SharePoint Connector - Security — Unique AI Documentation

SharePoint Connector - Security

Overview

This document describes security practices, update policies, and the Software Bill of Materials (SBOM) for the SharePoint Connector.

Security Updates

Security update cadence and release lifecycle expectations follow the canonical Upgrade and Release Process. Review this policy when planning upgrade windows and patch rollouts.

Security Reports

If you identify a potential vulnerability, report it through your standard Unique support/security contact and include connector version, affected tenant/environment, and reproduction details. Release handling expectations follow the Upgrade and Release Process.

Security Architecture

Security Principles

Least Privilege Access

Certificate-Based Authentication

Transport Security

Data Handling

Compliance Considerations

Data Residency

Audit Logging

All operations are logged with:

Access Controls

Control Implementation
Authentication Certificate-based (X.509)
Authorization Sites.Selected / Lists.SelectedOperations.Selected grants
Audit Structured logging
Encryption TLS 1.2+ in transit

Best Practices

For Operators

  1. Rotate certificates before expiration
  2. Review site grants periodically
  3. Monitor logs for anomalies
  4. Update promptly when security patches released
  5. Use certificate authentication for production environments

For Security Teams

  1. Review SBOM for each deployment
  2. Assess CVEs against deployed version
  3. Audit site grants for least privilege
  4. Monitor API usage for anomalies
  5. Test in staging before production updates

Standard References