The Microsoft 365 integration lets users embed Microsoft Word, Excel, and PowerPoint files (stored in SharePoint or OneDrive for work or school accounts) in Miro boards. This guide covers setup, the integration's technical implementation, security model, and data handling for admins evaluating or configuring the integration.
Key features
- Live embed: Users can embed a Word, Excel, or PowerPoint file into a Miro board as a live iframe.
- Secure: Every board visitor is prompted to log in to the iframe before they can view the embedded content.
- Display options: Users can choose to display embedded content as a live embed or as a bookmark.
- Focus mode: Users can expand a live embed or bookmark into focus mode to view it without distractions.
- Action shortcut: Users can add an action shortcut that opens a dialog for embedding a Microsoft 365 link.
- Asset picker: Users can add a specific page, sheet, or slide as a static image on the board, so collaborators can view and reference that exact content without needing access to the source file.
- Admin controls: Admins can prevent users from using the asset picker to add Microsoft 365 content as static images.
Requirements and limitations
- Requires a Microsoft 365 business account (SharePoint-based) with Word, Excel, or PowerPoint. Personal Microsoft accounts aren't supported.
Set up the Microsoft 365 integration
Prerequisites
- A Company admin has approved the Microsoft 365 integration for your Miro organization.
- You have Microsoft Entra admin access, to approve the integration for your Microsoft tenant.
Approve the integration in Microsoft Entra
The current version of the Miro Microsoft 365 app requires admin consent to install in a customer's Microsoft tenant.
- Log in to Microsoft Entra as an admin and go to Enterprise applications > Consent and permissions.
- Set Yes for Users can request admin consent to apps they are unable to consent to.
- Under Who can review admin consent requests, choose the users, roles, or groups who should be allowed to review these requests.
- Once this is configured, a non-admin user can paste a Microsoft 365 link to a Miro board (on a team enabled for the integration) to trigger an approval request.
- The admins selected in step 3 can go to Enterprise applications > Admin consent requests to review and approve the request. Once approved, the integration becomes available for any user in the tenant to authorize on their own.
Install and authorize the integration in Miro
Note: Only Miro team admins can install the app. If your Miro organization only allows approved apps, and a regular user pastes a Microsoft 365 link, that user sees an app install request dialog instead.
- Copy the Word, Excel, or PowerPoint file URL.
- Paste the URL onto your Miro board.
- What happens next depends on who pasted the link:
- A Miro team admin pastes the link: The app is authorized and installed automatically, and the link unfurls without further action.
-
A regular user pastes the link, and the organization only allows approved apps: An app install request dialog opens. After the user requests permission, company admins can follow the App request flow article to approve the request.
Connect a Microsoft 365 account
After the integration is installed and authorized:
- Click Connect on the widget created after pasting the URL on the board. You're redirected to a page asking you to grant Miro access to your Microsoft 365 account.
- Confirm authorization on the Microsoft side. The file's content is added to your board as an iframe.
Technical implementation
Miro integrates with Microsoft 365 through the Microsoft Graph REST API. Users authorize access with OAuth 2.0, then link their Word, Excel, or PowerPoint files to a Miro board.
Security considerations
The integration's asset picker lets users attach part of a Microsoft 365 file to the canvas as a static image. Only authorized users can access the live embed, but anyone with access to the board can view an attached static image. Adding assets from embeds is disabled by default on public boards.
Company admins can disable the asset picker for all boards:
- Go to Company settings > Apps and integrations > Apps > Microsoft documents integration (under the Manage apps tab).
- Toggle Prevent users from adding assets from embeds to the canvas.
Data flows
- A user who belongs to a team or organization with this feature enabled pastes a Microsoft 365 link onto a Miro board.
- Miro reads the link. If the user hasn't authorized the integration yet, Miro starts the OAuth flow and redirects the user to Microsoft's authorization page.
- After the user grants authorization, Miro's integration service uses the user's access token to call the Microsoft Graph REST API and retrieve the content.
