Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion docs/embedded/admin/admin-overview.md
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
---
title: Admin Overview
title: Admin overview
description: Learn how administrators manage SharePoint Embedded apps, containers, billing, and compliance in Microsoft 365.
ms.date: 07/13/2026
ms.reviewer: shsaravanan
Expand Down
10 changes: 5 additions & 5 deletions docs/embedded/admin/apply-security-compliance-controls.md
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
---
title: Apply Security and Compliance Controls
title: Apply security and compliance controls
description: Apply Microsoft Purview and SharePoint controls to protect and govern SharePoint Embedded content.
ms.date: 07/13/2026
ms.reviewer: dilucesr
Expand All @@ -14,7 +14,7 @@ ai-usage: ai-assisted

<!-- agent:
task_type: how-to
audience: compliance
audience: administrator
outcome: Apply supported Microsoft Purview and SharePoint controls to SharePoint Embedded containers and content.
next: ../reference/troubleshooting.md
-->
Expand All @@ -23,7 +23,7 @@ Apply security and compliance controls to SharePoint Embedded content by using M

SharePoint Embedded uses Microsoft 365 compliance and data governance capabilities so organizations can protect, govern, and investigate content stored by embedded applications.

Some compliance scenarios require the owning application to provide the end-user experience because SharePoint Embedded is API-only and doesn't have its own user interface.
Some compliance scenarios require the owning application to provide the user experience because SharePoint Embedded is API-only and doesn't have its own user interface.

> [!IMPORTANT]
> Coordinate compliance controls with the SharePoint Embedded app owner.
Expand Down Expand Up @@ -124,7 +124,7 @@ Use selected container URLs when a policy applies only to specific data.
![Microsoft Purview retention policy scoped to selected SharePoint Embedded container URLs.](../images/sc5.png)

> [!NOTE]
> SharePoint Embedded doesn't provide a native end-user interface for retention label interactions.
> SharePoint Embedded doesn't provide a native user interface for retention label interactions.
> If users need to apply or respond to retention labels in an app, the owning app must provide that experience.

For Microsoft Purview Data Lifecycle Management, see [Learn about Microsoft Purview Data Lifecycle Management](/purview/data-lifecycle-management).
Expand Down Expand Up @@ -184,7 +184,7 @@ For label concepts, see [Learn about sensitivity labels](/purview/sensitivity-la
SharePoint Administrators and Global Administrators can block file downloads from SharePoint Embedded containers with the SharePoint site policy cmdlet.

```powershell
Set-SPOSite -Identity <ContainerSiteURL> -BlockDownloadPolicy $true
Set-SPOContainer -Identity <ContainerSiteURL> -BlockDownloadPolicy $true
```

A SharePoint Advanced Management license is needed to enforce this policy.
Expand Down
26 changes: 13 additions & 13 deletions docs/embedded/admin/consuming-tenant-admin.md
Original file line number Diff line number Diff line change
Expand Up @@ -12,7 +12,7 @@ ai-usage: ai-assisted
**Applies to:** Consuming tenant admin — SharePoint Embedded admin / Global admin

> [!IMPORTANT]
> Assign the SharePoint Embedded Administrator role available in Microsoft 365 Admin Center or Microsoft Entra ID to execute SharePoint Embedded Container cmdlets mentioned in this article.
> Assign the SharePoint Embedded Administrator role available in Microsoft 365 admin center or Microsoft Entra ID to execute SharePoint Embedded Container cmdlets mentioned in this article.
>
> Global Administrators can continue to execute SharePoint Embedded container cmdlets.
>
Expand All @@ -27,13 +27,13 @@ outcome: Understand the consuming tenant administrator role and the admin tools
next: install-sharepoint-embedded-app.md
-->

## Consuming Tenant Admin Role
## Consuming tenant admin role

Microsoft 365 SharePoint Embedded Administrator serves as the consuming tenant admin. Global Administrators in Microsoft 365 can assign users the SharePoint Embedded Administrator role. The Global Administrator role already has all the permissions of the SharePoint Embedded Administrator role. The SharePoint Embedded Role is available in Microsoft Entra ID and Microsoft 365 Admin Center.
Microsoft 365 SharePoint Embedded Administrator serves as the consuming tenant admin. Global Administrators in Microsoft 365 can assign users the SharePoint Embedded Administrator role. The Global Administrator role already has all the permissions of the SharePoint Embedded Administrator role. The SharePoint Embedded Administrator role is available in Microsoft Entra ID and Microsoft 365 admin center.

For information on the SharePoint Embedded Administrator role, see [Admin overview](admin-overview.md).

## Administration Tools
## Administration tools

Consuming tenant admins can manage SharePoint Embedded applications with the following options:

Expand All @@ -52,16 +52,16 @@ On PowerShell, the SharePoint Embedded Admin can run the following cmdlets:

1. Enumerate applications in a tenant
1. Enumerate containers of an application in a tenant
1. Enumerate containers of an application sorted by storage basis storage
1. Enumerate containers of an application sorted by storage usage
1. Enumerate archived containers of an application
1. Edit the sensitivity label on a container
1. Set the sharing capability configuration on a container

For information on consuming tenant admin in PowerShell, see [Manage containers with PowerShell](manage-containers-powershell.md).

### SharePoint Administrator Center
### SharePoint admin center

The SharePoint Embedded Admin can access the Active and Deleted containers page on SPAC and perform SharePoint Embedded application-level and container-level actions. This includes the following:
The SharePoint Embedded Admin can access the Active and Deleted containers page in the SharePoint admin center and perform SharePoint Embedded application-level and container-level actions. This includes the following:

1. View the Active container page
1. View the Archived container page
Expand All @@ -78,13 +78,13 @@ SharePoint Embedded uses Microsoft’s comprehensive compliance and data governa

## Set up billing for pass-through container type

To use a pass-through billing SharePoint Embedded app, the SharePoint Embedded admin needs to set up Microsoft Syntex billing in the [Microsoft 365 admin center](https://admin.microsoft.com/). No user can access any pass-through SharePoint Embedded apps before valid billing is set up for the SharePoint Embedded platform.
To use a pass-through billing SharePoint Embedded app, a Global Administrator needs to set up Microsoft Syntex billing in the [Microsoft 365 admin center](https://admin.microsoft.com/). The SharePoint Embedded Administrator role can't configure billing. No user can access any pass-through SharePoint Embedded apps before valid billing is set up for the SharePoint Embedded platform.

### [Meters](../reference/billing-meters.md)

SharePoint Embedded employs a pay-as-you-go (PAYG) billing model through an Azure subscription. Billing is determined by how much data in GB you store in SharePoint Embedded in active and archived states, transactions used to access and modify the container and container contents, and data that's egressed from the SharePoint Embedded platform. Each of these factors contributes to the overall cost, ensuring that you only pay for the resources and services you use. You can view this usage and billing details in the [Microsoft Cost Management](https://portal.azure.com/).

SharePoint Embedded has three billing meters, as shown. Refer to the [product page](https://adoption.microsoft.com/en-us/sharepoint/embedded/) for pricing details
SharePoint Embedded has four billing meters, as shown. Refer to the [product page](https://adoption.microsoft.com/en-us/sharepoint/embedded/) for pricing details.

| SharePoint Embedded Service Meters | Meter Unit |
| ---------------------------------- | -------------- |
Expand All @@ -93,7 +93,7 @@ SharePoint Embedded has three billing meters, as shown. Refer to the [product pa
| API Transactions | $/Transactions |
| Egress | $/GB |

### Set Up Guide
### Set up guide

1. A valid Azure subscription is required. You can create one by following the steps here to [create an Azure subscription](/azure/cloud-adoption-framework/ready/azure-best-practices/initial-subscriptions).
1. A valid Azure resource group is required. You can create one by following the steps here to [create a resource group](/azure/azure-resource-manager/management/manage-resource-groups-portal).
Expand All @@ -106,15 +106,15 @@ SharePoint Embedded has three billing meters, as shown. Refer to the [product pa

![Microsoft 365 admin center SharePoint Embedded Billing setting](../images/DTCBilling2.png)

1. Follow the instructions on the **SharePoint Embedded** flyer to turn on SharePoint Embedded apps.
1. Follow the instructions on the **SharePoint Embedded** flyout to turn on SharePoint Embedded apps.

### [Billing management](monitor-usage-billing-cost.md)

The [Microsoft Cost Management portal](https://portal.azure.com/#view/Microsoft_Azure_CostManagement/Menu/~/overview/openedBy/AzurePortal) provides a comprehensive overview of your costs, allowing you to track and analyze your spending for the SharePoint Embedded application. This guide walks you through the steps to view your billing details and SharePoint Embedded consumption in the Microsoft Cost Management portal.

### Invalid Billing/Turn off SharePoint Embedded
### Invalid billing / turn off SharePoint Embedded

If you turn off SharePoint Embedded or disconnect the linked Azure subscription, all users will immediately lose access to any application built on the service along with any read and write permissions.
If you turn off SharePoint Embedded or disconnect the linked Azure subscription, all users immediately lose access to any application built on the service along with any read and write permissions.

