Everything Notate-specific that your administrators need to set up SharePoint Embedded for Notate 2026. Download the files here; the step-by-step procedure is in Setting Up Container Provisioning.
The Microsoft-side prerequisites (tenant, Azure subscription, pay-as-you-go billing, admin consent) are covered in the Deployment Readiness Guide below and need nothing from this kit.
Files
|
File |
What it is |
Used in |
|---|---|---|
|
|
Azure deployment template. Creates the provisioning function (Consumption plan), its storage account, Application Insights and a system-assigned managed identity in the resource group you choose. Deployed with |
Provisioning Step 2 |
|
|
The provisioning function's code package. Deployed to the function with |
Provisioning Step 2 |
|
|
PowerShell script that registers Notate's container type in your tenant and grants the provisioning application create, read, write and delete on the container object only. Runs on an administrator's own machine (PowerShell 7 or Windows PowerShell 5.1 with the Microsoft.Graph.Authentication module), shows the permissions it will write, and asks for confirmation. Safe to re-run. |
Provisioning Step 4 |
|
Notate 2026 Deployment Readiness Guide (PDF) |
The checklist of what to have in place before a trial or rollout begins: roles, subscription, billing, consent, and what we send you. |
Before you start |
IntuneConfig.xmlNotate_2026_Deployment_Readiness_Guide.pdfspe_deployment_kit.zip
Fixed identifiers, the same for every customer
|
Name |
Value |
|---|---|
|
Notate application ID (iOS, Android, Mac, Windows) |
|
|
Notate container type ID |
|
Values you will produce
|
Value |
Where it comes from |
Where it is used |
|---|---|---|
|
Provisioning app ID |
Step 1 (Entra app registration) |
Steps 2, 3, 4, 5 and the MDM value |
|
|
Step 2 deployment output |
Step 3 (federated credential) |
|
|
Step 2 deployment output |
The MDM value |
Before a security review
Your security team will want to know: the service runs in your Azure, under your control; the provisioning application holds exactly one delegated Graph permission and no application permissions; the credential that reaches SharePoint Embedded is keyless (a managed-identity federated credential); the service cannot read or write document content; and you choose who may be provisioned through standard Entra assignment, which composes with your Conditional Access and access-review policies. The "Security Model" section of the provisioning chapter is written for that review.
Help
We are glad to run the 30-minute provisioning procedure live with your Azure and Entra administrators. Write to support@shafersystems.com.