What is the issue?

CloudFiles flow actions and other automations that use SharePoint suddenly start failing, for example Create Folder, Copy Resources or Create Attachment. Nothing changed in Salesforce. In Document Management → Libraries → SharePoint, the integration user may show a Connection Expired warning, and flows may fail with an error such as "Invalid refresh token".

This usually follows a change on the Microsoft side: the Microsoft 365 account connected as the integration user was removed from your tenant, disabled, or lost its license. A common example is when the person whose account was used leaves the company.

Why does it happen?

An integration user is a real Microsoft 365 account. Every account-level automation runs as that account and uses its SharePoint access. When the account is removed or disabled, Microsoft revokes its sign-in, so CloudFiles can no longer act on SharePoint and every automation that runs as the integration user fails.

Reconnecting the same account does not help, because that account no longer exists or can no longer sign in. You need to connect a different account.

How to fix this issue?

Replace the integration user with a new Microsoft 365 account:

  1. Choose a Microsoft 365 account that is active, licensed, and not tied to a person who may leave. A dedicated service account is best.
  2. Make sure that account has access to every SharePoint site, library and folder your automations use. Ask your SharePoint admin to grant it if needed.
  3. Open the CloudFiles app from the App Launcher in Salesforce and go to the Document Management tab.
  4. In the left sidebar, click Libraries and open the SharePoint section.
  5. Under Integration User, click Disconnect.
  6. Click Connect and sign in with the new account. Use a private or incognito browser window so the browser does not reuse the old account's cached sign-in.
  7. Check that the new account's username and today's date now show under Integration User.
  8. Re-run one of the failed flows to confirm it works.

Connecting an account does not give it accessConnecting the new account signs it in to CloudFiles. It does not give the account access to any SharePoint site or folder. If automations still fail after you reconnect, the new account is usually missing access to the site or folder the flow uses. Ask your SharePoint admin to grant it, then re-run the flow.
Check SharePoint REST API Authorization tooIf the removed account was also used under SharePoint REST API Authorization in the same SharePoint section, disconnect it there as well and connect the new account. That authorization has its own connected account, separate from the integration user. See SharePoint for the steps.

If the Microsoft sign-in window does not open, or closes straight away, see I am unable to reconnect the Integration User.

How to prevent it

Use a service principal instead of an integration user. CloudFiles then authenticates as its own application in your Microsoft directory, with no person's account behind it, so automations are not affected when staff leave, licenses change or passwords are reset. See SharePoint Connection Methods: Integration User vs Service Principal to compare the two, and SharePoint for the setup steps.