Outlook + OneDrive: The Freelancer's Filing Setup

You're on Microsoft. Outlook for email, OneDrive for files, maybe a Microsoft 365 Business plan tying it all together. You like it. You've been on it for years.
Now you want the same thing every Gmail+Drive freelancer is doing: email attachments auto-filed into folders so tax time isn't a search-bar emergency.
Good news. As of this week, AutoFileEmail's Outlook + OneDrive integration is live. No Power Automate flow. No custom expressions. No 750-action daily ceiling. Two OAuth screens and you're done.
This is the working setup guide. End to end, what you click, where the files land, and the M365 admin gotchas to know about before you start.
Table of Contents
- The 90-second version
- What's different from a Gmail+Drive setup
- Step one: connect Outlook
- Step two: connect OneDrive
- Where your files actually appear in OneDrive
- M365 work accounts: the admin consent layer
- How incremental consent will work for Pro
- Why we're not just shipping a Power Automate template
- The freelancer-on-Outlook playbook
- TL;DR
The 90-second version
Sign up at autofile.email. In onboarding:
- Click "Connect Outlook." Microsoft consent screen. Approve
Mail.Read. - Click "Connect OneDrive." Second consent screen. Approve "Have full access to the application's folder."
- AutoFileEmail starts polling your inbox every 30 seconds.
- New attachments file into
/Apps/AutoFileEmail/{vendor-domain}/{YYYY}/{MM}/in your OneDrive.
That's it. No flows, no expressions, no per-action metering. The first 30 days of historical mail also get backfilled automatically as a free preview, so you'll see receipts populate within a few minutes of finishing onboarding.
If your inbox is at a Microsoft 365 work account and your IT department blocks third-party apps, skip ahead to the admin-consent section. If you're on a personal outlook.com / hotmail.com / live.com address, you can stop reading the warnings and just connect.

What's different from a Gmail+Drive setup
Functionally? Almost nothing. Same dashboard, same activity log, same {vendor-domain}/{YYYY}/{MM}/ folder layout, same dedup logic.
The two real differences are cosmetic and live in OneDrive itself:
Files land under /Apps/AutoFileEmail/, not at the root. Microsoft's "App folder" mode for OneDrive sandboxes us. We can read and write inside that folder. We cannot see anything outside it. Your family photos, your work docs, your Documents folder full of half-finished pitch decks - invisible to us. We literally cannot list them via the Graph API. Drive's drive.file scope works the same way (we only see files we created), but OneDrive surfaces the sandbox more visibly with that /Apps/ prefix.
Outlook consent reads "Mail.Read." Drive's read-mail equivalent for Gmail says "Read all your email." Microsoft's wording is the same shape, slightly less alarming. Same access either way: we read message metadata and download attachments. We don't reply, we don't forward, we don't mark anything as read.
If you've already got a Gmail+Drive setup running and you're adding Outlook+OneDrive on Pro (5 inboxes, $14.99/mo, coming soon), the second pair just slots in. One activity log, both inboxes filing into their respective clouds.

Step one: connect Outlook
In onboarding, after the Drive folder bootstrap step, you'll see a "Connect inbox" screen with three tiles: Gmail, Outlook, IMAP.
Click Outlook.
A Microsoft sign-in window opens. You sign in with the account you want filed - personal Microsoft (outlook.com, hotmail.com, live.com, msn.com) or your M365 work account (yourname@yourcompany.com). The consent screen lists exactly one permission:
Mail.Read- "Read your mail"
That's the entire scope. We don't ask for Mail.Send, we don't ask for Mail.ReadWrite, we don't ask for contacts, calendars, or anything else. The whole point of this product is filing attachments. We need to read mail. That's it.
Click Accept. The window closes. Onboarding shows a green checkmark next to "Outlook connected" and the email address.
If Outlook 365 with two-factor auth nags you, that's normal - approve the push or enter the code, then click Accept on the consent screen. Connection succeeds.

Step two: connect OneDrive
Next screen. "Connect cloud storage." Three tiles: Google Drive, OneDrive, Dropbox.
Click OneDrive.
Second Microsoft window. Same account login (or sometimes it auto-fills). The consent screen this time lists:
Files.ReadWrite.AppFolder- "Have full access to the application's folder"User.Read- "Read your profile" (used for auth, nothing else)
Files.ReadWrite.AppFolder is the narrowest OneDrive scope Microsoft offers. Translated: we can create, read, update, and delete files inside /Apps/AutoFileEmail/. We have zero access to anything else in your OneDrive. The Graph API will refuse if we try.
Click Accept. The window closes. Onboarding shows the OneDrive folder location: /Apps/AutoFileEmail/. AutoFileEmail kicks off the 30-day historical preview backfill in the background.
You're done. Onboarding hands you off to the dashboard.

Where your files actually appear in OneDrive
Open OneDrive in your browser. Click "My files" in the left nav.
Scroll down (or look for the "Apps" folder). Inside Apps, you'll see "AutoFileEmail." That's our folder. We're the only thing that writes to it.
Inside /Apps/AutoFileEmail/, the structure looks like this once you've got a few vendors filed:
One folder per registrable sender domain. Subfolders by year, then month. Files keep their original names, prefixed with the email date so they sort cleanly inside the month folder.
This is the same layout used by the Gmail+Drive flow. If you ever switch clouds, your accountant doesn't have to learn anything new.

M365 work accounts: the admin consent layer
If you're on a personal Microsoft account, skip this section.
If you're connecting an M365 work account and your tenant restricts third-party apps (most enterprise tenants do, plenty of small-business ones don't), the consent screen will say "Approval required" and the connection will fail.
Two paths forward.
Option 1: Tenant-wide admin consent. Send your IT admin a one-line ask: "Please grant tenant consent for AutoFileEmail at https://login.microsoftonline.com/<your-tenant-id>/adminconsent?client_id=<our-client-id>." Once approved, any user in your org can connect without further IT involvement. The scopes IT will see are exactly the two listed above (Mail.Read and Files.ReadWrite.AppFolder), which is narrower than Hubdoc, narrower than Zapier, narrower than Power Automate's broad connectors. IT teams that scrutinize this rarely push back because the footprint is genuinely small.
Option 2: Per-user admin consent. If IT doesn't want to grant tenant-wide access, they can grant just-you consent for your specific account. Lower-stakes ask. Same outcome for you.
If you ARE the IT admin (solo founder running a single-user M365 tenant), the consent screen just adds one extra "Consent on behalf of your organization" checkbox. Tick it. Done.
For a comparison of how this scope footprint stacks up against the alternatives, see the OneDrive folder structure your accountant actually wants.

How incremental consent will work for Pro
Right now, free tier files into /Apps/AutoFileEmail/. That's the only destination, locked by the App folder scope.
When Pro ships (5 inboxes, custom destination folders, $14.99/mo), some users will want files going somewhere else - say, a shared OneDrive folder named Receipts/ that their bookkeeper has access to. That requires a broader scope (Files.ReadWrite instead of Files.ReadWrite.AppFolder).
Microsoft's incremental consent flow handles this cleanly. When you upgrade to Pro and pick a custom destination, AutoFileEmail re-prompts you for the broader scope. The old Files.ReadWrite.AppFolder permission stays active alongside the new one until the upgrade completes, then we migrate. You don't lose access to anything during the switch.
If your IT department needs to re-approve the broader scope, you'll see the "Approval required" screen again at upgrade time. Same one-line ask to IT. Same approval flow.
For now, free tier and /Apps/AutoFileEmail/ is the working pair. Pro and custom destinations are on the waitlist.
Why we're not just shipping a Power Automate template
Reasonable question. Microsoft's Power Automate already does ~80% of this for free with M365.
Five reasons we built our own anyway:
-
Domain routing is the 80/20. A flat dump of attachments isn't useful at tax time. Your accountant doesn't want one folder with 600 PDFs; they want them split by vendor. Power Automate can do this with custom expressions, but most users won't write them, and the ones who do find the expressions break in edge cases when sender headers are malformed.
-
Power Automate has action limits. 750 actions/day on the free tier. A user with 30 vendors emailing receipts averages 100+ actions a day during busy seasons. Premium licensing starts at $15/user/month - more than our Pro tier.
-
No retroactive backfill. Power Automate triggers on new mail going forward. There's no native "process my last 3 years of inbox" path. We built backfill specifically because nobody else does it well. The $29 Tax Year Pack covers a full year retroactively. No per-email surcharge.
-
Tax-relevant deduplication. Our
(account_id, message_id, filename)unique index means no duplicates regardless of how many times we re-process a message. Power Automate flows can double-file in edge cases. -
One product, two clouds. Same dashboard, same folder structure, same logic, regardless of whether your inbox is Gmail or Outlook and whether your storage is Drive or OneDrive. Power Automate locks you to Microsoft.
If your needs are very simple (one vendor, one folder, fewer than 750 attachments a day), Power Automate is genuinely fine. It's free with M365. If your needs are anything beyond that, the math shifts hard toward purpose-built.
The freelancer-on-Outlook playbook
If you're a freelancer or solo founder on Outlook, the working setup is:
- Sign up at autofile.email with your Microsoft account. 30 seconds.
- Connect Outlook + OneDrive in onboarding. Two minutes.
- Let the 30-day backfill catch up. Within a few minutes you'll see April's receipts already in OneDrive.
- If you want the last full tax year filed too, buy the $29 Tax Year Pack. One-time payment, no subscription. Backfill runs in the background.
- Every receipt going forward files itself within 30 seconds of arriving.
For a deeper look at why the auto-filing approach beats the OCR-everything alternative, see why we don't OCR your receipts.
TL;DR
- AutoFileEmail's Outlook + OneDrive integration is live. Two OAuth screens, no Power Automate, no custom expressions.
- Files land under
/Apps/AutoFileEmail/{vendor-domain}/{YYYY}/{MM}/in OneDrive. App folder mode means we cannot see anything else in your OneDrive. - Microsoft scopes:
Mail.Readfor Outlook,Files.ReadWrite.AppFolder+User.Readfor OneDrive. That's the entire footprint. - M365 work accounts may need IT to grant tenant or per-user consent. The ask is small because the scope is small.
- Pro (custom destination folders, 5 inboxes) is on the waitlist. Microsoft's incremental consent flow handles the upgrade cleanly when it ships.
Free for one inbox + one cloud, no credit card, no per-receipt fees. Connect Outlook and OneDrive today and your April receipts are filed before you finish your coffee.
We don't read your receipts. We just file them.
The last time you'll dread tax season.
Connect Gmail and Drive, watch the 30-day preview file itself, and never think about new email attachments again. Forward filing is free, forever. When tax season comes, grab a Backfill Pack and we'll sweep the rest of your history.