diff --git a/docs/embedded/admin/admin-overview.md b/docs/embedded/admin/admin-overview.md index 8f3de0cbab..8e1ac3b05d 100644 --- a/docs/embedded/admin/admin-overview.md +++ b/docs/embedded/admin/admin-overview.md @@ -41,6 +41,7 @@ SharePoint Embedded administration commonly involves the following roles. | Role | Use it for | | --- | --- | | Global Administrator | Assign the SharePoint Embedded Administrator role and perform any SharePoint Embedded admin task when needed. | +| Billing Administrator | Set up pass-through billing in the Microsoft 365 admin center. | | SharePoint Embedded Administrator | Manage SharePoint Embedded apps and containers through SharePoint admin center and supported SharePoint PowerShell cmdlets. | | Tenant administrator | Manage apps and settings in the consuming Microsoft 365 tenant. | | Compliance administrator | Configure Microsoft Purview audit, retention, DLP, eDiscovery, and related policies. | @@ -88,7 +89,7 @@ Developer tenant admins can create container types, configure billing for standa A consuming tenant uses a SharePoint Embedded application in its Microsoft 365 tenant. -Consuming tenant admins manage installed applications, containers, sharing settings, sensitivity labels, deleted containers, and compliance controls. A Global Administrator sets up billing for pass-through apps. +Consuming tenant admins manage installed applications, containers, sharing settings, sensitivity labels, deleted containers, and compliance controls. A Billing Administrator or Global Administrator sets up billing for pass-through apps. For the consuming tenant admin model, see [Install a SharePoint Embedded app](install-sharepoint-embedded-app.md). @@ -127,7 +128,7 @@ Developer tenants configure billing for standard billing container types. Consuming tenants configure billing for pass-through apps before users can access those apps. -Only a Global Administrator can set up billing in the Microsoft 365 admin center. The SharePoint Embedded Administrator role can't configure billing. +A Billing Administrator or Global Administrator can set up pass-through billing in the Microsoft 365 admin center. The SharePoint Embedded Administrator role alone doesn't grant access to this billing procedure. Set up pass-through billing with [Set up billing in Microsoft 365 admin center](setup-billing-microsoft-365-admin-center.md). @@ -194,7 +195,7 @@ Use this path when your tenant consumes a SharePoint Embedded app: 1. Assign or confirm the SharePoint Embedded Administrator role. 1. Install or approve the app in [Install a SharePoint Embedded app](install-sharepoint-embedded-app.md). 1. Grant admin consent when required. -1. Set up pass-through billing in [Set up billing in Microsoft 365 admin center](setup-billing-microsoft-365-admin-center.md). +1. Have a Billing Administrator or Global Administrator set up pass-through billing in [Set up billing in Microsoft 365 admin center](setup-billing-microsoft-365-admin-center.md). 1. Manage containers in the SharePoint admin center or with PowerShell. 1. Apply compliance controls in Microsoft Purview. diff --git a/docs/embedded/admin/consuming-tenant-admin.md b/docs/embedded/admin/consuming-tenant-admin.md index 438bf6188f..47dc9e8dc8 100644 --- a/docs/embedded/admin/consuming-tenant-admin.md +++ b/docs/embedded/admin/consuming-tenant-admin.md @@ -78,7 +78,7 @@ SharePoint Embedded uses Microsoft's comprehensive compliance and data governanc ## Set up billing for pass-through container type -To use a pass-through billing SharePoint Embedded app, a Global Administrator needs to set up pay-as-you-go services in the [Microsoft 365 admin center](https://admin.microsoft.com/). The SharePoint Embedded Administrator role can't configure billing. No user can access any pass-through SharePoint Embedded apps before valid billing is set up for the SharePoint Embedded platform. +To use a pass-through billing SharePoint Embedded app, a Billing Administrator or Global Administrator needs to set up pay-as-you-go services in the [Microsoft 365 admin center](https://admin.microsoft.com/). The SharePoint Embedded Administrator role alone doesn't grant access to this billing procedure. No user can access any pass-through SharePoint Embedded apps before valid billing is set up for the SharePoint Embedded platform. ### Meters diff --git a/docs/embedded/admin/create-apps-sharepoint-admin-center.md b/docs/embedded/admin/create-apps-sharepoint-admin-center.md index 3ea7daeb80..af47c9b75f 100644 --- a/docs/embedded/admin/create-apps-sharepoint-admin-center.md +++ b/docs/embedded/admin/create-apps-sharepoint-admin-center.md @@ -39,7 +39,7 @@ Confirm these prerequisites. - You know whether to create a new Microsoft Entra app or use an existing app registration. - You know which owners should manage the app. - You know which billing type applies to the app. -- For owner organization billing, you have owner or contributor access to the Azure subscription used for billing. +- For owner organization billing, you have [Owner](/azure/role-based-access-control/built-in-roles/privileged#owner) or [Contributor](/azure/role-based-access-control/built-in-roles/privileged#contributor) access to the Azure subscription used for billing. For role details, see [SharePoint Embedded administrator](admin-overview.md). @@ -103,7 +103,7 @@ Use one owning application for the SharePoint Embedded app that owns its contain Add up to three owners in the **Owners** field. -Owners can manage app settings and billing configuration. +Owners can manage app settings. Billing permissions depend on the billing model. For standard billing, a container type owner can manage billing for the container type they own through the [SharePoint Embedded Visual Studio Code extension](../build/quickstart-vscode.md#configure-standard-billing) or [SharePoint Embedded Model Context Protocol (MCP) server](../build/sharepoint-embedded-mcp-server.md#available-tools). SharePoint Embedded Administrators and Global Administrators can manage any standard-billed container type in the developer tenant. For **User org** billing, a Billing Administrator or Global Administrator in the consuming tenant completes pass-through billing setup in the Microsoft 365 admin center. Assign the developers who build the app as owners so you can hand the app off immediately after creation. @@ -148,7 +148,7 @@ If you select **Owner org**, choose when to connect the Azure billing subscripti *Figure 4: For Owner org billing, choose Setup now to attach an Azure subscription during creation, or Setup later to attach it from the app details panel afterward.* > [!NOTE] -> **User org** billing isn't set up in this panel. For a User org app, a Global Administrator in the consuming tenant sets up billing in the Microsoft 365 admin center before users can access the app. Only a Global Administrator can set up billing. +> **User org** billing isn't set up in this panel. For a User org app, a Billing Administrator or Global Administrator in the consuming tenant sets up billing in the Microsoft 365 admin center before users can access the app. The SharePoint Embedded Administrator role alone doesn't grant access to this billing procedure. ## Configure advanced settings diff --git a/docs/embedded/admin/install-sharepoint-embedded-app.md b/docs/embedded/admin/install-sharepoint-embedded-app.md index 621914d492..2951177ae9 100644 --- a/docs/embedded/admin/install-sharepoint-embedded-app.md +++ b/docs/embedded/admin/install-sharepoint-embedded-app.md @@ -154,7 +154,7 @@ Don't substitute a different application ID. SharePoint Embedded supports standard and pass-through billing models. -For pass-through billing, a Global Administrator in the consuming tenant must set up billing in the Microsoft 365 admin center before users can access the app. Only a Global Administrator can set up billing; the SharePoint Embedded Administrator role can't. +For pass-through billing, a Billing Administrator or Global Administrator in the consuming tenant must set up billing in the Microsoft 365 admin center before users can access the app. The SharePoint Embedded Administrator role alone doesn't grant access to this billing procedure. If billing is invalid or SharePoint Embedded is turned off, users can no longer create new containers, although existing containers and their content remain accessible. @@ -166,7 +166,7 @@ If billing was skipped during app creation, you can attach it later from the app 1. Select the app to open its details panel. 1. In **Billing info**, attach a billing subscription or update the existing one. -For a **User org** app, billing isn't attached from this panel. A Global Administrator in the consuming tenant sets up billing in the Microsoft 365 admin center. See [Set up billing in Microsoft 365 admin center](setup-billing-microsoft-365-admin-center.md). +For a **User org** app, billing isn't attached from this panel. A Billing Administrator or Global Administrator in the consuming tenant sets up billing in the Microsoft 365 admin center. See [Set up billing in Microsoft 365 admin center](setup-billing-microsoft-365-admin-center.md). Use [Set up billing in Microsoft 365 admin center](setup-billing-microsoft-365-admin-center.md) to configure billing for consuming-tenant scenarios. diff --git a/docs/embedded/admin/setup-billing-microsoft-365-admin-center.md b/docs/embedded/admin/setup-billing-microsoft-365-admin-center.md index 218f41745f..e59efafacb 100644 --- a/docs/embedded/admin/setup-billing-microsoft-365-admin-center.md +++ b/docs/embedded/admin/setup-billing-microsoft-365-admin-center.md @@ -10,7 +10,7 @@ ai-usage: ai-assisted # Set up billing in Microsoft 365 admin center -**Applies to:** Consuming tenant admin — Billing admin / Global admin +**Applies to:** Billing Administrator or Global Administrator in a consuming tenant -Set up SharePoint Embedded billing in the Microsoft 365 admin center when your tenant uses an app with pass-through or user organization billing. +Set up SharePoint Embedded billing in the Microsoft 365 admin center when your tenant uses an app with pass-through billing, also called user organization billing. No user can access a pass-through SharePoint Embedded app before valid billing is configured for the SharePoint Embedded platform in the consuming tenant. > [!IMPORTANT] -> Only a Global Administrator can set up SharePoint Embedded billing in the Microsoft 365 admin center. The SharePoint Embedded Administrator role can't configure billing. +> A Billing Administrator or Global Administrator can set up pass-through billing in the Microsoft 365 admin center. The SharePoint Embedded Administrator role alone doesn't grant access to this billing procedure. SharePoint Embedded billing is pay-as-you-go through Azure. @@ -38,8 +38,8 @@ Charges are based on supported meters such as storage, archived storage, API tra Confirm these prerequisites. - You can sign in to the [Microsoft 365 admin center](https://admin.microsoft.com/). -- You have the Global Administrator role. -- You have owner or contributor permissions on the Azure subscription used for billing. +- You have the Billing Administrator or Global Administrator role. +- You have [Owner](/azure/role-based-access-control/built-in-roles/privileged#owner) or [Contributor](/azure/role-based-access-control/built-in-roles/privileged#contributor) access to the Azure subscription used for billing. - You have an Azure subscription in the tenant. - You have a resource group attached to the subscription. - The SharePoint Embedded app is installed or ready to use in the consuming tenant. @@ -69,9 +69,9 @@ The following diagram shows pass-through billing, where consumption charges are ![Pass-through billing model, where the consuming tenant is billed for all consumption.](../images/2bill521.png) -For standard billing, a Global Administrator in the developer tenant sets up billing for the container type. +For standard billing, a [container type owner](../plan/authentication-permissions.md#container-type-owners) can manage billing for a container type they own through the [SharePoint Embedded Visual Studio Code extension](../build/quickstart-vscode.md#configure-standard-billing) or [SharePoint Embedded Model Context Protocol (MCP) server](../build/sharepoint-embedded-mcp-server.md#available-tools). SharePoint Embedded Administrators and Global Administrators can manage billing for any standard-billed container type in the developer tenant. -For pass-through billing, a Global Administrator in the consuming tenant sets up billing in the Microsoft 365 admin center. +For pass-through billing, a Billing Administrator or Global Administrator in the consuming tenant sets up billing in the Microsoft 365 admin center. This article focuses on the consuming tenant pass-through path. @@ -158,12 +158,12 @@ For detailed monitoring steps, see [Monitor usage, billing, and cost](monitor-us Use these checks when setup fails. -- The admin doesn't have the Global Administrator role required to set up billing. -- The admin lacks owner or contributor permissions on the Azure subscription. +- The admin doesn't have the Billing Administrator or Global Administrator role required to set up billing. +- The admin lacks Owner or Contributor access to the Azure subscription. - The subscription is disabled or unavailable. - No resource group is available for billing setup. - The app uses pass-through billing but the consuming tenant hasn't turned on SharePoint Embedded apps. -- The app uses owner organization billing, so the app owner must resolve billing instead. +- The app uses standard billing, so billing must be resolved in the developer tenant instead. - Tenant policies restrict access to the Microsoft 365 admin center billing experience. ## Common access symptoms diff --git a/docs/embedded/build/create-container-type.md b/docs/embedded/build/create-container-type.md index 24c3dc57a5..e70c645c1b 100644 --- a/docs/embedded/build/create-container-type.md +++ b/docs/embedded/build/create-container-type.md @@ -44,13 +44,13 @@ Choose the container type purpose when you create it. You can't convert a trial container type to production later. -You can't convert a standard billing type to pass-through billing later. +You can't change a container type from standard billing to pass-through billing later. | Use case | Container type | |---|---| | Local proof of concept | Trial container type | -| App owner pays | Standard container type with billing profile | -| Customer tenant pays | Standard container type with pass-through billing | +| Developer tenant pays | Container type with standard billing | +| Consuming tenant pays | Container type with pass-through billing | > [!IMPORTANT] > If you choose the wrong purpose or billing model, you must recreate the container type. @@ -63,7 +63,8 @@ Before you create a container type, make sure you have: - A Microsoft Entra ID app registration for the owning app. - A non-guest member account in the owning tenant. - For standard billing, an Azure subscription and resource group. -- For standard billing setup, owner or contributor permissions on the Azure subscription. +- To manage billing for an existing standard container type as a non-administrator, be an [owner of that container type](../plan/authentication-permissions.md#container-type-owners). SharePoint Embedded Administrators and Global Administrators can manage any standard-billed container type in the developer tenant. +- For standard billing setup, [Owner](/azure/role-based-access-control/built-in-roles/privileged#owner) or [Contributor](/azure/role-based-access-control/built-in-roles/privileged#contributor) access to the Azure subscription. > [!NOTE] > - Creating a container type through Microsoft Graph requires only the `FileStorageContainerType.Manage.All` delegated permission. Any non-guest user in the owning tenant can create one and is automatically assigned as an [owner of that container type](../plan/authentication-permissions.md#container-type-owners). For tenant-wide administrative operations, see [Create apps with PowerShell](../admin/create-apps-powershell.md). @@ -88,15 +89,15 @@ The following restrictions apply to trial container types: - The developer must permanently delete all containers of an existing container type in trial status to create a new container type for trial. This includes containers in the deleted container collection. - The container type is restricted to work in the developer tenant. It can't be deployed in other consuming tenants. -## Create a standard container type with app-owner billing +## Create a container type with standard billing -Use standard billing when the developer or app owner tenant pays for consumption. +Use standard billing when the developer tenant pays for consumption. Each tenant can create up to 25 container types in total. One of these can be a free trial container type; the rest are standard (billed) container types. 1. Create or identify the owning Microsoft Entra ID application. 1. Create the container type with the `standard` billing classification. -1. Attach an Azure billing profile with the SharePoint Embedded Visual Studio Code extension or an administrator-managed billing flow. +1. [Manage billing](../plan/choose-billing-model.md#manage-standard-billing-as-a-container-type-owner) on the container type. The SharePoint Embedded Visual Studio Code extension and the [SharePoint Embedded Model Context Protocol (MCP) server](sharepoint-embedded-mcp-server.md#available-tools) enable billing management for standard-billed container types. SharePoint Embedded Administrators and Global Administrators can also [use PowerShell to manage billing](../plan/choose-billing-model.md#manage-standard-billing-as-an-administrator). 1. Record the container type ID. 1. Continue to registration in the consuming tenant. @@ -110,12 +111,12 @@ Use pass-through billing when the consuming tenant pays for consumption. 1. Create or identify the owning Microsoft Entra ID application. 1. Create the container type with the `directToCustomer` billing classification. 1. Register the container type in the consuming tenant. -1. Have the consuming tenant admin activate pay-as-you-go services. +1. Have a Billing Administrator or Global Administrator in the consuming tenant activate pay-as-you-go services. > [!IMPORTANT] > The consuming tenant must complete billing setup before a pass-through application can be used successfully. -The consuming tenant admin activates pay-as-you-go services in the Microsoft 365 admin center. In **Setup** > **Billing and licenses**, select **Activate pay-as-you-go services**. +A Billing Administrator or Global Administrator in the consuming tenant activates pay-as-you-go services in the Microsoft 365 admin center. In **Setup** > **Billing and licenses**, select **Activate pay-as-you-go services**. ![Microsoft 365 admin center Billing and licenses section with the Activate pay-as-you-go services option.](../images/SyntexActivatePAYGSetup.png) @@ -144,7 +145,7 @@ For auth details, see [Configure authentication and authorization](configure-aut | Container type name | Use a durable name that maps to your workload. | | Owning application ID | Use the app registration that owns this type. | | Application redirect URL | Use the URL where files from this app should redirect. | -| Billing model | Choose trial, standard, or pass-through at creation time. | +| Billing model | Choose trial, standard billing, or pass-through billing at creation time. | > [!CAUTION] > The container type ID and owning application ID can't be updated later. @@ -168,9 +169,9 @@ Use the Microsoft Graph [Update fileStorageContainerType](/graph/api/filestorage Use Microsoft Graph to list and update container types. -A non-administrator container type owner can update the container types they own. +A non-administrator container type owner can update container types they own. They can also [create and manage the standard billing profile](../plan/choose-billing-model.md#manage-standard-billing-as-a-container-type-owner). -You need owner or contributor access to billing subscriptions for billing changes. +The owner needs Owner or Contributor access to the Azure subscription for billing changes. ### Manage container types with Microsoft Graph @@ -189,7 +190,7 @@ You can delete only trial container types; deletion of standard container types ## Understand billing dependency -For app-owner billing, the developer tenant attaches an Azure subscription and resource group. +For standard billing, the developer tenant attaches an Azure subscription and resource group. For pass-through billing, the consuming tenant activates pay-as-you-go services. diff --git a/docs/embedded/plan/choose-billing-model.md b/docs/embedded/plan/choose-billing-model.md index 5d4161b856..ef41ce5c3e 100644 --- a/docs/embedded/plan/choose-billing-model.md +++ b/docs/embedded/plan/choose-billing-model.md @@ -21,7 +21,7 @@ next: ../plan/security-compliance-governance.md Use this article to choose a billing model for production SharePoint Embedded container types. SharePoint Embedded is a consumption-based, pay-as-you-go offering, and you select billing at the container type level. -For the full billing setup procedure, see [PAYG billing for SharePoint Embedded](../admin/setup-billing-microsoft-365-admin-center.md). +For consuming-tenant pass-through setup, see [Set up billing in Microsoft 365 admin center](../admin/setup-billing-microsoft-365-admin-center.md). ## Billing models @@ -32,38 +32,57 @@ SharePoint Embedded provides two billing models: Both models use the same billing meters. -The model determines which tenant is billed and which admin configures the billing profile. +The model determines which tenant is billed and who configures the billing profile. > [!IMPORTANT] > Once a container type is created, its billing model can't be changed. To switch models, you must delete and re-create the container type with the desired billing model. | Billing model | Who is billed | Who configures billing | | --- | --- | --- | -| Standard | Tenant that owns or develops the application. | Admin in the developer tenant. | -| Pass-through | Tenant registered to use the SharePoint Embedded application. | Admin in the consuming tenant. | +| Standard | Tenant that owns or develops the application. | Container type owner, SharePoint Embedded Administrator, or Global Administrator in the developer tenant. | +| Pass-through | Tenant registered to use the SharePoint Embedded application. | Billing Administrator or Global Administrator in the consuming tenant. | ## Standard billing With standard billing, all consumption-based charges are directly billed to the tenant that owns or develops the application. -The admin in the developer tenant must establish a valid billing profile when creating a standard container type. +A container type owner can create and manage a billing profile for a container type they own. The owner doesn't need the SharePoint Embedded Administrator or Global Administrator role. + +SharePoint Embedded Administrators and Global Administrators can manage billing for any standard-billed container type in the developer tenant. Use standard billing when: -- The application owner wants to centralize usage charges. +- The developer tenant wants to centralize usage charges. - The app is an internal enterprise line-of-business (LOB) app. - The independent software vendor (ISV) or developer tenant plans to absorb or separately recover usage costs. -- Customer tenants shouldn't configure their own SharePoint Embedded billing profile. +- Consuming tenants shouldn't configure their own SharePoint Embedded billing profile. The billing setup requires: -- An existing SharePoint tenancy. -- An Azure subscription in the tenancy. +- An existing SharePoint tenant. +- An Azure subscription in the developer tenant. - A resource group attached to the Azure subscription. -- A SharePoint Embedded Administrator or Global Administrator to operate billing cmdlets. -- Owner or contributor permissions on the Azure subscription for the admin who sets up billing. +- A container type owner, SharePoint Embedded Administrator, or Global Administrator in the developer