Summary
- Microsoft is removing the Word Online (Business) connector’s reliance on temporary, pre-authorized download URLs and switching file retrieval to authenticated access.
- Most connector actions are not expected to break, including GetFile, GetSchema, and ConvertFile/GetFilePDF.
- CreateWordFileWithContent may break if flows use its returned URL as an unauthenticated direct download link or pass it to downstream systems that do not authenticate to SharePoint or Microsoft Graph.
- Organizations using Power Automate, Power Apps, SharePoint Online, or OneDrive for Business should review flows and integrations that consume connector-generated URLs.
- Update affected flows to use authenticated file content retrieval or proper SharePoint sharing links instead of anonymous download URLs.
Primary Service: Word
Admin Impact: Medium
User Impact: Low
Release Start: 15 Sept 2026
Release End: 15 Oct 2026
Services: OneDrive, Power Apps, Power Automate, SharePoint
Category: Plan for change
Tags: Admin Action
History
9/25/2026 Item Added to Message Center
Microsoft Message
We are updating the Word Online (Business) connector to remove its dependency on temporary, pre-authorized download URLs. After this change, connector actions will use authenticated access to retrieve files instead of returning or relying on unauthenticated download URLs.
This update improves the security posture for file access in SharePoint and OneDrive scenarios by requiring authenticated access for generated document content.
Impacted actions:
- GetFile: No customer-facing breaking change is expected. The connector will retrieve content using authenticated access.
- GetSchema: No customer-facing breaking change is expected.
- ConvertFile / GetFilePDF: No customer-facing breaking change is expected. The connector will use authenticated streaming instead of a pre-authorized download URL.
- CreateWordFileWithContent: Potential breaking change. Customers should review any flows that depend on the returned URL for unauthenticated file access.
What is changing:
CreateWordFileWithContent currently returns a pre-authorized URL that can be used to download the generated document without additional authentication. After temporary authentication is removed, customers should no longer rely on this URL as an unauthenticated file-download mechanism.
Flows may be impacted if the returned URL is passed to:
- Email or similar actions as a direct download link.
- HTTP actions that access the file without SharePoint or Microsoft Graph authentication.
- Custom connectors that consume the URL without authentication.
- Azure Functions or other external services that download the file without authentication.
- Azure Blob or other downstream integrations that use the URL to retrieve the file.
Rollout Schedule
General Availability: We will begin rolling out in mid-September 2026 and expect to complete by mid-October 2026.
Impact on Your Organization
Who is affected
- Organizations using the Word Online (Business) connector in Power Automate, Power Apps, or related SharePoint and OneDrive scenarios.
- Makers and admins with flows or integrations that depend on unauthenticated temporary or pre-authorized download URLs returned by connector actions.
Platforms/Services
- SharePoint Online.
- OneDrive for Business.
- Power Automate and Power Apps connectors.
What will happen
- The connector will remove its dependency on temporary or pre-authorized download URLs.
- Most actions are not expected to have customer-facing breaking changes because they will retrieve content using authenticated access.
- Flows may be impacted if they rely on the CreateWordFileWithContent returned URL as an unauthenticated direct download link.
- Customers should use authenticated file content retrieval or appropriate SharePoint sharing links instead of unauthenticated download URLs.
Action Required/Recommendations
- Review flows and integrations that use Word Online (Business) connector output URLs for unauthenticated file access.
- For file-content scenarios, use SharePoint or OneDrive Get file content and pass the file content or bytes downstream.
- For email attachment scenarios, use Get file content and then send the email with the file attached.
- For sharing-link scenarios, use file metadata and create an appropriate SharePoint sharing link that matches your tenant and site sharing policies.
- For HTTP, custom connector, Azure Function, or external service scenarios, ensure the downstream caller authenticates to SharePoint or Microsoft Graph and has permission to the file.
- If an anonymous or public URL is required, use an Anyone sharing link only if permitted by your tenant and site sharing policies.
Compliance considerations
Does the change alter how existing customer data is processed, stored, or accessed?
Yes. The connector will use authenticated access instead of temporary or pre-authorized download URLs for file access. Customers should review flows and integrations that depend on unauthenticated access to SharePoint or OneDrive file content.
Does the change include an admin control, and can it be controlled through Entra ID group membership?
Yes. Admins can manage access through SharePoint and OneDrive permissions, sharing policies, connector configuration, and relevant Microsoft 365 admin controls.