What Microsoft 365 data Miro stores
Miro fetches and stores the following data from pasted Microsoft 365 links:
- Document and file titles
- Images created by the asset picker
Data retention
Embedded data follows Miro's standard data retention policy for all customer data.
Authentication and authorization
Embedding a Microsoft 365 link on a board requires the user to authorize the integration through Microsoft's OAuth API. This also requires a Microsoft Entra admin to approve the integration — see Approve the integration in Microsoft Entra above.
Required authorization scopes
The Microsoft 365 integration requires the following scopes:
-
offline_access— required to refresh tokens. -
Files.ReadWrite— allows the app to read, create, update, and delete the signed-in user's files. -
Files.ReadWrite.All— allows the app to read, create, update, and delete all files the signed-in user can access. -
Sites.ReadWrite.All— allows the app to edit or delete documents and list items in all site collections on behalf of the signed-in user.
What's stored in Miro and how
Miro stores two categories of data for this integration: authorization data and unfurling data.
Authorization data: Miro stores the access token and refresh token in its database for several days. While the authorization is active, Miro automatically refreshes an expired access token using the refresh token, without requiring the user to reauthorize. All data stored for this integration is encrypted at rest using 256-bit AES.
Unfurling data: Miro stores two kinds of unfurling data: the images captured by the asset picker (stored as part of the board) and the titles and image references (stored encrypted in an internal service).
Revoking a token
Microsoft Entra admins can revoke the integration's access — see Microsoft's guide to revoking application access (external).
Frequently asked questions
How do I turn off the integration?
A Microsoft Entra admin can revoke the Miro integration's permissions by deleting the app: go to Enterprise applications > All applications, select the Contenthub Microsoft Integration application, then Properties > Delete.
Which users can embed Microsoft 365 content into Miro?
The user and the Miro board must meet both of these criteria:
- The user has authorized the Miro Microsoft 365 integration.
- The user has access to the Microsoft 365 content they're trying to embed.
Which users can view the embedded Microsoft 365 content?
Anyone with access to the Miro board and permission from the owner of the embedded content — that is, anyone with view, comment, or edit permissions on the board. Viewers don't need to authorize the integration or hold a Microsoft 365 license to view the embedded content on the board.
Do users have to reauthorize to paste links on other boards?
No, as long as the authorization is still valid (Miro treats an authorization as valid for a month after it's granted). Users can paste Microsoft 365 links on any board, and the content imports normally.
If the board belongs to a different team or organization where this integration isn't enabled, the user can't use it there.
Can I access Microsoft 365 content through Miro that I can't access directly in Microsoft?
No. You can only embed Microsoft 365 content you already have access to — you can't use the integration to see something you couldn't otherwise open in Microsoft. That said, if someone with access has already embedded the content as a static image on a board you share with them, you can view that snapshot even without direct access to the source file. The integration doesn't enforce any additional access policies beyond this; use the Miro board's own sharing settings to restrict who can collaborate. Note that a static image snapshot can't be used to explore the underlying document, open the original file, or change filters.
Where can I find the Miro Data Processing Addendum?
See the Miro Data Processing Addendum.
What's disallowed on public Miro boards?
For security reasons, public boards disable:
- Asset extraction — supported by the Looker, Google Slides, Figma, Power BI, Microsoft Word, Microsoft Excel, and Microsoft PowerPoint integrations.
- Direct asset unfurling (asset instead of live embed) — supported by the Figma integration.
How can I restrict board access to the same people who have access to the source file?
The integration only manages file access from the source system (Microsoft 365), not from Miro. By default, this isn't enforced — to maintain this level of security, Miro organization admins must disable the asset picker in the app's admin settings (see Security considerations).
Disabling the asset picker prevents Microsoft 365 content from being saved as static images on a Miro board, where it could later be seen by people who don't have access to it in Microsoft 365 (for example, if the board is shared publicly or with people who lack source access).