## Next steps

Expand Down
4 changes: 2 additions & 2 deletions docs/embedded/admin/create-apps-powershell.md
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,7 @@ ai-usage: ai-assisted

# Create apps with PowerShell

**Applies to:** Owning tenant administrator — SharePoint Embedded admin / Global admin
**Applies to:** Developer tenant administrator — SharePoint Embedded admin / Global admin

<!-- agent:
task_type: how-to
Expand Down Expand Up @@ -49,7 +49,7 @@ Add-SPOContainerTypeBilling -ContainerTypeId <ContainerTypeId> -AzureSubscriptio

## Create a pass-through billed app

Use pass-through billing, also known as direct-to-customer billing, when the consuming tenant pays for SharePoint Embedded usage.
Use pass-through billing when the consuming tenant pays for SharePoint Embedded usage.

```powershell
New-SPOContainerType -IsPassThroughBilling -ContainerTypeName <ContainerTypeName> -OwningApplicationId <OwningApplicationId>
Expand Down
4 changes: 2 additions & 2 deletions docs/embedded/admin/create-apps-sharepoint-admin-center.md
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
---
title: Create Apps in SharePoint Admin Center
title: Create apps in SharePoint admin center
description: Create a SharePoint Embedded app from the SharePoint admin center and validate the new app registration.
ms.date: 07/13/2026
ms.reviewer: shsaravanan
Expand All @@ -10,7 +10,7 @@ ai-usage: ai-assisted

# Create apps in SharePoint admin center

**Applies to:** Owning tenant administrator — SharePoint Embedded admin / Global admin
**Applies to:** Developer tenant administrator — SharePoint Embedded admin / Global admin

<!-- agent:
task_type: how-to
Expand Down
10 changes: 5 additions & 5 deletions docs/embedded/admin/grant-admin-consent-permissions.md
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
---
title: Grant Admin Consent and Permissions
title: Grant admin consent and permissions
description: Review SharePoint Embedded permissions, grant admin consent, and verify the consent state in a consuming tenant.
ms.date: 07/13/2026
ms.reviewer: dilucesr
Expand Down Expand Up @@ -32,7 +32,7 @@ Use this article to review requested permissions, grant consent, and troubleshoo
Confirm these prerequisites:

- You can grant admin consent (see [Grant tenant-wide admin consent](/entra/identity/enterprise-apps/grant-admin-consent?pivots=portal#prerequisites)).
- You know you Microsoft Entra tenant ID (see [How to find your Microsof Entra tenant ID](/entra/fundamentals/how-to-find-tenant))
- You know your Microsoft Entra tenant ID (see [How to find your Microsoft Entra tenant ID](/entra/fundamentals/how-to-find-tenant)).
- You know the owning application client ID.
- You understand why the app needs each requested permission.
- The app owner has provided installation and consent instructions.
Expand Down Expand Up @@ -73,13 +73,13 @@ Before granting consent, review the requested permissions with the app owner.
Ask the app owner to explain any permission that doesn't align with the expected scenario.

> [!CAUTION]
> - DON'T grant consent from a copied URL unless you've verified the `client_id` value in the URL. A consent URL grants permissions to the app identified by that client ID.
> - Don't grant consent from a copied URL unless you've verified the `client_id` value in the URL. A consent URL grants permissions to the app identified by that client ID.
>
> - DON'T grant consent if you don't understand why each permission is being requested.
> - Don't grant consent if you don't understand why each permission is being requested.

## Grant admin consent from the consent endpoint

The SharePoint Embedded may request admin consent on your tenant by providing you with, or redirecting you to, the admin consent URL. To learn more about the admin consent URL, see [Admin consent on the Microsoft identity platform](/entra/identity-platform/v2-admin-consent).
The SharePoint Embedded app may request admin consent on your tenant by providing you with, or redirecting you to, the admin consent URL. To learn more about the admin consent URL, see [Admin consent on the Microsoft identity platform](/entra/identity-platform/v2-admin-consent).

```http
https://login.microsoftonline.com/{your-tenant-id}/v2.0/adminconsent?client_id={owning-app-clientid}&scope=https://graph.microsoft.com/.default&redirect_uri={spe-app-redirect-uri}
Expand Down
6 changes: 3 additions & 3 deletions docs/embedded/admin/manage-containers-powershell.md
Original file line number Diff line number Diff line change
Expand Up @@ -243,9 +243,9 @@ Use `Set-SPOApplicationPermission` for this scenario.

```powershell
Set-SPOApplicationPermission
[[-OwningApplicationId] <OwningApplicationid>]
[[-GuestApplicationId] <GuestApplicationId>]
[[-PermissionAppOnly] <AppOnlyPermission>]
[-OwningApplicationId] <OwningApplicationid>
[-GuestApplicationId] <GuestApplicationId>
[-PermissionAppOnly] <AppOnlyPermission>
[[-PermissionDelegated] <DelegatedPermission>]
```

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -160,6 +160,9 @@ For broader controls, see [Apply security and compliance controls](apply-securit

Archive a container when it's no longer actively used but must be retained for legal, compliance, or business purposes. Documents in an archived container can't be accessed by any user or application until the container is reactivated.

> [!NOTE]
> Container archival relies on Microsoft 365 Archive, which is in preview for SharePoint Embedded. Validate tenant availability, billing, and API behavior before you archive production containers. For more information, see [Archive and restore containers](../build/archive-restore-containers.md).

1. Open **Active containers**.
1. Select the container.
1. Select **Archive**.
Expand Down
2 changes: 1 addition & 1 deletion docs/embedded/admin/monitor-usage-billing-cost.md
Original file line number Diff line number Diff line change
Expand Up @@ -83,7 +83,7 @@ Calls made by internal services to containers aren't charged when the applicatio
Nonchargeable transactions include:

- eDiscovery service queries that search container content for compliance or legal purposes.
- Admin actions taken by SharePoint Embedded Admins or Global Admins through SharePoint admin center or SharePoint PowerShell.
- Admin actions taken by SharePoint Embedded Administrators or Global Administrators through SharePoint admin center or SharePoint PowerShell.

Use app telemetry from the owning application to correlate app releases, user activity, and transaction growth.

Expand Down
2 changes: 1 addition & 1 deletion docs/embedded/admin/review-audit-events.md
Original file line number Diff line number Diff line change
Expand Up @@ -14,7 +14,7 @@ ai-usage: ai-assisted

<!-- agent:
task_type: how-to
audience: compliance
audience: administrator
outcome: Review SharePoint Embedded audit events in Microsoft Purview and use container fields for investigations.
next: apply-security-compliance-controls.md
-->
Expand Down
4 changes: 2 additions & 2 deletions docs/embedded/build/archive-restore-containers.md
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
---
title: Archive and Restore Containers
title: Archive and restore containers
description: Archive inactive SharePoint Embedded containers and reactivate them with Microsoft Graph beta APIs.
ms.date: 07/13/2026
ms.reviewer: jaeccles
Expand All @@ -19,7 +19,7 @@ outcome: Enable archival and call Graph beta archive or unarchive operations.
next: fluid-framework.md
-->

Use SharePoint Embedded container archival when a container must be retained but no longer needs to be active accessed or used for collaboration. Archival uses Microsoft 365 Archive, a cold-storage tier that reduces storage cost while keeping the same security, compliance, and search standards. For the Microsoft 365 Archive overview, see [Microsoft 365 Archive](/microsoft-365/archive/archive-overview).
Use SharePoint Embedded container archival when a container must be retained but no longer needs to be actively accessed or used for collaboration. Archival uses Microsoft 365 Archive, a cold-storage tier that reduces storage cost while keeping the same security, compliance, and search standards. For the Microsoft 365 Archive overview, see [Microsoft 365 Archive](/microsoft-365/archive/archive-overview).

> [!IMPORTANT]
> Microsoft 365 Archive is in Preview for SharePoint Embedded. Validate tenant availability, billing, and API behavior before you expose archive actions to users.
Expand Down
4 changes: 2 additions & 2 deletions docs/embedded/build/configure-authentication-authorization.md
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
---
title: Configure Authentication and Authorization
title: Configure authentication and authorization
description: Configure Microsoft Entra ID authentication and SharePoint Embedded authorization for your application.
ms.date: 07/13/2026
ms.reviewer: cindylay
Expand Down Expand Up @@ -175,7 +175,7 @@ The owning application grants container type application permissions through [co
Any Microsoft Entra user that isn't an external identity can be a container type owner. Owners are managed through the [permissions](/graph/api/filestoragecontainertype-post-permissions) navigation property on the [fileStorageContainerType](/graph/api/resources/filestoragecontainertype) resource. Each entry has the `owner` role and identifies the user through `grantedToV2`.

- **Automatic assignment**: The user who [creates a container type](/graph/api/filestorage-post-containertypes) is automatically assigned as an owner.
- **Add owners**: Use [`POST /containerTypes/{id}/permissions`](/graph/api/filestoragecontainertype-post-permissions) to add up to three owners per container type.
- **Add owners**: Use [`POST /containerTypes/{id}/permissions`](/graph/api/filestoragecontainertype-post-permissions) to add owners. A container type can have at most three owners in total, including the creator who is automatically assigned as the first owner.
- **Remove owners**: Use [`DELETE /containerTypes/{id}/permissions/{id}`](/graph/api/filestoragecontainertype-delete-permissions) to remove an owner.
- **Read owners**: Use [`GET /containerTypes/{id}?$expand=permissions`](/graph/api/filestoragecontainertype-get) or [`GET /containerTypes/{id}/permissions`](/graph/api/filestoragecontainertype-list-permissions) to retrieve owners.

Expand Down
Loading