Exchange Online customers: Microsoft is retiring Exchange Web Services. Here is what administrators need to do.
Notate Resource Center

Container administration, security and compliance

How to manage Notate's SharePoint Embedded containers with Microsoft's own tools, and how your existing compliance policies apply to them.

Management tools

Tool

Best for

SharePoint Admin Center

Day-to-day monitoring, viewing container metadata, managing permissions, ad hoc tasks through a graphical interface.

PowerShell

Bulk operations, scripted management, automation, repeated or scheduled tasks.

Microsoft Graph APIs

Programmatic integration, custom tooling, event-driven automation.

Viewing containers in the SharePoint Admin Center

The Active Containers page lists every active SharePoint Embedded container in your tenant with its name and description, application name and publisher, storage used and creation date, owner, manager, reader and writer permissions, and any sensitivity labels applied. You can filter by application, publisher, ownership type, principal owner, owner count, creation date and sensitivity label. Notate's containers show the server display name "My Files".

Container lifecycle

Soft delete and recovery

When a container is deleted it moves to the Recycle Bin, where it is retained for 93 days. During that period you can restore the container and all of its contents with the Restore-SPODeletedContainer PowerShell cmdlet or from the SharePoint Admin Center. After 93 days containers are permanently deleted; you can also force permanent deletion from the Recycle Bin.

Caution. Deleting a container deletes all content within it and may interrupt Notate for the affected user. Coordinate with your Notate administrator before deleting containers.

Container activation

Newly created containers must be activated within 24 hours or they are automatically removed. Notate handles this automatically, but administrators should be aware of it when troubleshooting.

Security and Compliance Administration

SharePoint Embedded uses Microsoft’s comprehensive compliance and data governance solutions to help your organization manage risks, protect sensitive data, and respond to regulatory requirements. Security and compliance solutions work in SPE the same way they work across the broader Microsoft 365 platform.

Admin roles and permissions

Role

Capabilities

Global Administrator

Full access to all management tasks, including assigning other admin roles and managing all containers and compliance policies.

SharePoint Embedded Administrator

Manage, configure and maintain SharePoint Embedded containers. Enumerate and manage container permissions. Apply security and compliance policies. Does not include SharePoint site management.

We recommend assigning the SharePoint Embedded Administrator role to dedicated administrators, following least privilege, rather than relying on Global Administrator accounts.

Retention policies

  • A Microsoft Purview retention policy configured for "All SharePoint Sites" automatically applies to all SharePoint Embedded containers, including Notate's.

  • You can also create targeted retention policies for specific containers by specifying their container URLs.

  • Retention policies preserve documents for the required period and dispose of them appropriately afterward.

Data Loss Prevention

  • Apply Purview DLP policies to all sites, which covers both SharePoint and all SharePoint Embedded containers, or target specific container URLs.

  • Sensitive content is detected and protected according to your organizational policies.

  • DLP actions and alerts integrate with your existing Purview monitoring.

eDiscovery

  • Select "All SharePoint Sites" in Purview eDiscovery to search across SharePoint sites and all SharePoint Embedded containers.

  • For targeted searches, select "Choose sites" under the SharePoint sites workload and provide specific container URLs.

  • Results include full document content and metadata.

Encryption and tenant isolation

  • All data is encrypted at rest with AES-256 and in transit with TLS 1.2.

  • Per-file encryption keys are unique to each tenant.

  • Each tenant uses a unique subscription ID for data segregation; real-time monitoring detects and prevents unauthorized cross-tenant access; enforcement is automatic through Microsoft Entra ID and SharePoint.

Quick reference: key admin actions

Task

Where

Set up SharePoint Embedded billing

Microsoft 365 Admin Center, Setup, Billing and licenses, Activate pay-as-you-go services, Apps, SharePoint Embedded

Monitor costs

Azure Portal, Cost Management, Cost analysis

View active containers

SharePoint Admin Center, Active Containers

Restore deleted containers

PowerShell: Restore-SPODeletedContainer

Configure retention policies

Microsoft Purview, Data lifecycle management, Retention policies

Configure DLP policies

Microsoft Purview, Data loss prevention, Policies

Run an eDiscovery search

Microsoft Purview, eDiscovery, select All SharePoint Sites

Assign the SharePoint Embedded Admin role

Microsoft Entra ID, Roles and administrators

Manage container permissions

SharePoint Admin Center or PowerShell

Microsoft documentation

  • SharePoint Embedded overview, billing, security and compliance, container management in the Admin Center, the SharePoint Embedded Administrator role, and PowerShell for consuming-tenant administrators, all on Microsoft Learn.

Last updated: