Microsoft 365 change notifications allow Microsoft to inform Foldr as soon as a file is added, renamed, edited or deleted directly in OneDrive, SharePoint or Teams, so that Foldr reflects the change without waiting for a user to refresh or for the next scheduled crawl.
Without change notifications, a file uploaded through the Microsoft 365 web interface will not appear in an open folder view in Foldr until the user navigates away and back, and will not appear in search results until the share is next crawled.
This article assumes Microsoft 365 is already connected to Foldr, either through the Foldr Cloud integration or its self-hosted appliance equivalent. The feature itself works identically on both, and the only real difference is the network requirements below, which Foldr Cloud meets for you.
What change notifications provide
- Folder views update automatically. Files added, renamed or deleted directly in Microsoft 365 appear in the Foldr web app without user interaction.
- Search results stay current. Where the share has Index deltas enabled (on the share’s Search tab), a change in Microsoft 365 also updates the search index, without waiting for the next scheduled crawl.
Change notifications do not alter how files are stored or which users can access them. Existing permissions continue to apply.
Requirements
Application permissions
Change notifications are requested from Microsoft by the registered application itself, not by an individual user account. Microsoft does not issue notifications on behalf of a signed-in user, so Application permissions are required in addition to any delegated permissions already configured.
This applies to both linking modes. Deployments using manual (per-user) account linking have delegated permissions only by default, and change notifications will not function until application permissions are added.
In the Microsoft Azure portal, open the app registration used by Foldr, then go to API permissions > Add a permission > Microsoft Graph > Application permissions and add:
Files.Read.AllGroup.Read.All(only required if presenting Teams storage)
Click Grant admin consent and confirm.
Deployments using automatic (service account) linking already have Files.ReadWrite.All and, where Teams is presented, Group.Read.All as application permissions. No further permissions are required in that case.
On Foldr Cloud, the application permissions in the setup article cover this already (Files.ReadWrite.All, plus Group.Read.All where Teams is presented), so there is usually nothing to add. It is still worth confirming admin consent was granted, because a missing consent produces no visible error anywhere.
Network requirements (self-hosted appliances)
Foldr Cloud tenants can skip this section. Your Foldr is already published on a public address with a certificate from a public authority, and Microsoft is told where to send notifications for you, even where you have a custom domain in front of it.
On an appliance, notifications are sent from Microsoft to the Foldr server, rather than requested by the server. The following are required:
- The Foldr server must be reachable from the internet over HTTPS (TCP 443).
- The certificate must be issued by a public certificate authority. Self-signed certificates are rejected.
Microsoft validates that the address is reachable at the point change notifications are enabled. Servers that are only accessible on the internal network, or via a VPN, cannot use this feature.
Where the server is published on an external address that differs from the address it uses internally, contact [email protected] so that notifications can be directed to the correct address.
HTTPS inspection (self-hosted appliances)
If HTTPS / SSL inspection is performed by a firewall or web filter, graph.microsoft.com and login.microsoftonline.com must be excluded, as covered in the main integration article.
Enabling change notifications
Go to Foldr Settings > Integrations and open the Microsoft entry. It is listed as Microsoft Azure under Cloud, or as Microsoft Entra ID under Authentication where the appliance is licensed for Entra ID sign-in. Switch on Enable change notifications.
Debounce (seconds) determines how long the server waits after the first change before acting on it. Bulk operations in Microsoft 365, such as copying a large number of files into a library, are collapsed into a single update rather than one per file. The default of 5 seconds is suitable for most deployments. Increase it for libraries that change frequently.
Testing it
Underneath the debounce setting there is a Test button, and it is worth running once as soon as you have switched the feature on. Foldr signs in to Microsoft with the application credentials, picks a Microsoft 365 share that has change notifications enabled, and asks Microsoft to create a short-lived subscription against it, which is what makes Microsoft call back to your Foldr. The subscription is removed again immediately. Nothing else on the share is touched.
That single click covers both requirements above: the permissions have to be in place for the subscription to be accepted, and the address has to be reachable for Microsoft to deliver to it. If no Microsoft 365 share has notifications enabled yet, the test can only confirm the sign-in, and it says so.
The same Test button appears on each share (Advanced tab, under Microsoft 365) if you would rather test one share in particular.
Per-share control
Individual shares can override the server-wide setting. Open the share, select the Advanced tab, and under Microsoft 365 set Change notifications to one of:
| Setting | Behaviour |
|---|---|
| Use global setting | Follows the server-wide setting. Default. |
| On | Change notifications enabled for this share. |
| Off | Change notifications disabled for this share, regardless of the server-wide setting. |
How changes are detected
Changes are normally reflected within a few seconds, plus the configured debounce period.
Microsoft does not guarantee delivery of every notification, and individual notifications can be lost, particularly on busy Microsoft 365 tenants. Foldr also polls Microsoft periodically as a safety net, so a missed notification results in a short delay rather than a folder view that remains out of date indefinitely.
Teams storage behaves slightly differently. A team’s files are not known to Foldr until a user opens that team, so Teams locations begin reporting changes after they have been visited once. SharePoint sites and OneDrive locations do not require this.
Troubleshooting
If changes made in Microsoft 365 are not being reflected in Foldr, check the following in order:
- Run the test first. The Test button described above checks the permissions and the delivery address in one go, and its message names whichever of the two failed. It saves working through the rest of this list by hand.
- Application permissions and admin consent. The most common cause, particularly where users link their own Microsoft 365 accounts. Delegated permissions alone are not sufficient and produce no visible error.
- External reachability (appliances). Confirm the Foldr server is reachable from the internet over HTTPS, using a publicly trusted certificate.
- The share setting. Check the Advanced tab of the share in case change notifications are set to Off.
- Teams storage only. Confirm the team has been opened in Foldr at least once, then allow a minute for the location to be registered.
- Search results specifically. If folder views update but search results do not, confirm Index deltas is enabled on the share’s Search tab, and that the share has been crawled at least once to establish a baseline.
If the issue persists, generate a support bundle and send it to the support team. See Generating a support bundle.
Related articles
- OneDrive & SharePoint Online integration (Foldr Cloud) - the Entra app and Federated Identity Credential to set up before change notifications can be used.
- OneDrive & SharePoint Online integration (self-hosted) - the appliance equivalent, covering the app registration and account linking modes.
- Presenting SharePoint Online sites - storage address recipes for individual sites, subsites and document libraries.
- Generating a support bundle - how to provide diagnostic information to the support team.