Which setup do you need?

Find the row that matches the capabilities you want, then follow only those steps. Details for each step are in Setup steps below. Note that co-authoring has two tiers, basic and full — see Co-authoring: basic vs. full experience below.
If you need... Follow Notes
Microsoft 365 Storage only (no co-authoring) Steps 1–2 No vault permissions enablement needed. Enabling storage cannot be undone — test in a non-production vault first.
Basic co-authoring (fastest setup) Steps 1–2, and check the co-authoring option in step 2 Uses on-demand, session-based permission checks — not the full experience.
Full co-authoring (no session limits) Steps 1–5, and check the co-authoring option in step 2 Permissions are stored permanently in SharePoint Embedded.
Microsoft 365 Copilot and/or Search Steps 1–5 Co-authoring is optional — check the box in step 2 for the full co-authoring experience too.

Prerequisites

  • Global administrator access to Microsoft 365
  • The Microsoft 365 tenant ID
  • The Microsoft 365 SharePoint URL
  • Access to M-Files Manage
  • Vault administrator permissions in M-Files Admin (per-vault configuration — storage and co-authoring)
Important:

Microsoft 365 Storage works without vault permissions enablement, and basic co-authoring does too but only with time-limited, on-demand permission checks.

Vault permissions enablement (steps 3–5) is required for full co-authoring, and for Microsoft 365 Copilot and Microsoft Search to access vault content.

Both enabling Microsoft 365 Storage and enabling vault permissions are one-way actions that cannot be reversed once completed for a vault.

Test in a non-production vault first — see Test before production rollout below.

Overview

Microsoft 365 Storage (SPE) is delivered on a per-vault basis and enables three Microsoft experiences with M-Files content:
  • Native Microsoft co-authoring
  • Microsoft 365 Copilot and Microsoft Search

As of M-Files 26.6, Microsoft 365 Storage, co-authoring, and Copilot/Search can each be enabled independently — co-authoring is optional and not required for Copilot or Search.

Note: (M-Files 26.6+) Microsoft 365 Storage, co-authoring, and Microsoft 365 Copilot and Search can be enabled independently. Co-authoring is optional and not required for Copilot or Search.

Co-authoring: basic vs. full experience

Co-authoring behaves differently depending on whether vault permissions enablement (steps 3–5) has been completed:

  • Co-authoring "basic" (steps 1–2 only): M-Files checks permissions on demand each time a file is opened. The resulting permission grant is valid for 12 hours. If a user leaves a file open in Microsoft Office for longer than that window, they can lose access mid-session, even though co-authoring appeared to start correctly.
  • Co-authoring "full" (steps 1–5 completed): Permissions are stored permanently in SharePoint Embedded, so there is no session timeout. This is the recommended setup for any vault where co-authoring is used regularly.

Setup steps

Steps 1-2: Enable Microsoft 365 Storage:

  1. Set up a Microsoft 365 connection in M-Files Manage.
  2. Enable Microsoft 365 storage for the vault in the M-Files Admin.
    • Optional: check the co-authoring box to also enable basic co-authoring.
Warning: This step cannot be undone.

Enabling Microsoft 365 Storage for a vault cannot be reversed. Once enabled, document files are migrated to SharePoint Embedded (SPE) and M-Files cannot move the vault back to its previous storage.

Validate the configuration in a test or development vault before enabling Microsoft 365 Storage for a production vault. See Test before production rollout below.

If Microsoft 365 Storage or basic co-authoring is all you need, you’re done — skip to Microsoft 365 Storage activation and rollout below.

For full co-authoring without the session timeout, continue to steps 3–5.

Steps 3–5: Enable full permission sync

Complete these steps for the full co-authoring experience (no session timeout), or to allow Microsoft 365 Copilot and/or Microsoft Search to access vault content.

  1. Configure user provisioning with Microsoft Entra ID in M-Files Manage.
    Note: Legacy SCIM provisioning can leave external IDs populated incorrectly. If this happens, you must move to a Microsoft Entra Gallery Application or another SCIM provider before you complete step 3. This action enables the updated SCIM provisioning model, which adds and synchronizes external IDs correctly.

    If you use M-Files authentication for external users, validate your setup before you enable Microsoft Entra ID synchronization. External access scenarios can require additional configuration.

  2. Verify that your users have been provided with the correct external ID from Microsoft Entra ID. Check this in M-Files Admin before continuing to step 5.
  3. Submit a support request in the support portal to enable M-Files vault permissions for SharePoint Embedded. Your trusted person will need to approve the request. You’ll then receive an estimated deployment start date within 48 hours, and a confirmation email once vault permissions are enabled.
Note: Controlling Copilot and Search access separately

If you want full co-authoring but don’t want Copilot or Search accessing vault content, restrict that access separately in your Azure/Entra configuration rather than skipping steps 3–5.

Warning: This step also cannot be undone

Like enabling Microsoft 365 Storage in step 2, enabling vault permissions starts a one-way migration to permanent permission storage in SharePoint Embedded. Once vault permissions are enabled for a vault, this cannot be reversed either.

Validate the configuration in a test or development vault before submitting the support request for a production vault. See Test before production rollout below.

Understanding vault permissions enablement

When vault permissions are enabled, M-Files synchronizes users and permissions permanently into Microsoft 365 Storage. This removes the session-timeout limitation from basic co-authoring and lets Microsoft Search and Microsoft 365 Copilot securely access vault content while respecting M-Files access permissions.

M-Files completes this step as part of a phased rollout. The external ID verification in step 4 and the support request in step 5 let M-Files confirm prerequisites before enabling it for your vault.

Test before production rollout

Both enabling Microsoft 365 Storage (step 2) and enabling vault permissions (step 5) are one-way actions and can’t be reversed. Validate the configuration in a test or development environment before enabling either one for production vaults. This lets administrators confirm access behavior and Microsoft 365 experiences beforehand.

Validating the configuration

After storage is enabled and content migration has started, verify:
  • Users can access documents as expected
  • Basic co-authoring works as expected, if enabled

After vault permissions are enabled, additionally verify:

  • Full co-authoring works with no session timeout
  • Microsoft Search can find M-Files documents
  • Microsoft 365 Copilot can reference M-Files content

Microsoft 365 Storage activation and rollout

M-Files enables Microsoft 365 Storage separately for each vault as part of a phased rollout. Your vault may not have access immediately after configuration is completed and vault permissions are enabled.

Once vault permissions are enabled, M-Files starts to migrate content to Microsoft 365 Storage. After content is migrated, these become available:
  • Native Microsoft 365 co-authoring (full experience, if vault permissions are enabled)
  • Native Microsoft 365 Search
  • Native Microsoft 365 Copilot (requires Microsoft 365 Copilot licenses)
Microsoft 365 Search and Copilot can only access documents after they are migrated to Microsoft 365 Storage.

Using Microsoft 365 native experiences

For more information about the Microsoft 365 experiences available for M-Files, refer to Microsoft documentation: