Every Notate capability an administrator can control is delivered to the app as an application policy published by your mobile device management platform. Notate ships a configuration file for each supported platform. Import the file for your platform, set the values your organization needs, and assign the configuration to the Notate app. Policies reach the device the next time your MDM checks in, and the app applies them the next time the user signs in. The policies are the same in every edition.
Supported management platforms
|
Platform |
Configuration file |
|---|---|
|
BlackBerry UEM |
Edit in the UEM console |
|
Generic AppConfig |
|
|
MobileIron / Ivanti |
|
|
Microsoft Intune |
|
|
Citrix / XenMobile |
Edit in the XenMobile console after importing the MDX file |
The configuration files are on the pages under Deploy with your MDM.
License and support
|
Policy ID |
Type and default |
Definition |
|---|---|---|
|
|
text, max 2048 |
Product license key. Contact sales@shafersystems.com to retrieve your key. Determines which licensed features are available to the user. |
|
|
checkbox, true |
Allow reporting of crash logs to Shafer Systems. |
|
|
checkbox, true |
Allow users to enable verbose diagnostic logging to assist in debugging. |
|
|
text, support@shafersystems.com |
Address where user feedback and debug logs are submitted. Point it at your own help desk to triage internally first. |
|
|
text, https://links.notatepro.com/support/home |
URL for the in-application support page. |
|
|
text, https://links.notatepro.com/support/learning |
URL for the Notate learning center page. |
Branding
New in Notate 2026. You can put your organization’s logo and name in Notate, so your users see at a glance that this is your firm’s own, IT-managed app. They appear in the header at the top of Notate’s navigation panel:
|
What you see |
Policy |
|---|---|
|
The logo (“CONTOSO” with its mark) |
|
|
The name on the right (“Contoso”) |
|
|
The header’s background color (teal here) |
|
|
The color of the name (white here) |
|
Notate stays in the background: “Powered by Notate” appears in small type at the foot of the same panel.
All four policies are optional. Leave them blank and Notate keeps its standard look. The logo is fetched from the URL you give, so use an address your users’ devices can reach.
|
Policy ID |
Type and default |
Definition |
|---|---|---|
|
|
text, max 1024 |
URL of your company logo. |
|
|
text, max 256 |
Optional company name displayed alongside the logo. |
|
|
text, max 64 |
Background color behind the company logo, as a hex value such as #1F2A44. |
|
|
text, max 64 |
Foreground color for the company name text, as a hex value such as #FFFFFF. |
Notate Drive
Notate Drive is each user’s own place in Notate for their notes, documents and folders. For Microsoft 365 customers it lives in the user’s own OneDrive; for Exchange on-premises customers it stays in the user’s mailbox. Either way it stays inside your organization, under your own retention, DLP and governance policies. See Notate Drive and OneDrive.
|
Policy ID |
Type and default |
Definition |
|---|---|---|
|
|
select, |
Where Notate Drive lives: |
|
|
checkbox, true |
Authenticate against Microsoft 365 / Entra ID using OAuth. Named |
|
|
checkbox, true |
When using modern authentication, allow sign-in through the Microsoft Authenticator app. |
|
|
Meaning |
|---|---|
|
|
Notate Drive stays in the user’s Exchange mailbox. For Exchange on-premises, and for Exchange Online customers who have not moved yet. |
|
|
Copy Notate Drive from Exchange to the user’s OneDrive, then run on OneDrive. For existing Exchange Online customers. |
|
|
Notate Drive in the user’s OneDrive, with nothing moved. For new Microsoft 365 customers. |
|
|
Copy Notate Drive from Exchange Online to SharePoint Embedded. Only for customers who already use SharePoint Embedded. |
|
|
SharePoint Embedded, with nothing moved. Only for customers who already use SharePoint Embedded. |
Customers who use SharePoint Embedded also set two provisioning policies. They are listed on Notate and SharePoint Embedded.
Corporate document repositories
|
Policy ID |
Type and default |
Definition |
|---|---|---|
|
|
checkbox, true |
Allow users to open and edit documents from email attachments. |
|
|
checkbox, true |
Allow users to return edited email attachments to the sender. |
|
|
checkbox, true |
Allow users to read and write files in Microsoft OneDrive. |
|
|
checkbox, true |
Allow users to read and write files in Microsoft SharePoint. |
|
|
checkbox, true |
Allow users to read and write files in Microsoft Teams. |
|
|
checkbox, false (Citrix: true) |
Allow users to read and write files in ShareFile (Citrix Files). Off by default except in the Citrix edition. |
|
|
checkbox, false |
Allow users to read and write files in BlackBerry Workspaces. BlackBerry UEM only; beta in this release. (*BlackBerry only) |
|
|
text, max 256 |
BlackBerry Workspaces server URL. Required when |
|
|
checkbox, true |
Allow users to read and write files on SMB network drives (Windows file shares). How to set them up, including Kerberos and the network path the app needs: Network drives (SMB file shares). |
|
|
text, max 1024 |
The shares users see, comma-separated. Each entry is a path followed by an optional friendly name after a vertical bar: |
|
|
checkbox, false |
Authentication for network drives: false uses NTLM, true uses Kerberos. Kerberos also needs |
|
|
textarea, max 4096 |
Your krb5.conf file, Base64-encoded into a single line. Required when |
|
|
text, max 256 |
Full URL to the BEMS server including port, for example |
Notate AI
Notate AI runs against your own Azure OpenAI resource. No prompt or document content reaches Shafer Systems. Setup is in Notate AI features: setup on your own Azure OpenAI resource; this is the policy reference.
|
Policy ID |
Type and default |
Definition |
|---|---|---|
|
|
checkbox, true |
Master switch. Must be on for any Notate AI feature to be available: PDF create and edit via AI, document Q&A, meeting audio transcription and summary, handwriting to text. Nothing is active until the endpoint policies below are also set. How to set it up: Notate AI features: setup on your own Azure OpenAI resource. |
|
|
text, max 256 |
Base endpoint URL of your Azure OpenAI resource. |
|
|
text, max 256 |
Deployment name assigned to the model in Azure AI Foundry / Azure OpenAI Studio (the deployment name, not the model name). |
|
|
text, max 64 |
Azure OpenAI REST API version to target, for example 2024-10-21. |
|
|
text, max 256 |
Token audience override. Older resources use |
|
|
text, max 256 |
Audio transcription endpoint. |
|
|
text, max 256 |
Audio transcription model deployment name. |
|
|
text, max 64 |
Audio transcription REST API version. |
Document editing and data loss prevention
|
Policy ID |
Type and default |
Definition |
|---|---|---|
|
|
checkbox, true (Intune: false) |
Allow editing of Word, Excel and PowerPoint documents with Notate's built-in editors. Off by default on Intune, where Microsoft Office is expected to handle Office formats. |
|
|
checkbox, true |
Allow opening Word, Excel and PowerPoint documents in the native Microsoft Office apps. |
|
|
checkbox, true |
Allow editing original PDF text directly in Notate. |
|
|
checkbox, true |
Allow digitally signing PDF documents using MDM-issued certificates. |
|
|
checkbox, true |
Allow redacting sensitive, confidential and privileged information from PDFs. |
|
|
checkbox, false |
Flatten PDF annotations on export regardless of the user's preference. |
|
|
checkbox, false |
Prevent users from converting Office documents to PDF. |
|
|
checkbox, false |
DLP watermark: overlay user identity on documents to deter leaks and support forensic attribution. (*BlackBerry only) |
Sharing
|
Policy ID |
Type and default |
Definition |
|---|---|---|
|
|
checkbox, true |
Allow users to securely share folders with other internal users. Sharing applies to Notate Drive and Exchange folders. |
Notes and handwriting
|
Policy ID |
Type and default |
Definition |
|---|---|---|
|
|
checkbox, true |
Allow annotations on notes. |
|
|
select, 2 |
Handwriting compression level: 2 = High, 3 = Low, 4 = None. |
|
|
checkbox, true |
Allow the device camera to insert pictures into notes. |
|
|
checkbox, true |
Allow users to paste images from the photo gallery. |
|
|
checkbox, true |
Allow notes to be tagged with location. BlackBerry spells the key |
|
|
checkbox, true |
Allow hyperlinks in notes to be followed. |
|
|
checkbox, true |
Allow users to attach voice recordings to notes. |
|
|
checkbox, true |
Allow users to insert web clippings into notes. |
|
|
checkbox, true |
Allow users to insert documents into notes. |
|
|
checkbox, true |
Allow users to insert text boxes into notes. |
|
|
checkbox, true |
Allow users to scan paper documents with the device camera. Requires |
Exchange connection
These policies apply when Notate reaches Exchange through Exchange Web Services: for Exchange on-premises customers, and for Exchange Online customers until Notate Drive moves to OneDrive.
|
Policy ID |
Type and default |
Definition |
|---|---|---|
|
|
text, max 256 |
Explicit EWS URL, required only when autodiscovery is not possible. Format |
|
|
text, max 256 |
Custom autodiscovery URLs; not required if they are in the standard locations. Separate multiple URLs with a semicolon and no space. |
|
|
checkbox, true |
Permit local or private TLS certificates on Exchange. |
|
|
text, max 2048 |
One or more trusted server certificates as SHA-1 hashes in hex, separated by comma or semicolon. (*BlackBerry only) |
User identity
These policies carry your MDM's own substitution macros, so each user receives their own value.
|
Policy ID |
Default |
Definition |
|---|---|---|
|
|
AppConfig and Ivanti: emailAddress variable; Intune: |
The user's email address, pre-filled by the MDM. (*All except BlackBerry) |
|
|
see definition |
Pre-filled user name; leave blank to let the user enter their own. BlackBerry: |
|
|
|
The user's UPN, required by the Intune MAM SDK for app protection enrollment. Not a Notate feature switch. (*Intune only) |
Device security
|
Policy ID |
Type and default |
Definition |
|---|---|---|
|
|
select, None |
Type of passcode the application requires: None, Digits (simple) or Alpha (complex). (*AppConfig and Ivanti (MobileIron) only) |
|
|
boolean, true |
Prevent data leaving the application through the iOS clipboard. (*AppConfig and Ivanti (MobileIron) only) |
|
|
checkbox, false |
Allow users to email notes using the native iOS mail client. Off by default because it moves content out of the managed container. (*AppConfig, Ivanti (MobileIron) and Intune only) |
Intune, Citrix and BlackBerry provide the equivalent controls through their own container policies.
Deprecated features
These features come from Notate's original personal-information-manager identity and are retired in Notate 2026. allowDeprecatedFeatures must be on for any of the individual switches to take effect; enabling allowTasks on its own does nothing. With the master switch off, which is the default, none of them appear. They are available only while a user’s Notate Drive is in Exchange.
When notateDriveMode is anything other than ews, these features are hidden regardless of the switches below, because their data lives in the Exchange mailbox. They remain available to Exchange-backed users (mode ews) for as long as that storage is in use.
|
Policy ID |
Type and default |
Definition |
|---|---|---|
|
|
checkbox, false |
Master switch. Must be on for any individual deprecated feature below to apply. |
|
|
checkbox, true |
Tasks. Recommended replacement: Microsoft To Do, included in Microsoft 365. |
|
|
checkbox, true |
Contacts. Business-card workflows: TheLastBusinessCard.com. |
|
|
checkbox, false |
AI business-card recognition. Applies only when legacy Contacts is enabled. |
|
|
checkbox, true |
Calendar. Use the native Microsoft calendar app on each platform. |
Tasks, Contacts and Calendar default to on so that an administrator who turns the master switch on gets the familiar feature set without enabling each one individually.