Exchange Online customers: Microsoft is retiring Exchange Web Services. Here is what administrators need to do.
Notate Resource Center

Notate for Intune Data Flow

For IT and security teams. How Notate for Intune connects to Microsoft Intune, Microsoft 365 and your network, and what data moves where. This describes the current production architecture.

2026-10-01-notate-architecture.png

Notate 2026 when deployed against Microsoft 365

  1. Notes and documents live in OneDrive. Notate used to keep each user's notes and documents in their Exchange mailbox, reached through Exchange Web Services (EWS). Notate now keeps them in the user's own OneDrive, in a folder named "Notate Drive (app-managed)", reached through Microsoft Graph. Your OneDrive versioning, retention, data loss prevention, eDiscovery and audit policies apply to them automatically. See Notate Drive and OneDrive.

  2. Email uses Microsoft Graph. Notate opens email attachments and sends edited documents through Microsoft Graph instead of EWS.

  3. Optional AI in your own tenant. Notate can use Azure OpenAI running in your own Microsoft Foundry. It is off unless you turn it on.

Everything else is unchanged. The full list of permissions Notate requests is on Prerequisites and Microsoft Entra ID permissions.

Components

In your network (optional)

Component

Role

Windows file shares (SMB)

Reached through the Intune VPN tunnel. Notate uses the latest SMB 3.0 over the tunnel to open and save files.

Microsoft cloud services

Service

Role

Microsoft Intune

Device management, app configuration and policy delivery. Intune sends all Notate app policy settings to the app.

OneDrive (Notate Drive)

Stores the user's notes and documents, and Notate's app data (recents, cache, favorites, settings) in a .notate subfolder. Notate reaches it with the Microsoft Authentication Library (MSAL) and Microsoft Graph.

Exchange Online

Opens email attachments for editing and sends edited documents. Notate uses MSAL and Microsoft Graph.

OneDrive, SharePoint, Teams file access

Optional connectors to the user's other files. Each can be turned off by Intune policy.

Shafer Systems service

Service

Role

Notate licensing and sharing notification server, https://api.notatepro.com

License activation and notifications for shared folders. No document content and nothing that identifies a user is sent: only opaque tokens and device and app metadata. See Notate Sharing Architecture.

Connection path

Device → MSAL OAuth → Microsoft Graph (OneDrive, Exchange Online, SharePoint, Teams) → optionally the Intune VPN tunnel → your file shares over SMB

Data flows by feature

Feature

Path

Notes and documents

Notate → MSAL OAuth → Microsoft Graph → the user's OneDrive (Notate Drive)

Moving existing notes and documents from Exchange (one time)

Notate → EWS → the user's Exchange mailbox, then → Microsoft Graph → OneDrive. Only when the policy is set to migrate. See Step 2: Move Notate Drive to OneDrive.

Email attachments

Notate → Microsoft Graph → Exchange Online

Files on your network

Notate → Intune VPN tunnel → SMB server

Cloud files (if turned on)

Notate → Microsoft Graph → OneDrive, Teams, SharePoint; Notate → ShareFile

Licensing and sharing notifications

Notate → api.notatepro.com (no personal data, no documents, no email content)

App registrations in Microsoft Entra ID

Application

Application ID

Notes

Notate

215843d3-1ef5-43d0-9b0f-76d16094ae79

The same ID for iOS, Android, Mac and Windows. Permissions are listed on Prerequisites and Microsoft Entra ID permissions.

Notate for Intune

a60a715a-feef-43bd-97ef-3f6bdab7cf4f

Needed for Intune deployments. Add it as an enterprise application. Delegated permission: Microsoft Mobile Application Management.

All cloud connectors can be turned off by policy in Intune or your MDM.

If your organization adopted SharePoint Embedded with Notate, its storage path and permissions are described in Notate and SharePoint Embedded.

Last updated: