Exchange Online customers: Microsoft is retiring Exchange Web Services. Here is what administrators need to do.
Notate Resource Center

Notate MDM application policy configuration (Notate 2026)

Every Notate capability an administrator can control is delivered to the app as an application policy published by your mobile device management platform. Notate ships a configuration file for each supported platform. Import the file for your platform, set the values your organization needs, and assign the configuration to the Notate app. Policies reach the device the next time your MDM checks in, and the app applies them the next time the user signs in. The policies are the same in every edition.

Supported management platforms

Platform

Configuration file

BlackBerry UEM

Edit in the UEM console

Generic AppConfig

appConfig.xml

MobileIron / Ivanti

appConfigMobileIron.xml

Microsoft Intune

IntuneConfig.xml

Citrix / XenMobile

Edit in the XenMobile console after importing the MDX file

The configuration files are on the pages under Deploy with your MDM.

License and support

Policy ID

Type and default

Definition

licensingKey

text, max 2048

Product license key. Contact sales@shafersystems.com to retrieve your key. Determines which licensed features are available to the user.

allowCrashReports

checkbox, true

Allow reporting of crash logs to Shafer Systems.

allowLogging

checkbox, true

Allow users to enable verbose diagnostic logging to assist in debugging.

supportEmail

text, support@shafersystems.com

Address where user feedback and debug logs are submitted. Point it at your own help desk to triage internally first.

supportURL

text, https://links.notatepro.com/support/home

URL for the in-application support page.

learningCenterURL

text, https://links.notatepro.com/support/learning

URL for the Notate learning center page.

Branding

New in Notate 2026. You can put your organization’s logo and name in Notate, so your users see at a glance that this is your firm’s own, IT-managed app. They appear in the header at the top of Notate’s navigation panel:

2026-09-30-branding-header-contoso.png

What you see

Policy

The logo (“CONTOSO” with its mark)

companyLogoURL

The name on the right (“Contoso”)

companyName

The header’s background color (teal here)

companyLogoBackColor

The color of the name (white here)

companyLogoForeColor

Notate stays in the background: “Powered by Notate” appears in small type at the foot of the same panel.

2026-09-30-branding-powered-by-notate.png

All four policies are optional. Leave them blank and Notate keeps its standard look. The logo is fetched from the URL you give, so use an address your users’ devices can reach.

Policy ID

Type and default

Definition

companyLogoURL

text, max 1024

URL of your company logo.

companyName

text, max 256

Optional company name displayed alongside the logo.

companyLogoBackColor

text, max 64

Background color behind the company logo, as a hex value such as #1F2A44.

companyLogoForeColor

text, max 64

Foreground color for the company name text, as a hex value such as #FFFFFF.

Notate Drive

Notate Drive is each user’s own place in Notate for their notes, documents and folders. For Microsoft 365 customers it lives in the user’s own OneDrive; for Exchange on-premises customers it stays in the user’s mailbox. Either way it stays inside your organization, under your own retention, DLP and governance policies. See Notate Drive and OneDrive.

Policy ID

Type and default

Definition

notateDriveMode

select, ews

Where Notate Drive lives: ews, migrate_to_onedrive, onedrive, migrate or spe. See the table below.

useModernAuth

checkbox, true

Authenticate against Microsoft 365 / Entra ID using OAuth. Named modernAuth in the configuration file.

allowMicrosoftAuthenticator

checkbox, true

When using modern authentication, allow sign-in through the Microsoft Authenticator app.

notateDriveMode value

Meaning

ews

Notate Drive stays in the user’s Exchange mailbox. For Exchange on-premises, and for Exchange Online customers who have not moved yet.

migrate_to_onedrive

Copy Notate Drive from Exchange to the user’s OneDrive, then run on OneDrive. For existing Exchange Online customers.

onedrive

Notate Drive in the user’s OneDrive, with nothing moved. For new Microsoft 365 customers.

migrate

Copy Notate Drive from Exchange Online to SharePoint Embedded. Only for customers who already use SharePoint Embedded.

spe

SharePoint Embedded, with nothing moved. Only for customers who already use SharePoint Embedded.

Customers who use SharePoint Embedded also set two provisioning policies. They are listed on Notate and SharePoint Embedded.

Corporate document repositories

Policy ID

Type and default

Definition

allowEmailAttachmentList

checkbox, true

Allow users to open and edit documents from email attachments.

allowReplyToEmail

checkbox, true

Allow users to return edited email attachments to the sender.

allowOneDrive

checkbox, true

Allow users to read and write files in Microsoft OneDrive.

allowSharePoint

checkbox, true

Allow users to read and write files in Microsoft SharePoint.

allowTeams

checkbox, true

Allow users to read and write files in Microsoft Teams.

allowCitrixFiles

checkbox, false (Citrix: true)

Allow users to read and write files in ShareFile (Citrix Files). Off by default except in the Citrix edition.

allowBlackBerryWorkspaces

checkbox, false

Allow users to read and write files in BlackBerry Workspaces. BlackBerry UEM only; beta in this release. (*BlackBerry only)

workspacesUrl

text, max 256

BlackBerry Workspaces server URL. Required when allowBlackBerryWorkspaces is on. (*BlackBerry only)

allowSMB

checkbox, true

Allow users to read and write files on SMB network drives (Windows file shares). How to set them up, including Kerberos and the network path the app needs: Network drives (SMB file shares).

smbConnectionList

text, max 1024

The shares users see, comma-separated. Each entry is a path followed by an optional friendly name after a vertical bar: server/share/optional/subpath|Friendly Name. The first segment is the server, as a host name or IP address; without a friendly name, Notate shows the path. Example: fileserver01.example.com/Corporate|Corporate Drive,192.168.4.20/Engineering/Specs|Eng Specs.

useSMBKerberos

checkbox, false

Authentication for network drives: false uses NTLM, true uses Kerberos. Kerberos also needs kerberosConfig.

kerberosConfig

textarea, max 4096

Your krb5.conf file, Base64-encoded into a single line. Required when useSMBKerberos is true; ignored otherwise.

GEMSServerURL

text, max 256

Full URL to the BEMS server including port, for example https://server.domain.com:8443. Only for BlackBerry Dynamics deployments that route SMB traffic through BEMS. (*BlackBerry only)

Notate AI

Notate AI runs against your own Azure OpenAI resource. No prompt or document content reaches Shafer Systems. Setup is in Notate AI features: setup on your own Azure OpenAI resource; this is the policy reference.

Policy ID

Type and default

Definition

allowAI

checkbox, true

Master switch. Must be on for any Notate AI feature to be available: PDF create and edit via AI, document Q&A, meeting audio transcription and summary, handwriting to text. Nothing is active until the endpoint policies below are also set. How to set it up: Notate AI features: setup on your own Azure OpenAI resource.

azureOpenAIEndpoint

text, max 256

Base endpoint URL of your Azure OpenAI resource.

azureOpenAIDeployment

text, max 256

Deployment name assigned to the model in Azure AI Foundry / Azure OpenAI Studio (the deployment name, not the model name).

azureOpenAIApiVersion

text, max 64

Azure OpenAI REST API version to target, for example 2024-10-21.

azureOpenAIAudience

text, max 256

Token audience override. Older resources use https://cognitiveservices.azure.com; newer AI Foundry resources need https://ai.azure.com.

azureOpenAIWhisperEndpoint

text, max 256

Audio transcription endpoint.

azureOpenAIWhisperDeployment

text, max 256

Audio transcription model deployment name.

azureOpenAIWhisperApiVersion

text, max 64

Audio transcription REST API version.

Document editing and data loss prevention

Policy ID

Type and default

Definition

allowOfficeEditor

checkbox, true (Intune: false)

Allow editing of Word, Excel and PowerPoint documents with Notate's built-in editors. Off by default on Intune, where Microsoft Office is expected to handle Office formats.

useMicrosoftOffice

checkbox, true

Allow opening Word, Excel and PowerPoint documents in the native Microsoft Office apps.

allowPDFContentEditing

checkbox, true

Allow editing original PDF text directly in Notate.

allowDigitalSignature

checkbox, true

Allow digitally signing PDF documents using MDM-issued certificates.

allowPDFRedaction

checkbox, true

Allow redacting sensitive, confidential and privileged information from PDFs.

forceFlattenAnnotations

checkbox, false

Flatten PDF annotations on export regardless of the user's preference.

convertOfficeToPDFRestricted

checkbox, false

Prevent users from converting Office documents to PDF.

blackberry.security.EnableDLPWatermark

checkbox, false

DLP watermark: overlay user identity on documents to deter leaks and support forensic attribution. (*BlackBerry only)

Sharing

Policy ID

Type and default

Definition

allowHashedSharing

checkbox, true

Allow users to securely share folders with other internal users. Sharing applies to Notate Drive and Exchange folders.

Notes and handwriting

Policy ID

Type and default

Definition

allowAnnotations

checkbox, true

Allow annotations on notes.

annotationCompression

select, 2

Handwriting compression level: 2 = High, 3 = Low, 4 = None.

allowCamera

checkbox, true

Allow the device camera to insert pictures into notes.

allowGallery

checkbox, true

Allow users to paste images from the photo gallery.

allowGeoTag

checkbox, true

Allow notes to be tagged with location. BlackBerry spells the key allowGeotag; lookups are case-insensitive.

allowHyperlinks

checkbox, true

Allow hyperlinks in notes to be followed.

allowVoiceRecordings

checkbox, true

Allow users to attach voice recordings to notes.

allowWebClippings

checkbox, true

Allow users to insert web clippings into notes.

allowAttachments

checkbox, true

Allow users to insert documents into notes.

allowTextBoxes

checkbox, true

Allow users to insert text boxes into notes.

allowDocumentScanner

checkbox, true

Allow users to scan paper documents with the device camera. Requires allowCamera.

Exchange connection

These policies apply when Notate reaches Exchange through Exchange Web Services: for Exchange on-premises customers, and for Exchange Online customers until Notate Drive moves to OneDrive.

Policy ID

Type and default

Definition

exchangeURL

text, max 256

Explicit EWS URL, required only when autodiscovery is not possible. Format https://server.domain.com/EWS/Exchange.asmx. The Intune file ships pre-set to the Microsoft 365 endpoint.

autodiscoveryURLs

text, max 256

Custom autodiscovery URLs; not required if they are in the standard locations. Separate multiple URLs with a semicolon and no space.

disablePeerVerification

checkbox, true

Permit local or private TLS certificates on Exchange.

trustedCertificates

text, max 2048

One or more trusted server certificates as SHA-1 hashes in hex, separated by comma or semicolon. (*BlackBerry only)

User identity

These policies carry your MDM's own substitution macros, so each user receives their own value.

Policy ID

Default

Definition

userEmail

AppConfig and Ivanti: emailAddress variable; Intune: {{mail}}; Citrix: blank

The user's email address, pre-filled by the MDM. (*All except BlackBerry)

userName

see definition

Pre-filled user name; leave blank to let the user enter their own. BlackBerry: $USER$ (username from the UPN) or $UPN$, optionally prefixed with a domain. Intune: {{username}}. AppConfig and MobileIron: the sAMAccountName variable.

IntuneMAMUPN

{{userprincipalname}}

The user's UPN, required by the Intune MAM SDK for app protection enrollment. Not a Notate feature switch. (*Intune only)

Device security

Policy ID

Type and default

Definition

SSPassCodeStyle

select, None

Type of passcode the application requires: None, Digits (simple) or Alpha (complex). (*AppConfig and Ivanti (MobileIron) only)

SSClipboardIsRestricted

boolean, true

Prevent data leaving the application through the iOS clipboard. (*AppConfig and Ivanti (MobileIron) only)

allowiOSEmail

checkbox, false

Allow users to email notes using the native iOS mail client. Off by default because it moves content out of the managed container. (*AppConfig, Ivanti (MobileIron) and Intune only)

Intune, Citrix and BlackBerry provide the equivalent controls through their own container policies.

Deprecated features

These features come from Notate's original personal-information-manager identity and are retired in Notate 2026. allowDeprecatedFeatures must be on for any of the individual switches to take effect; enabling allowTasks on its own does nothing. With the master switch off, which is the default, none of them appear. They are available only while a user’s Notate Drive is in Exchange.

When notateDriveMode is anything other than ews, these features are hidden regardless of the switches below, because their data lives in the Exchange mailbox. They remain available to Exchange-backed users (mode ews) for as long as that storage is in use.

Policy ID

Type and default

Definition

allowDeprecatedFeatures

checkbox, false

Master switch. Must be on for any individual deprecated feature below to apply.

allowTasks

checkbox, true

Tasks. Recommended replacement: Microsoft To Do, included in Microsoft 365.

allowContacts

checkbox, true

Contacts. Business-card workflows: TheLastBusinessCard.com.

allowAICardRecognition

checkbox, false

AI business-card recognition. Applies only when legacy Contacts is enabled.

allowCalendar

checkbox, true

Calendar. Use the native Microsoft calendar app on each platform.

Tasks, Contacts and Calendar default to on so that an administrator who turns the master switch on gets the familiar feature set without enabling each one individually.

Last updated: