Exchange Online customers: Microsoft is retiring Exchange Web Services. Here is what administrators need to do.
Notate Resource Center

Notate and SharePoint Embedded

For organizations that already use SharePoint Embedded with Notate. SharePoint Embedded is a Microsoft 365 service that stores an app’s content in containers inside your own Microsoft 365 tenant. Notate can keep Notate Drive there instead of in each user’s OneDrive.

We now recommend OneDrive for every new deployment. It needs no extra Microsoft billing, no container setup and no additional permissions. See Notate Drive and OneDrive.

SharePoint Embedded remains supported for organizations that have already adopted it.

Setting up and running SharePoint Embedded

Page

What it covers

Setting up SharePoint Embedded billing

Connecting SharePoint Embedded to pay-as-you-go billing on your Azure subscription.

Setting up container provisioning

Deploying the small Azure Function that creates each user's container, and the two MDM values that point Notate to it.

Container administration, security and compliance

Managing Notate's containers once they exist, and how your compliance tools see them.

SharePoint Embedded FAQ

The questions administrators ask most.

SharePoint Embedded resource kit

The files your Azure administrator works from: the deployment template, the provisioning code package, the registration script and the Deployment Readiness Guide.

What SharePoint Embedded needs in addition

On top of the prerequisites for every Notate deployment:

Requirement

Details

Azure subscription

A valid Azure subscription for pay-as-you-go billing.

Azure resource group

A resource group within the Azure subscription. It anchors billing and hosts the provisioning function.

Admin role

SharePoint Embedded Administrator or Global Administrator in Microsoft Entra ID.

Azure permissions

Owner or Contributor on the Azure subscription.

Additional Microsoft Graph permissions

Notate asks for these two permissions only when notateDriveMode is set to spe or migrate.

Permission

Purpose

FileStorageContainer.Selected

Read and write user data in Notate's SharePoint Embedded container.

FileStorageContainerTypeReg.Selected

Register Notate's container type within the tenant.

MDM policies for SharePoint Embedded

Set these two policies in your MDM’s app configuration for Notate, together with notateDriveMode set to spe or migrate. Both values come from Setting up container provisioning.

Policy ID

Type

Definition

NotateProvisioningEndpoint

text, max 256

URL of the container provisioning function deployed in your own Azure tenant, for example https://yourname-func.azurewebsites.net/api/provision.

NotateProvisioningAppId

text, max 64

Application (client) ID of the “Notate SPE Provisioning” app registration in your Entra tenant.

Last updated: