Skip to main content
Microsoft Solutions Partner — SharePoint · 6,500+ deployments

SharePoint Embedded for ISVs + SaaS Developers (2026)

The Microsoft 365 storage substrate for ISVs and SaaS developers — container architecture, Microsoft Graph APIs, app-only and app-on-behalf-of authentication, Purview governance inheritance, and Microsoft 365 Copilot grounding. Shipped by a senior-architect-led Microsoft Solutions Partner founded in 1997.

What is SharePoint Embedded and why are ISVs building on it? SharePoint Embedded is the Microsoft 365 file-storage substrate for ISV and SaaS applications — partner applications register a container type against the partner Microsoft Entra tenant, customer tenants consent to the partner application, and the partner creates containers per customer entity (account, matter, project, patient, encounter) that live inside the customer Microsoft 365 tenant. Containers are accessed exclusively through Microsoft Graph APIs using either app-only (service-to-service) or app-on-behalf-of (delegated user) authentication. Container content inherits the customer Purview sensitivity labels, DLP policies, Records Management retention, audit log, and eDiscovery scoping, and surfaces in Microsoft Search and Microsoft 365 Copilot grounding inside the customer tenant. ISVs serving legal, healthcare, contract lifecycle, engineering, code-signing, and life sciences regulatory submission use cases ship a Microsoft-native product instead of integrating a generic blob-storage substrate to the customer Microsoft 365 tenant.

SharePoint Embedded is the Microsoft 365 file-storage substrate for ISVs + SaaS developers — containerized storage accessed exclusively via Microsoft Graph APIs, with full Purview governance inheritance (sensitivity labels, DLP, Records Management retention, audit log, eDiscovery) from the customer Microsoft 365 tenant, and native Microsoft Search + Microsoft 365 Copilot grounding. Six ISV use cases anchor adoption: legal tech matter management, healthcare patient documents, contract lifecycle, engineering + design files, code-signing artifacts, and life sciences regulatory submissions. EPC Group ships the five-phase Embedded Accelerator covering container-type design, OAuth integration, container provisioning automation, Purview alignment, and managed Embedded operation under fixed fee $150K to $500K.

Key Facts

  • Container-type architecture — partner application identity registered in partner Entra tenant, consented per customer tenant
  • Containers are pure file-storage partitions — no SharePoint site UI, accessed exclusively via Microsoft Graph APIs
  • OAuth 2.0 app-only (service-to-service) and app-on-behalf-of (delegated user) authentication on the FileStorageContainer.Selected scope
  • Full Purview governance inheritance from customer tenant — sensitivity labels, DLP, retention, audit log, eDiscovery scoping
  • Native Microsoft Search and Microsoft 365 Copilot grounding inside the customer tenant — no custom Copilot connector required
  • Consumption-billed against the partner Microsoft account — storage gigabyte-months + per-operation Graph calls
  • No SharePoint user license required for end users — Embedded entitlement paid by partner Microsoft account
  • Microsoft Solutions Partner founded in 1997, 6,500+ SharePoint deployments, 11,000+ Microsoft engagements
The model

File storage as a service in container format — on the Microsoft 365 backbone

SharePoint Embedded is the answer to a question Microsoft heard repeatedly from ISVs building document-centric SaaS products into Microsoft 365 customers: "Can we have the SharePoint storage substrate without forcing every end user to be SharePoint-licensed?" The answer is Embedded — a containerized storage surface that lives inside the customer Microsoft 365 tenant, exposes the standard Microsoft Graph Drive resource model for access, and meters consumption against the partner Microsoft account instead of requiring per-user SharePoint licensing.

The substrate underneath Embedded is the same SharePoint storage backbone that powers SharePoint Online sites and OneDrive for Business — the same redundancy posture, the same encryption posture, the same regional residency model, the same versioning model, the same large-file optimization. The difference is the access model. Embedded containers have no SharePoint site UI, no list architecture, no page authoring surface, no Teams integration — they are pure file-storage partitions optimized for partner applications calling Microsoft Graph from outside the SharePoint user experience.

The governance posture is fully inherited from the customer Microsoft 365 tenant. Sensitivity labels the customer compliance officer defined in Purview Information Protection apply to container content. DLP policies the customer compliance officer defined apply to container content. Records Management retention applies to container content. The audit log is the same Purview audit log the customer compliance officer already reviews. eDiscovery Premium scoping covers container content. This is the architectural reason ISVs choose Embedded over Amazon S3, Azure Blob, Box, or Dropbox — the customer compliance conversation is already won before the procurement review starts.

Six ISV + SaaS use cases on SharePoint Embedded

EPC Group has modeled SharePoint Embedded patterns across the regulated SaaS landscape — legal tech, healthcare patient portals, contract lifecycle management, engineering and design, software supply chain, and life sciences regulatory submissions. Each use case has a different container-type design, a different authentication model, and a different consumption profile. Most ISVs ship one container type for the v1 product and add a second container type as the product line expands.

Use case 1 — Legal tech document management for matter-bearing SaaS

Legal tech ISVs building matter management, contract lifecycle, or e-discovery products historically chose between Amazon S3 (no governance), iManage or NetDocuments (vendor-controlled stack), or a custom Box or Dropbox integration (no Microsoft identity). SharePoint Embedded gives the legal tech ISV a Microsoft 365 storage substrate where each matter becomes a container, every document inherits the customer tenant Purview sensitivity label, eDiscovery Premium scoping flows through the container natively, and the law firm or in-house legal team sees the matter content searchable inside the firm Microsoft 365 tenant alongside email, Teams, and OneDrive content. The ISV writes no custom DLP, no custom retention, and no custom audit logging — every governance capability the customer compliance officer wants is inherited from the customer Purview baseline. EPC Group has shipped this pattern across legal tech SaaS founders launching matter management products into Am Law 200 firms and Fortune 500 in-house legal departments.

Use case 2 — Healthcare patient document portals + payer member portals

Healthcare ISVs building patient-facing document portals, payer member portals, or clinical documentation exchange products need PHI-grade storage with HIPAA Business Associate Agreement (BAA) coverage, retention aligned to state medical record statutes (six to ten years typical), and audit-log retention that satisfies HHS Office for Civil Rights breach-notification investigations. SharePoint Embedded inherits the customer healthcare-tenant BAA — the ISV does not negotiate its own per-deployment BAA with every payer or hospital customer — and inherits the customer Purview PHI sensitivity labels, DLP policies covering PHI exfiltration, and Records Management retention aligned to the customer state-specific schedule. Patient member portals get a container per patient or per member; clinical documentation exchange gets a container per encounter or per claim. The ISV ships HIPAA-aligned storage without rebuilding the governance stack.

Use case 3 — Contract lifecycle management + commercial agreements SaaS

Contract lifecycle management (CLM) ISVs — Ironclad, Agiloft, Sirion, ContractWorks, plus dozens of younger entrants — have historically shipped on Amazon S3 with custom encryption, custom DLP, custom retention, and custom Microsoft 365 integration. SharePoint Embedded collapses the custom integration layer — every contract becomes a document in a Microsoft 365 container, surfaces natively in Microsoft Search, gets indexed by Microsoft 365 Copilot for grounding, and inherits the customer Purview sensitivity-label scheme that legal and compliance already operates. The CLM ISV pivots from "we built our own Microsoft 365 connector" to "we are a Microsoft 365 storage native" — a meaningful sales conversation with enterprise legal and procurement buyers who prefer Microsoft-native stacks. EPC Group has modeled this pattern for both established CLM vendors evaluating Embedded as a migration path and early-stage CLM founders launching directly on the substrate.

Use case 4 — Engineering, architecture, and design-file SaaS

Engineering, architecture, and design ISVs — AEC project document control, CAD file management, BIM model collaboration, manufacturing engineering change management — store large binary files (PDFs, DWG, RVT, IFC, STEP) with deeply hierarchical project structures, version history, and per-discipline access control. SharePoint Embedded gives the engineering ISV containerized storage per project with full SharePoint version history, Microsoft 365 Copilot grounding for natural-language search across the project corpus ("show me all foundation drawings revised after May"), Purview sensitivity labels on confidential project data, and tenant-native sharing for external consultants without leaving the Microsoft identity perimeter. The ISV avoids rebuilding what SharePoint already does best — versioning, large-file storage, granular permissions — and competes on the engineering domain logic that justifies its product.

Use case 5 — Code-signing artifacts + software supply chain provenance

Code-signing artifact storage, software bill-of-materials (SBOM) repositories, software supply chain attestation services, and CI/CD evidence storage for SOC 2 and FedRAMP audits all require tamper-evident storage with immutable retention, cryptographic chain-of-custody, and long-term audit-log retention. SharePoint Embedded inherits Purview Records Management retention with regulatory-grade lock, sensitivity-label enforcement on the signing artifacts, and audit-log retention that satisfies SOC 2 Trust Services Criteria and FedRAMP Moderate audit-log requirements. The ISV provides the code-signing workflow, attestation chain, and developer experience; the storage substrate and the governance evidence package come from SharePoint Embedded with no custom build. This is a meaningful pattern for security ISVs shipping into the regulated software supply chain compliance market.

Use case 6 — Regulatory submissions + life sciences eCTD storage

Life sciences ISVs building regulatory submission platforms (eCTD, IND, NDA, BLA, MAA, biologic license applications), pharmacovigilance case file storage, and clinical trial master file (TMF) products operate in GxP-regulated environments with 21 CFR Part 11 electronic signature requirements, ALCOA+ data integrity requirements, and 15-to-25-year retention horizons. SharePoint Embedded inherits Purview Records Management with regulator-grade retention lock, audit-log retention aligned to FDA and EMA inspection expectations, Microsoft electronic signature surfaces for Part 11 evidence, and sensitivity labels that prevent unauthorized exfiltration of clinical trial blind data. The life sciences ISV ships GxP-aligned storage on Microsoft 365 instead of rebuilding the validation stack — and inherits the existing GxP qualification work Microsoft has invested in the Microsoft 365 platform.

Container architecture — type, container, drive, app-only, app-on-behalf-of

The Embedded architecture stack is five resources — the container type that identifies the partner application, the container that holds the storage partition, the Drive resource that exposes the storage to Microsoft Graph, and two authentication patterns (app-only and app-on-behalf-of) that govern how the partner application acts. Understanding these five resources up front saves weeks of rework in Phase 3 build.

Container type — the partner application identity

What it is: A SharePoint Embedded container type is the durable definition of an ISV application that wants to store files inside customer Microsoft 365 tenants. The container type is registered against the partner Microsoft Entra tenant, tied to a partner application registration, and consented into each customer tenant through Microsoft Entra admin consent. Once registered, the partner application creates and manages containers of that type in the consenting customer tenants. The container type defines the partner identity for billing — every storage byte and every Graph operation against any container of that type meters to the partner Microsoft account, regardless of which customer tenant the container lives in.

  • Registered in the partner Entra tenant — one container type per ISV application
  • Consented into each customer tenant via Entra admin consent flow
  • Billing identity — all storage and operations meter to the partner Microsoft account
  • Partner application registration owns the Graph API permissions used at runtime
  • Container type versioning supports schema evolution across the partner product lifecycle

Container — the durable storage partition

What it is: A SharePoint Embedded container is the durable storage partition where files actually live. Each container belongs to one customer tenant, holds a coherent set of related files (a customer account, a legal matter, a project, a patient encounter), and is governed by the customer tenant Purview baseline. Containers are NOT SharePoint sites — they have no team site UI, no list architecture, no page authoring surface; they are pure file-storage partitions optimized for partner-application access through Microsoft Graph. Containers carry the customer tenant sensitivity labels, DLP policies, Records Management retention labels, and audit log writes, and surface as searchable content in the customer tenant Microsoft Search and Microsoft 365 Copilot grounding indexes.

  • Pure file-storage partition — no SharePoint site UI surface
  • One container per logical customer entity (account, matter, project, patient)
  • Inherits customer tenant Purview sensitivity labels, DLP, retention, audit
  • Indexed by Microsoft Search and Microsoft 365 Copilot grounding inside the customer tenant
  • Per-container access policy and per-container admin delegation

Drive — the Graph access surface to container content

What it is: Each SharePoint Embedded container exposes a Drive resource — the standard Microsoft Graph Drive resource model — that the partner application uses to create folders, upload files, read files, manage versions, share links, and apply column metadata. The Drive surface is identical to the Microsoft Graph Drive surface that powers OneDrive for Business and SharePoint document libraries, so any existing Microsoft Graph code targeting Drives, DriveItems, folders, and DriveItem content endpoints applies directly. This is the substantial developer-experience advantage of SharePoint Embedded over a custom blob-storage build — the Graph SDK and the Graph documentation and the Graph debugging tooling all just work.

  • Standard Microsoft Graph Drive resource model — same as OneDrive and SharePoint
  • Folder, file, version, sharing-link, and metadata operations through Graph
  • All Microsoft Graph SDKs supported — .NET, JavaScript or TypeScript, Python, Java, PHP, Go
  • Drive operations meter to the partner Microsoft account as per-operation transactions
  • Indexed by Microsoft Search through the standard Graph indexing pipeline

App-only authentication — partner service-to-service access

What it is: App-only authentication is how the partner backend service operates on containers without an interactive user — server-to-server scenarios where the partner SaaS application reads or writes files on behalf of the customer organization. The partner application authenticates against Microsoft Entra using a client credential (certificate or client secret), receives an access token scoped to the container type, and calls Microsoft Graph as the application identity. App-only is the right pattern for ingestion pipelines, background processing, system-of-record synchronization, and backend reporting jobs where there is no interactive user identity to delegate.

  • Service-to-service auth — partner backend acts as application identity
  • Certificate or client secret credentials registered in the partner Entra tenant
  • Scoped FileStorageContainer.Selected permission limits to the container type
  • Suitable for ingestion pipelines, background jobs, and system synchronization
  • No user impersonation — operations log against the application identity in audit

App-on-behalf-of authentication — delegated user access

What it is: App-on-behalf-of authentication is how the partner application acts on behalf of a specific interactive user — typical user-facing partner SaaS scenarios where a customer employee signs into the partner application and operates on files in a container. The partner application uses the OAuth 2.0 on-behalf-of flow to exchange the user access token for a Microsoft Graph token scoped to the container type and the user identity. Graph operations log against the user identity in the customer tenant Purview audit log, sensitivity labels and DLP policies evaluate the user identity, and the customer compliance officer sees the actual user behind every file action — not just the partner application as an opaque service principal.

  • OAuth 2.0 on-behalf-of flow — user signs in, partner acts on the user identity
  • User identity flows through to Purview audit log and DLP policy evaluation
  • Sensitivity-label upgrade and downgrade evaluated against the user identity
  • Right pattern for user-facing partner SaaS where the customer wants user-level audit
  • FileStorageContainer.Selected delegated permission requires user consent
Pricing model

Consumption + storage — how SharePoint Embedded is billed to the partner

SharePoint Embedded is consumption-billed on a hybrid two-meter model — storage measured in gigabyte-months across every container the partner has provisioned and operations measured per Microsoft Graph call against the container Drive. Both meters settle to a single Microsoft invoice on the partner Microsoft account regardless of how many customer tenants the partner serves. The partner application creates the storage; the partner pays for the storage.

Storage meter — gigabyte-months

Every gigabyte of container content accrues storage charges per month. ISVs project storage growth from per-customer-tenant content profile (legal tech matters average X gigabytes, healthcare patient containers average Y megabytes, engineering project containers average Z gigabytes) and total customer-tenant count to forecast the storage meter at year one, year three, and year five.

Operations meter — per Graph call

Every Microsoft Graph call against the container Drive — upload, download, list, metadata write, sharing-link create, version restore — accrues an operation charge. ISVs estimate operations from per-customer-employee daily activity profile (reads per day, writes per day, share-link creates per day) and total active customer employee count.

EPC Group benchmarks Embedded consumption against the 11,000+ engagement portfolio, builds the three-year consumption forecast in Phase 1 of the Accelerator, and structures the partner commercial model so that customer per-seat or per-tenant pricing absorbs the consumption cleanly. Most ISVs find Embedded consumption settles at one to three percent of partner gross revenue at steady state — below the all-in cost of building a custom Amazon S3 plus DLP plus retention plus audit substrate.

Compliance inheritance

HIPAA BAA, FedRAMP alignment, and customer-scope governance inheritance

The compliance posture of SharePoint Embedded is the architectural reason regulated SaaS ISVs choose it over generic blob storage. The customer Microsoft 365 tenant already operates under its own compliance baseline — HIPAA BAA where the customer is a covered entity, FedRAMP-aligned boundary where the customer is in Microsoft 365 GCC, GCC High, or DoD, SOC 2 evidence the customer renews annually, and regulatory audit-log retention the customer compliance officer signed off. Container content inherits all of it, automatically, because the container lives inside the customer tenant.

HIPAA BAA inheritance from customer tenant

Healthcare customer tenants operate under the standard Microsoft BAA covering SharePoint Online and Microsoft 365 services. Container content within the customer tenant is covered by the customer tenant BAA — the partner ISV inherits the chain rather than negotiating per-deployment BAAs with every healthcare customer.

FedRAMP-aligned through customer cloud scope

Federal customer tenants in Microsoft 365 GCC, GCC High, and DoD environments run under the published FedRAMP and DoD IL5 boundary statements. Embedded availability in the sovereign clouds is on the published Microsoft roadmap with continued expansion through 2026; container content inside the sovereign customer tenant inherits the boundary statement.

Purview DLP, retention, and labels

Customer Purview sensitivity labels, DLP policies, and Records Management retention schedules evaluate against container content the same way they evaluate against SharePoint sites and OneDrive content. The partner ISV does not build a separate DLP or retention engine.

Audit log + eDiscovery alignment

Container operations write to the customer Purview audit log; eDiscovery Premium scoping covers container content for litigation hold, custodian management, and review-set tagging. Cross-link to the Purview enterprise data governance guide for the broader baseline.

EPC Group Phase 4 governance hardening produces the partner security attestation package — SOC 2 mapping for the partner application, inherited Microsoft 365 boundary statements for the storage substrate, customer-side admin consent documentation, and the audit evidence package the customer security and privacy officers sign off against HIPAA, SOC 2, FedRAMP, FINRA, CMMC, GxP profiles.

Microsoft 365 native

Microsoft Search + Microsoft 365 Copilot grounding — the differentiator

Container content is indexed by Microsoft Search inside the customer Microsoft 365 tenant automatically — no additional connector configuration, no custom search index, no separate Microsoft Search Graph connector to maintain. Customer employees searching from SharePoint, Microsoft 365 home, Microsoft Search in Bing, or the Microsoft 365 mobile app see partner container content alongside their own SharePoint sites, OneDrive content, Outlook mail, and Teams messages in a single ranked result set.

Microsoft 365 Copilot grounds against the same index — when a customer employee asks Copilot a question that touches partner container content, Copilot pulls relevant container documents into the grounding context, cites them inline, and respects the customer Purview sensitivity labels on the cited content. The ISV gains a substantial competitive position — partner application content appears natively in the customer Microsoft 365 Copilot experience without the partner building a custom Copilot connector, custom semantic index, or custom retrieval-augmented-generation pipeline.

Microsoft Search index

Container content surfaces in Microsoft Search results alongside SharePoint and OneDrive content inside the customer tenant.

Copilot grounding

Microsoft 365 Copilot pulls container content into grounding context and cites it inline in generative responses.

No custom connector

Native Microsoft 365 integration — the partner ISV ships no Graph Search connector and no Copilot plugin to achieve grounding parity.

The EPC Group five-phase SharePoint Embedded Accelerator for ISVs

Fixed-fee delivery in 10 to 16 weeks per partner surface, anchored on the The EPC Group Lifecycle. The engagement covers Assess (container-type + identity + billing model), Design (OAuth + Graph + Purview inheritance + Copilot grounding), Build (partner Graph integration + container provisioning + Copilot connector), Governance Harden (customer consent + Purview alignment + security attestation), and Operate (managed Embedded). Pricing ranges $150K to $500K depending on container-type count, authentication complexity, and the number of integrated customer compliance profiles.

Phase 1 — Assess

Container-type design, identity model, billing model

Phase one selects the container-type architecture — single container type for the whole product, or multiple container types per product surface area, with per-type permission scoping. EPC Group reviews the ISV target customer compliance profile (HIPAA, FedRAMP, SOC 2, GxP), the existing partner Entra tenant posture, the per-container access model (per-tenant, per-account, per-matter, per-project), and the projected per-container storage and operation volumes that drive the consumption-billing forecast. The deliverable is a container-type specification, an identity-and-consent model, and a three-year consumption-billing forecast against EPC Group Lifecycle Assess stage.

  • Container-type catalog with permission scope and per-type lifecycle policy
  • Partner Entra tenant + application registration architecture
  • Per-container storage and operation forecast with three-year consumption-billing model
  • Customer compliance profile inventory — HIPAA, SOC 2, FedRAMP, GxP, FINRA, CMMC
Phase 2 — Design

Auth flows, Graph contract, governance inheritance, Copilot grounding

Phase two designs the OAuth flows (app-only versus app-on-behalf-of versus hybrid), the Microsoft Graph API contract that the partner application will operate against, the Purview inheritance model that ensures customer-tenant sensitivity labels, DLP, and retention all flow through, the Microsoft Search and Microsoft 365 Copilot grounding integration that makes container content discoverable inside the customer Microsoft 365 experience, and the partner-side audit-log forwarding model that surfaces partner application telemetry alongside the customer tenant Purview audit log.

  • OAuth flow design — app-only, app-on-behalf-of, hybrid per partner surface area
  • Microsoft Graph contract spec with rate-limit, retry, and resiliency patterns
  • Purview inheritance model — sensitivity labels, DLP, retention, audit log alignment
  • Microsoft Search + Microsoft 365 Copilot grounding integration design
Phase 3 — Build

Partner Graph integration, container provisioning, Copilot connector

Phase three builds the partner-side Microsoft Graph integration, the container provisioning automation that creates per-customer or per-account containers on customer consent, the Microsoft Search connector that surfaces container content inside the customer tenant Microsoft 365 search experience, the Microsoft 365 Copilot grounding connector that makes container content available to Copilot for generative responses inside the customer tenant, and the partner-side observability — Graph API telemetry, throttling handling, retry logic, error-budget monitoring against the consumption budget.

  • Partner Graph SDK integration with rate-limit, retry, and back-off implementation
  • Container provisioning automation tied to customer consent and lifecycle events
  • Microsoft Search + Microsoft 365 Copilot grounding connector implementation
  • Partner-side telemetry — Graph throttling, error budget, consumption monitoring
Phase 4 — Governance harden

Customer consent, Purview alignment, attestations, audit packs

Phase four hardens the customer-tenant deployment posture — the admin consent experience that customer Microsoft 365 tenant admins see when consenting the partner application, the Purview alignment that ensures customer sensitivity labels and DLP policies and retention schedules all flow through to container content, the security attestation package (SOC 2 mapping, HIPAA BAA chain, FedRAMP boundary statement where applicable) the customer security review will request, and the audit evidence package required for regulator review across HIPAA, SOC 2, FedRAMP, GxP, and CMMC profiles.

  • Customer admin consent experience and tenant-side onboarding documentation
  • Purview alignment validation — labels, DLP, retention flow through to containers
  • Security attestation package — SOC 2 mapping, HIPAA BAA chain, FedRAMP boundary
  • Compliance sign-off with documented control map per regulatory profile
Phase 5 — Operate

Managed Embedded with consumption optimization + senior-architect escalation

Phase five is steady-state operation. EPC Group provides managed SharePoint Embedded services — Graph throttling and rate-limit monitoring, consumption optimization with monthly usage reviews against budget, container lifecycle management as customers churn or expand, Microsoft Graph API change-management as Microsoft evolves the Embedded surface, and senior-architect escalation for partner production incidents that matter. Quarterly governance review with the partner product and security functions. Annual capability roadmap review as Microsoft extends Embedded with new surfaces, new grounding integrations, and new Copilot capabilities.

  • Monthly Graph throttling, error-rate, and consumption-budget reviews
  • Container lifecycle automation as customers onboard, expand, or churn
  • Quarterly governance review with partner product + security stakeholders
  • Annual capability roadmap against Microsoft Embedded feature releases

Why ISVs choose EPC Group for SharePoint Embedded

Senior-architect-led delivery from a 1997-founded Microsoft Solutions Partner with 6,500+ SharePoint deployments, three Microsoft Press SharePoint titles authored by founder Errin O’Connor, and a Fortune 500 portfolio across regulated industries that ISVs ultimately sell into.

6,500+
SharePoint deployments
11,000+
Microsoft engagements
70+
Fortune 500 clients
1997
Founded · Microsoft consulting

Microsoft Solutions Partner — six designations

Modern Work, Data & AI (Azure), Digital & App Innovation, Infrastructure, Security, and Business Applications — the full Microsoft stack coverage required for governed SharePoint Embedded delivery anchored on Microsoft Graph and Purview.

Senior-architect-led delivery

Every ISV engagement is led by a senior Microsoft architect — no junior staff on container-type design, OAuth flow design, or Purview inheritance work. The architects who design your Embedded substrate ship the production deployment.

Microsoft Press SharePoint authorship

Founder Errin O’Connor is a four-time Microsoft Press & Sams author with three SharePoint titles, and brings nearly three decades of Microsoft consulting leadership to every SharePoint Embedded engagement — including the original SharePoint content services architecture work that became the Embedded substrate.

ISV-grade engineering delivery

Senior engineers fluent in Microsoft Graph SDK across .NET, TypeScript or JavaScript, Python, and Java — with production patterns for throttling, retry, idempotency, error budget, and consumption optimization that ISV product teams inherit alongside the architecture work.

Frequently asked questions — SharePoint Embedded for ISVs + SaaS Developers

How is SharePoint Embedded different from Amazon S3, Azure Blob Storage, Box, or Dropbox for ISV file storage?

Amazon S3, Azure Blob, Box, and Dropbox are generic file-storage substrates — the ISV is responsible for building DLP, sensitivity labeling, retention, audit logging, eDiscovery, and the Microsoft 365 integration that enterprise customers want. SharePoint Embedded is a Microsoft 365 storage substrate — files live inside the customer Microsoft 365 tenant, surface in Microsoft Search and Microsoft 365 Copilot grounding, inherit the customer Purview sensitivity-label scheme, inherit the customer DLP policies, inherit the customer Records Management retention schedule, and write to the customer Purview audit log. The ISV ships a Microsoft-native product instead of a Microsoft-integrated product. For enterprise legal, healthcare, financial services, government, and regulated SaaS buyers — most of whom run Microsoft 365 as the system of record for compliance — that is a meaningful competitive position. Cross-link to /microsoft-graph-api-enterprise-2026 for the broader Graph integration architecture.

What is the multi-tenant ISV pattern on SharePoint Embedded?

The multi-tenant ISV pattern registers one container type in the partner Microsoft Entra tenant, publishes the application to the Microsoft Entra app gallery, and walks customer tenant admins through admin consent. Once consented, the partner application creates containers of the registered type inside each customer tenant. Every container is logically isolated inside the customer tenant — the partner application cannot read across customer tenant boundaries, customer-tenant Purview governance fully applies, and customer eDiscovery covers customer container content. The partner application acts either as app-only (service-to-service) or app-on-behalf-of (delegated to interactive customer users) depending on the partner surface area. Billing for all customer-tenant container storage and operations meters back to the partner Microsoft account — the ISV consumes a single Microsoft consumption meter regardless of how many customer tenants they serve. EPC Group has designed this multi-tenant pattern for ISVs serving from 5 to 500 customer tenants on day one.

What regulated SaaS use cases is SharePoint Embedded best suited for?

SharePoint Embedded is best for regulated SaaS use cases where the customer compliance officer wants Microsoft-tenant governance over the partner application content — legal tech matter management, contract lifecycle management, healthcare patient portals and clinical document exchange, life sciences regulatory submission and TMF management, financial services document collaboration and KYC, government contractor document control under CMMC and FedRAMP, code-signing and software supply chain provenance, and engineering and design file management for AEC and manufacturing. The pattern fits any ISV whose customers are Microsoft 365 tenants and whose customer compliance officers care that DLP, sensitivity labels, retention, and audit log all evaluate against the customer Purview baseline. EPC Group has shipped Embedded patterns across HIPAA, SOC 2, FedRAMP, FINRA, CMMC, GxP compliance profiles. Cross-link to /microsoft-purview-data-governance-enterprise-2026 for the Purview baseline architecture.

How does OAuth 2.0 and Microsoft Entra identity work for SharePoint Embedded?

Microsoft Entra identity is the auth backbone for SharePoint Embedded. The partner application registers a Microsoft Entra application in the partner Entra tenant, defines the FileStorageContainer.Selected permission scope (delegated and application variants), and either publishes to the Entra app gallery for multi-tenant consent or enables admin consent inline at customer onboarding. At runtime the partner application acquires a Microsoft Graph access token either through the OAuth 2.0 client credentials flow (app-only — no user, partner backend acts as application identity) or the OAuth 2.0 on-behalf-of flow (delegated — customer user signs in, partner exchanges user token for Graph token). Tokens are scoped to the container type registered against the partner application, and Graph operations are evaluated against the partner application identity and (in delegated mode) the user identity. This is the same Microsoft Entra identity model as any other Microsoft Graph integration — no special Embedded-only identity surface to learn.

How is SharePoint Embedded priced and how does the consumption meter work?

SharePoint Embedded is consumption-billed against the partner Microsoft account — storage measured in gigabyte-months and operations measured per Graph call against the container drive. The meter accrues across every customer tenant where the partner has provisioned containers, but settles to a single partner Microsoft invoice — the ISV does not have to bill each customer tenant separately for the storage substrate. ISVs pass the consumption through to end customers via per-seat or per-tenant pricing, or absorb it into the product margin depending on the commercial model. EPC Group sizes the meter in Phase 1 of the Embedded Accelerator using projected per-container storage growth and per-container monthly operation volume across the customer cohort. For ISVs with substantial expected customer-tenant counts, the consumption meter is typically one to three percent of partner gross product revenue once the product reaches steady-state.

How does SharePoint Embedded integrate with Microsoft Search, Microsoft 365 Copilot, and Copilot grounding?

Container content surfaces in the customer tenant Microsoft Search index automatically — customer employees searching from SharePoint, Microsoft 365 home, Microsoft Search in Bing, or the Microsoft 365 mobile app see container content alongside SharePoint sites, OneDrive content, Outlook mail, and Teams messages. Microsoft 365 Copilot grounds against the same index — when a customer employee asks Copilot a question that touches container content, Copilot pulls relevant container documents into the grounding context and cites them inline. The ISV gains a meaningful competitive position — partner application content appears natively in the customer Microsoft 365 Copilot experience without the partner building a custom Copilot connector. Cross-link to /microsoft-copilot-studio-agents-enterprise-2026 for the broader Copilot agent architecture pattern.

Does SharePoint Embedded inherit HIPAA BAA coverage and FedRAMP boundary alignment from the customer tenant?

Yes — SharePoint Embedded is covered by the Microsoft Business Associate Agreement (BAA) as part of the broader SharePoint Online and Microsoft 365 service families, and inherits the customer tenant Microsoft 365 BAA — the ISV does not need to negotiate a separate BAA with every healthcare customer. For FedRAMP, SharePoint Embedded availability is on the published Microsoft roadmap for Microsoft 365 GCC, GCC High, and DoD environments with FedRAMP and DoD IL5 alignment; the customer tenant boundary governs partner container content regardless of where the partner application backend operates, with the standard inheritance model. The partner ISV produces a security attestation package — typically SOC 2 Type II for the partner application plus inherited Microsoft 365 boundary statements — that the customer security team uses to satisfy procurement. EPC Group Phase 4 governance hardening produces the attestation evidence package signed off by the customer privacy and security officers.

How does SharePoint Embedded compare to building a custom Microsoft Graph integration on SharePoint sites or OneDrive?

A custom Microsoft Graph integration on SharePoint sites or OneDrive requires every customer-tenant user who touches partner content to be SharePoint-licensed (Microsoft 365 E3 or E5, or SharePoint Online plan), and forces the partner application to navigate site permissions, site collection administration, and the broader SharePoint information architecture. SharePoint Embedded eliminates both — partner application users do not need SharePoint user licenses (Embedded consumption is paid by the partner Microsoft account), and containers are pure file-storage partitions with no site UI or list architecture overhead. For ISVs whose end users are not customer-tenant Microsoft 365 employees (external customers, members, patients, partners, vendors), Embedded is the only viable Microsoft 365 storage pattern. For ISVs whose end users are customer employees, Embedded eliminates per-user SharePoint license dependency and simplifies the architecture. EPC Group models the licensing-versus-consumption math in Phase 1 of the Embedded Accelerator against the partner customer profile.

Related EPC Group enterprise guides

Ship your ISV product on SharePoint Embedded — fixed fee, senior-architect-led

Book a SharePoint Embedded briefing with a senior EPC Group architect. Two-week container-type and identity assessment, costed five-phase roadmap, Purview inheritance review, customer consent flow design, and a three-year consumption-billing model — all delivered against the The EPC Group Lifecycle.

AI assistant — not human