Exchange Online customers: Microsoft is retiring Exchange Web Services. Here is what administrators need to do.
Notate Resource Center

Prerequisites and Microsoft Entra ID permissions

For Microsoft 365 customers. If your users’ mailboxes are on Exchange Server on-premises, this page does not apply to you.

What your Microsoft 365 environment needs before Notate can use it, and how to authorize Notate in Microsoft Entra ID.

Prerequisites

Requirement

Details

Microsoft 365 tenant

An active Microsoft 365 tenant with OneDrive.

OneDrive for each Notate user

Each user's OneDrive must be provisioned. Microsoft creates it the first time the user opens OneDrive, unless you provision it in advance.

An administrator who can grant consent

An account that can grant tenant-wide admin consent to an application in Microsoft Entra ID, such as a Global Administrator.

Nothing else is needed: no Azure subscription, no server software and no additional Microsoft charges. If your organization uses SharePoint Embedded with Notate, see Notate and SharePoint Embedded for what it needs in addition.

Granting Notate permissions in Microsoft Entra ID

Before users can connect to Microsoft 365, an administrator must authorize Notate as an enterprise application and grant the Microsoft Graph and SharePoint permissions below.

First-time authorization

The simplest approach: an administrator launches Notate on any device, signs in with their admin account, and consents to the requested permissions when prompted. After that, every user in the organization can sign in without a permissions error. If a user tries to sign in before an administrator has consented, they see an authorization error. Nothing is needed from the user; have an administrator complete the consent first.

Manual configuration (optional)

  1. In the Azure portal, open Microsoft Entra ID and select Enterprise Applications.

  2. Select New Application and search for Notate, or add it by application ID: 215843d3-1ef5-43d0-9b0f-76d16094ae79. The same ID applies to Notate on iOS, Android, Mac and Windows.

  3. Open Permissions and grant admin consent for the permissions listed below.

You can also grant consent from this URL, replacing the placeholder with your tenant ID: https://login.microsoftonline.com/<your-tenant-id>/adminconsent?client_id=215843d3-1ef5-43d0-9b0f-76d16094ae79

Required permissions

All permissions are delegated. The mail permissions carry the same capabilities Notate previously used through EWS, now routed through Microsoft Graph. The openid, profile and offline_access permissions serve Notate Web and desktop.

Microsoft Graph

Permission

Purpose

Files.ReadWrite.All

Read and write files in the user's OneDrive, including Notate Drive.

Group.Read.All

List SharePoint and Teams sites the user has access to.

Sites.ReadWrite.All

Read and write to SharePoint sites the user has access to.

Teams.ReadBasic.All

Access files shared within Teams channels and chats.

User.Read

Retrieve the user's profile and enumerate accessible Teams and SharePoint resources.

offline_access

Lets Notate renew short-lived access tokens in the web and desktop client.

openid

Lets the user sign in with their Microsoft Entra ID identity.

profile

Shows who is signed in and attributes their work, for example putting their name on PDF comments.

Microsoft Graph mail

Permission

Purpose

Mail.Read

Display email attachments for editing.

Mail.ReadWrite

Reply to emails with edited attachments.

Mail.Send

Send emails with edited attachments.

SharePoint

Permission

Purpose

MyFiles.Read

Read files from the user's SharePoint folders.

MyFiles.Write

Write files to the user's SharePoint folders.

Microsoft Office 365 Exchange Online (legacy)

Permission

Purpose

EWS.AccessAsUser.All

Reads and writes Notate Drive in the user's Exchange mailbox. Needed while users are still on Exchange Online and while Notate Drive moves to OneDrive; not needed once every user has moved.

Microsoft Cognitive Services (only if you enable Notate AI)

Permission

Purpose

Microsoft Cognitive Services (delegated)

Used for classic Azure OpenAI resources.

Azure Machine Learning Services (delegated)

Used for native Azure AI Foundry resources.

Next chapter: Notate Drive and OneDrive.

Last updated: