Exchange Online customers: Microsoft is retiring Exchange Web Services. Here is what administrators need to do.
Notate Resource Center

SharePoint Embedded resource kit

Everything Notate-specific that your administrators need to set up SharePoint Embedded for Notate 2026. Download the files here; the step-by-step procedure is in Setting Up Container Provisioning.

The Microsoft-side prerequisites (tenant, Azure subscription, pay-as-you-go billing, admin consent) are covered in the Deployment Readiness Guide below and need nothing from this kit.

Files

File

What it is

Used in

main.bicep

Azure deployment template. Creates the provisioning function (Consumption plan), its storage account, Application Insights and a system-assigned managed identity in the resource group you choose. Deployed with az deployment group create in Azure Cloud Shell.

Provisioning Step 2

notate-provisioning.zip

The provisioning function's code package. Deployed to the function with az functionapp deployment source config-zip. It creates a user's container on first use and never reads document content.

Provisioning Step 2

Set-NotateContainerTypeRegistration.ps1

PowerShell script that registers Notate's container type in your tenant and grants the provisioning application create, read, write and delete on the container object only. Runs on an administrator's own machine (PowerShell 7 or Windows PowerShell 5.1 with the Microsoft.Graph.Authentication module), shows the permissions it will write, and asks for confirmation. Safe to re-run.

Provisioning Step 4

Notate 2026 Deployment Readiness Guide (PDF)

The checklist of what to have in place before a trial or rollout begins: roles, subscription, billing, consent, and what we send you.

Before you start

IntuneConfig.xmlNotate_2026_Deployment_Readiness_Guide.pdfspe_deployment_kit.zip


Fixed identifiers, the same for every customer

Name

Value

Notate application ID (iOS, Android, Mac, Windows)

215843d3-1ef5-43d0-9b0f-76d16094ae79

Notate container type ID

9620194f-2626-4430-904a-b52089f9f4e0

Values you will produce

Value

Where it comes from

Where it is used

Provisioning app ID

Step 1 (Entra app registration)

Steps 2, 3, 4, 5 and the MDM value NotateProvisioningAppId

functionPrincipalId

Step 2 deployment output

Step 3 (federated credential)

provisioningEndpoint

Step 2 deployment output

The MDM value NotateProvisioningEndpoint

Before a security review

Your security team will want to know: the service runs in your Azure, under your control; the provisioning application holds exactly one delegated Graph permission and no application permissions; the credential that reaches SharePoint Embedded is keyless (a managed-identity federated credential); the service cannot read or write document content; and you choose who may be provisioned through standard Entra assignment, which composes with your Conditional Access and access-review policies. The "Security Model" section of the provisioning chapter is written for that review.

Help

We are glad to run the 30-minute provisioning procedure live with your Azure and Entra administrators. Write to support@shafersystems.com.

Last updated: