Skip to content

Set up CtrlTMS

By the end of this section the teams in your tenant appear as objects in the vault.

Time: around two hours for a first deployment, most of it the Entra ID registration and waiting for admin consent.

Who you need: someone with administrative access to the vault, and someone who can register an application in Microsoft Entra ID and grant admin consent for application permissions. These are usually two different people at the customer, and not lining them up in advance is the most common cause of a stalled deployment.

  • Administrative access to the target vault through M-Files Admin.
  • A Microsoft 365 tenant, and someone who can grant admin consent for application permissions.
  • The CtrlTMS .mfappx file and its .lic licence file.
  • An agreed window for a vault restart.
  • A decision about whether CtrlTMS will create connection objects for CtrlSync to synchronise. If it will, both applications have to agree on the object type and class — see Set up CtrlTeams.
  1. Register the Entra ID application.

    Create the registration, add the application permissions CtrlTMS needs, and have an administrator consent to them. See Register the Entra ID application.

    Check: the permission list in Entra shows each permission as granted, not as Not granted.

  2. Install the application and its licence.

    See Install CtrlTMS, then Install a vault application licence.

    Check: CtrlTMS appears under the vault’s Applications node and the vault has been restarted.

  3. Create the vault structure.

    The object type and classes that hold teams and channels, and the properties CtrlTMS writes onto them — the Graph ID in particular, which is how a second run recognises a team it has already created. See Vault structure.

    Check: you can create a team object by hand with every property the configuration will ask for.

  4. Enter the Graph credentials.

    Put the tenant ID, client ID and client secret into the Graph settings, and save.

    Check: the application status in M-Files Admin reports no configuration or authentication error.

  5. Run discovery once.

    Let discovery run and look at what it created.

    Check: teams that exist in Microsoft 365 appear as objects in the vault, with their members, and no duplicates were created.

See Troubleshooting. The first thing to check is the application status in M-Files Admin, which lists configuration errors directly.