tenant. +- [Owner](/azure/role-based-access-control/built-in-roles/privileged#owner) or [Contributor](/azure/role-based-access-control/built-in-roles/privileged#contributor) access to the Azure subscription for the person who sets up billing. + +### Manage standard billing as a container type owner + +A non-administrator container type owner can create and manage a standard billing profile for a container type they own through the SharePoint Embedded Visual Studio Code extension or Model Context Protocol (MCP) server. + +The owner also needs Owner or Contributor access to the Azure subscription. Choose one of these facilities: + +- In the [SharePoint Embedded Visual Studio Code extension](../build/quickstart-vscode.md#configure-standard-billing), select the container type and use **Attach billing**. Then select the Azure subscription and resource group. +- In the [SharePoint Embedded MCP server](../build/sharepoint-embedded-mcp-server.md#available-tools), use `billing_setup` to connect the container type to an Azure subscription and resource group. Use `billing_check` to inspect the billing configuration. + +The SharePoint Embedded billing service verifies that the signed-in user owns the container type. + +A user who doesn't own the container type needs the SharePoint Embedded Administrator or Global Administrator role. + +### Manage standard billing as an administrator + +SharePoint Embedded Administrators and Global Administrators can use the SharePoint Online Management Shell to manage billing for any standard-billed container type in the developer tenant. -The standard billing pattern creates the container type and then attaches an Azure billing profile (see [Create and configure a container type](../build/create-container-type.md)): +Create the container type: ```powershell New-SPOContainerType -ContainerTypeName -OwningApplicationId -ApplicationRedirectUrl @@ -82,16 +101,16 @@ Add-SPOContainerTypeBilling -ContainerTypeId -AzureSubscriptio With pass-through billing, consumption-based charges are billed directly to the tenant registered to use the SharePoint Embedded application. -Admins in the developer tenant don't need to set up a billing profile when creating a pass-through container type. +SharePoint Embedded Administrators and Global Administrators in the developer tenant don't set up a billing profile when creating a pass-through container type. -After the container type is registered in the consuming tenant, the consuming tenant admin sets up the billing profile in that tenant. +After the container type is registered in the consuming tenant, a Billing Administrator or Global Administrator in that tenant sets up the billing profile. Use pass-through billing when: -- Each customer tenant should pay for its own SharePoint Embedded usage. +- Each consuming tenant should pay for its own SharePoint Embedded usage. - The app is an ISV multitenant application. -- The customer tenant controls the Azure subscription used for pay-as-you-go charges. -- The consuming tenant admin is expected to complete billing onboarding. +- The consuming tenant controls the Azure subscription used for pay-as-you-go charges. +- A Billing Administrator or Global Administrator in the consuming tenant completes billing onboarding. Use this pass-through creation pattern: @@ -138,7 +157,7 @@ Calls made by internal services to containers aren't charged when the applicatio Nonchargeable transactions include: - eDiscovery queries that search through container content for compliance or legal purposes. -- Admin actions taken through SharePoint Admin Center or SharePoint PowerShell. +- Admin actions taken through SharePoint admin center or SharePoint PowerShell. ## Egress meter @@ -148,16 +167,16 @@ Downloads from the SharePoint Embedded application server to Office desktop clie Review pricing and cost management in Azure Cost Management as part of your operations plan. -## Admin responsibilities +## Billing responsibilities Plan these responsibilities by billing model. | Responsibility | Standard billing | Pass-through billing | | --- | --- | --- | -| Create container type | Developer tenant admin | Developer tenant admin | -| Attach billing profile at creation | Developer tenant admin | Not in developer tenant | +| Create container type | Developer in the developer tenant | Developer in the developer tenant | +| Attach or manage billing profile | Container type owner for a container type they own; SharePoint Embedded Administrator or Global Administrator for any standard-billed container type in the developer tenant | Not in developer tenant | | Register container type | Owning app in consuming tenant | Owning app in consuming tenant | -| Set up consuming tenant billing | Not required for app usage billing | Consuming tenant admin | +| Set up consuming tenant billing | Not required for app usage billing | Billing Administrator or Global Administrator in the consuming tenant | | Monitor Azure cost | Developer tenant | Consuming tenant | ## Relationship to app model @@ -177,7 +196,7 @@ For model selection, see [Choose an app model: single-tenant or multitenant](../ Use these setup references after you choose a model: - Create and configure container types: [SharePoint Embedded container types](../build/create-container-type.md). -- Set up billing: [PAYG billing for SharePoint Embedded](../admin/setup-billing-microsoft-365-admin-center.md). +- Set up pass-through billing: [Set up billing in Microsoft 365 admin center](../admin/setup-billing-microsoft-365-admin-center.md). - Review meters: [SharePoint Embedded billing meters](../reference/billing-meters.md). - Register a consuming tenant: [Register file storage container type application permissions](../build/register-application-permissions.md). @@ -187,9 +206,10 @@ Use these setup references after you choose a model: - Confirm the app model. - Confirm whether the container type is standard or pass-through. - Identify the Azure subscription and resource group if using standard billing. -- Identify the consuming tenant admin if using pass-through billing. -- Confirm SharePoint Embedded Administrator or Global Administrator roles. -- Confirm owner or contributor permissions on the Azure subscription. +- Identify a Billing Administrator or Global Administrator in the consuming tenant if using pass-through billing. +- Confirm container type owner access or the SharePoint Embedded Administrator or Global Administrator role for standard billing. +- Confirm Billing Administrator or Global Administrator access for pass-through billing. +- Confirm Owner or Contributor access to the Azure subscription. - Plan cost monitoring in Azure Cost Management. - Plan storage lifecycle to control storage consumption. - Plan calling patterns to manage API transaction cost. diff --git a/docs/embedded/plan/container-types-containers.md b/docs/embedded/plan/container-types-containers.md index 135409e18c..8985730566 100644 --- a/docs/embedded/plan/container-types-containers.md +++ b/docs/embedded/plan/container-types-containers.md @@ -145,7 +145,7 @@ The developer creates the container type with the `directToCustomer` billing cla } ``` -After registration, a Global Administrator in the consuming tenant sets up billing in the consuming tenant. +After registration, a Billing Administrator or Global Administrator in the consuming tenant sets up billing. ## Admin and developer interaction diff --git a/docs/embedded/publish/choose-app-billing-model.md b/docs/embedded/publish/choose-app-billing-model.md index cba02e8327..63b0d882f2 100644 --- a/docs/embedded/publish/choose-app-billing-model.md +++ b/docs/embedded/publish/choose-app-billing-model.md @@ -20,7 +20,7 @@ next: customer-tenant-setup-guide.md SharePoint Embedded is a consumption-based pay-as-you-go service. As an independent software vendor (ISV), you choose the billing model when you create the production container type for your app. -That choice affects who pays for storage, API transactions, and egress, and it changes what the customer administrator must do during onboarding. +That choice affects who pays for storage, API transactions, and egress. It also changes what the Billing Administrator or Global Administrator in the consuming tenant must do during onboarding. Use this article to decide between standard billing and pass-through billing before you publish customer setup instructions. @@ -30,8 +30,8 @@ SharePoint Embedded supports two production billing models for standard containe | Billing model | Who is billed | Who configures billing | Typical ISV use | | --- | --- | --- | --- | -| Standard billing | Developer tenant | Developer | You include SharePoint Embedded consumption in your product price or centralize billing. | -| Pass-through billing | Consuming tenant | Customer admin | The customer pays Microsoft directly for their SharePoint Embedded consumption. | +| Standard billing | Developer tenant | Container type owner for a container type they own; SharePoint Embedded Administrator or Global Administrator for any standard-billed container type in the developer tenant | You include SharePoint Embedded consumption in your product price or centralize billing. | +| Pass-through billing | Consuming tenant | Billing Administrator or Global Administrator in the consuming tenant | The customer pays Microsoft directly for their SharePoint Embedded consumption. | For current billing details, see [Pay-as-you-go billing for SharePoint Embedded](../admin/setup-billing-microsoft-365-admin-center.md). @@ -57,7 +57,7 @@ For more about container types, see [Understand container types and containers]( ## Standard billing With standard billing, all consumption-based SharePoint Embedded charges are billed to the tenant that owns or develops the application. -The developer must establish a valid Azure billing profile for the container type. +A container type owner can establish a valid Azure billing profile only for a container type they own. A SharePoint Embedded Administrator or Global Administrator can establish a valid Azure billing profile for any standard-billed container type in the developer tenant. Choose standard billing when: @@ -76,13 +76,17 @@ Before you create or activate a standard billing container type, confirm that yo - An active SharePoint tenant. - A Microsoft Entra owning application. -- A SharePoint Embedded Administrator or Global Administrator. +- A container type owner, SharePoint Embedded Administrator, or Global Administrator. - An Azure subscription in the developer tenant. - A resource group attached to the subscription. -- Owner or contributor permissions for the admin who sets up the billing relationship. +- [Owner](/azure/role-based-access-control/built-in-roles/privileged#owner) or [Contributor](/azure/role-based-access-control/built-in-roles/privileged#contributor) access to the Azure subscription for the person who sets up the billing relationship. When you set up standard billing, provide the Azure subscription, resource group, and region for the billing profile. +A non-administrator container type owner can create and manage the billing profile only for the container type they own, through the [SharePoint Embedded Visual Studio Code extension](../build/quickstart-vscode.md#configure-standard-billing) or [SharePoint Embedded Model Context Protocol (MCP) server](../build/sharepoint-embedded-mcp-server.md#available-tools). For the owner path, see [Manage standard billing as a container type owner](../plan/choose-billing-model.md#manage-standard-billing-as-a-container-type-owner). + +SharePoint Embedded Administrators and Global Administrators can manage billing for any standard-billed container type in the developer tenant. + > [!NOTE] > Standard billing doesn't remove the need for customer consent, container type registration, or validation. > It only changes who configures and pays for SharePoint Embedded consumption. @@ -91,7 +95,7 @@ When you set up standard billing, provide the Azure subscription, resource group With pass-through billing, consumption charges are billed directly to the tenant registered to use the SharePoint Embedded application. The developer creates the container type with pass-through billing enabled. -The customer administrator then configures billing in the consuming tenant before users can access the app. +A Billing Administrator or Global Administrator in the consuming tenant then configures billing before users can access the app. Choose pass-through billing when: @@ -102,17 +106,17 @@ Choose pass-through billing when: - You want a cleaner separation between app subscription revenue and platform consumption. Pass-through billing adds customer onboarding work. -The customer admin must set up pay-as-you-go billing in the Microsoft 365 admin center and connect a valid Azure subscription and resource group. +A Billing Administrator or Global Administrator in the consuming tenant must set up pay-as-you-go billing in the Microsoft 365 admin center and connect a valid Azure subscription and resource group. ### Pass-through billing dependencies Before a customer can use a pass-through SharePoint Embedded app, the consuming tenant needs: - A SharePoint tenant. -- A Global Administrator or SharePoint Embedded Administrator. +- A Billing Administrator or Global Administrator to set up pass-through billing. - A valid Azure subscription. - A valid Azure resource group. -- Owner or contributor permissions for the admin who creates the billing relationship. +- Owner or Contributor access to the Azure subscription for the administrator who creates the billing relationship. - Completed app registration and consent steps. Until valid billing is set up for the SharePoint Embedded platform in the consuming tenant, users can't create new containers in a pass-through SharePoint Embedded app. Existing containers and their content remain accessible. @@ -138,7 +142,7 @@ Tell the customer: 1. The app uses SharePoint Embedded pass-through billing. 1. The customer must provide an Azure subscription and resource group. -1. The customer admin must turn on billing for SharePoint Embedded apps. +1. A Billing Administrator or Global Administrator in the consuming tenant must turn on billing for SharePoint Embedded apps. 1. Users can't use the app until billing is valid. 1. The customer can track usage in Azure Cost Management. diff --git a/docs/embedded/publish/customer-tenant-setup-guide.md b/docs/embedded/publish/customer-tenant-setup-guide.md index 645533d4be..88f17275d0 100644 --- a/docs/embedded/publish/customer-tenant-setup-guide.md +++ b/docs/embedded/publish/customer-tenant-setup-guide.md @@ -36,7 +36,7 @@ Ask the customer to confirm these prerequisites before the setup meeting or inst | Area | Customer requirement | | --- | --- | | Microsoft 365 | An active Microsoft 365 tenant with at least one SharePoint license. | -| Admin role | A Global Administrator or SharePoint Embedded Administrator can complete setup. | +| Admin role | A SharePoint Embedded Administrator or Global Administrator can complete app and container setup. For pass-through billing, a Billing Administrator or Global Administrator must also complete billing setup. | | Users | Users who authenticate to SharePoint Embedded containers exist in Microsoft Entra ID as members or guests. | | Consent | The customer can review and grant the Microsoft Entra permissions your app requests. | | Billing | An Azure subscription and resource group are available if the app uses pass-through billing. | @@ -88,9 +88,9 @@ Use this high-level sequence in your customer guide: ## Step 1: Assign the administrator -Ask the customer to choose an administrator who can complete the full setup. If the customer doesn't want to use a Global Administrator, they can assign the SharePoint Embedded Administrator role. +Ask the customer to choose a SharePoint Embedded Administrator or Global Administrator for app and container setup. If the app uses pass-through billing, ensure that a Billing Administrator or Global Administrator completes billing setup in the Microsoft 365 admin center. -Tell the customer to finish role assignment before the installation window. This avoids delays when billing or validation needs elevated access. +Tell the customer to finish the required role assignments before the installation window. This avoids delays during setup and validation. ## Step 2: Review the application @@ -136,7 +136,7 @@ Ask the customer to confirm that: Skip this step when your app uses standard billing. If your app uses pass-through billing, tell the customer that SharePoint Embedded billing must be configured before users can access the app. -The customer needs a valid Azure subscription and resource group. A Global Administrator sets up billing in the Microsoft 365 admin center, and the admin who creates the billing relationship also needs the Owner or Contributor role on the Azure subscription. Then set up billing: +The customer needs a valid Azure subscription and resource group. A Billing Administrator or Global Administrator sets up billing in the Microsoft 365 admin center. This administrator also needs the [Owner](/azure/role-based-access-control/built-in-roles/privileged#owner) or [Contributor](/azure/role-based-access-control/built-in-roles/privileged#contributor) role on the Azure subscription. Then set up billing: 1. Open the [Microsoft 365 admin center](https://admin.microsoft.com/). 1. Go to **Setup** > **Billing and licenses**, and select **Activate pay-as-you-go services**. @@ -165,7 +165,8 @@ For deeper validation steps, see [Validate customer app installation](validate-c Give customers a checklist they can sign off. -- [ ] The assigned admin has the Global Administrator or SharePoint Embedded Administrator role. +- [ ] A SharePoint Embedded Administrator or Global Administrator is assigned for app and container setup. +- [ ] A Billing Administrator or Global Administrator is available to complete pass-through billing setup, if required. - [ ] The app ID and publisher match the ISV handoff. - [ ] Admin consent is granted for the expected app. - [ ] The container type is registered in the consuming tenant. diff --git a/docs/embedded/publish/validate-customer-installation.md b/docs/embedded/publish/validate-customer-installation.md index c35b1e4ca6..d9d75db24c 100644 --- a/docs/embedded/publish/validate-customer-installation.md +++ b/docs/embedded/publish/validate-customer-installation.md @@ -47,8 +47,9 @@ Validation usually needs both ISV and customer roles. | Role | Responsibility | | --- | --- | | ISV developer | Supplies expected app IDs, container type ID, app behavior, and support troubleshooting. | -| Customer Global Administrator or SharePoint Embedded Administrator | Confirms SharePoint Embedded app setup, billing, and administration visibility. | -| Customer Azure billing owner or contributor | Helps resolve pass-through billing setup issues. | +| Customer Billing Administrator or Global Administrator | Sets up or confirms pass-through billing. | +| Customer SharePoint Embedded Administrator or Global Administrator | Confirms SharePoint Embedded app setup and administration visibility. | +| Customer with the [Owner](/azure/role-based-access-control/built-in-roles/privileged#owner) or [Contributor](/azure/role-based-access-control/built-in-roles/privileged#contributor) role on the Azure subscription | Helps resolve pass-through billing setup issues. | | Customer test user | Signs in and performs app-level document actions. | ## Before you start @@ -142,7 +143,7 @@ Check: - A valid Azure subscription is connected. - A valid resource group is selected. - The setup was completed for SharePoint Embedded apps. -- The customer billing admin has owner or contributor permissions where required. +- The customer administrator who sets up billing has the Owner or Contributor role on the Azure subscription where required. - The customer understands that disabling billing interrupts user access. For billing model guidance, see [Choose a billing model for your app](choose-app-billing-model.md). diff --git a/docs/embedded/reference/troubleshooting.md b/docs/embedded/reference/troubleshooting.md index 9013ee9ca0..a02f081f88 100644 --- a/docs/embedded/reference/troubleshooting.md +++ b/docs/embedded/reference/troubleshooting.md @@ -28,7 +28,7 @@ Use this reference to identify likely causes and fixes. For end-to-end setup, se | Access denied when calling container or file APIs. | The container type hasn't been registered in the consuming tenant, or the application lacks container type application permissions. | Grant admin consent, call the container type registration API, and verify delegated or app-only permissions include the required operations. | [Create and manage containers](../build/create-manage-containers.md) | | Container creation fails from a single-page, mobile, or desktop app. | The create container API requires a confidential client, and the token came from a public client application that can't hold a credential. | Move container creation to a back-end component that acquires the token with a client secret or certificate, then retry. | [Create and manage containers](../build/create-manage-containers.md#use-a-confidential-client-to-create-containers) | | Delegated API calls return `403 Forbidden` when listing containers. | The signed-in user doesn't have a OneDrive. The List containers operation on behalf of a user requires the user to have a OneDrive. | Use app-only mode for list containers, or ensure the user has a OneDrive until this dependency is removed. | [Create and manage containers](../build/create-manage-containers.md) | -| Pass-through app users can't create new containers (or can't use the app before billing is first configured). | Pass-through billing hasn't been configured, SharePoint Embedded was turned off, or the linked Azure subscription was disconnected. A Global Administrator must set up billing in the Microsoft 365 admin center. | Have a Global Administrator configure pay-as-you-go services for SharePoint Embedded in the Microsoft 365 admin center and confirm the Azure subscription remains linked. Existing containers stay accessible while billing is misconfigured or disconnected. | [Monitor usage, billing, and cost](../admin/monitor-usage-billing-cost.md) | +| Pass-through app users can't create new containers (or can't use the app before billing is first configured). | Pass-through billing hasn't been configured, SharePoint Embedded was turned off, or the linked Azure subscription was disconnected. A Billing Administrator or Global Administrator must set up billing in the Microsoft 365 admin center. | Have a Billing Administrator or Global Administrator configure pay-as-you-go services for SharePoint Embedded in the Microsoft 365 admin center and confirm the Azure subscription remains linked. Existing containers stay accessible while billing is misconfigured or disconnected. | [Monitor usage, billing, and cost](../admin/monitor-usage-billing-cost.md) | | Office documents open but mentions don't resolve expected users. | Mentions require target users to have a Microsoft 365 license and are restricted to people inside the consuming tenant organization. | Assign the required Microsoft 365 license to internal target users; don't expect guest or cross-tenant users in the mentions picker. | [Manage files](../build/manage-files.md) | | Search returns unexpected containers or content. | Microsoft Search runs in the context of the signed-in user and can return content the user can access unless scoped. | Include `ContainerTypeId` or `ContainerId` in the query string. If discoverability is disabled, set `includeHiddenContent` to `true` as described in [Build search experiences](../build/search-containers-files.md). | [Build search experiences](../build/search-containers-files.md) | | Search API calls fail because of permissions. | Search scenarios require delegated Microsoft Graph permissions during preview, including `Files.Read.All` in addition to `FileStorageContainer.Selected`. | Request and consent to the required delegated permissions and retest with a signed-in user. | [Build search experiences](../build/search-containers-files.md) |