Settings > Connections – where you set your own default*/allowed* values. This configuration applies to the tool everywhere you use it, including directly in a chat with no assistant.
Assistant > Configure Tool > Scope tab – an additional restriction (scopeOverride) that applies only to that assistant and can narrow the values from Connections further. A connector used directly in a chat with no assistant has no such additional restriction — only the Connections configuration applies there.
allowedChannelIds: additional channel restriction within allowed teams.
For Outlook and Teams, these fields apply only at the connection level (Settings > Connections) — they can not be additionally restricted per assistant, unlike Google Drive, OneDrive, and SharePoint.
defaultSiteId: default site used when no site is given explicitly in the tool call.
allowedSiteIds (UI label "Restrict to Sites"): restricts access to the selected SharePoint sites.
Attention
For SharePoint, the unit of restriction is the site, not the folder. Unlike Google Drive and OneDrive (allowedFolderIds), the SharePoint connector cannot be restricted to a single subfolder within a site — only to whole site(s). For an actual subdirectory-level restriction with a guarantee that no other SharePoint content is pulled in, a data source with SharePoint as its source is the right tool, not the native connector.