.elastic.co/u/amolpathak224)\
**Post date:** [April 19, 2023, 6:40pm UTC](https://discuss.elastic.co/t/sharepoint-online-connector-content-source-403-after-few-days-of-connecting-and-validating/328287/6 "2023-04-19T18:40:10Z")

</div>

We copied the VM image and moved it a new cluster in prod. So all the config, indices remained same. Once the image is copied, I changed all the config files for IP address and URL changes and after that started ELK services and enterprise-search. Everything worked fine, except the sharepoint connector. I removed the source, thereby the index also got deleted and tried reconnecting it using the same admin user of Azure but no luck. Still it's seeing 403 issues on all the URIs.  
Is it possible to check if the Elastic is receiving the token from Azure on redirect URI? I can't find any relevant failure in logs except this 403 error. The encryption key is same as the older machine.  
Thanks

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 17, 2023, 6:40pm UTC](https://discuss.elastic.co/t/sharepoint-online-connector-content-source-403-after-few-days-of-connecting-and-validating/328287/7 "2023-05-17T18:40:37Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
