Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
7 changes: 4 additions & 3 deletions docs/embedded/admin/admin-overview.md
Original file line number Diff line number Diff line change
Expand Up @@ -41,6 +41,7 @@ SharePoint Embedded administration commonly involves the following roles.
| Role | Use it for |
| --- | --- |
| Global Administrator | Assign the SharePoint Embedded Administrator role and perform any SharePoint Embedded admin task when needed. |
| Billing Administrator | Set up pass-through billing in the Microsoft 365 admin center. |
| SharePoint Embedded Administrator | Manage SharePoint Embedded apps and containers through SharePoint admin center and supported SharePoint PowerShell cmdlets. |
| Tenant administrator | Manage apps and settings in the consuming Microsoft 365 tenant. |
| Compliance administrator | Configure Microsoft Purview audit, retention, DLP, eDiscovery, and related policies. |
Expand Down Expand Up @@ -88,7 +89,7 @@ Developer tenant admins can create container types, configure billing for standa

A consuming tenant uses a SharePoint Embedded application in its Microsoft 365 tenant.

Consuming tenant admins manage installed applications, containers, sharing settings, sensitivity labels, deleted containers, and compliance controls. A Global Administrator sets up billing for pass-through apps.
Consuming tenant admins manage installed applications, containers, sharing settings, sensitivity labels, deleted containers, and compliance controls. A Billing Administrator or Global Administrator sets up billing for pass-through apps.

For the consuming tenant admin model, see [Install a SharePoint Embedded app](install-sharepoint-embedded-app.md).

Expand Down Expand Up @@ -127,7 +128,7 @@ Developer tenants configure billing for standard billing container types.

Consuming tenants configure billing for pass-through apps before users can access those apps.

Only a Global Administrator can set up billing in the Microsoft 365 admin center. The SharePoint Embedded Administrator role can't configure billing.
A Billing Administrator or Global Administrator can set up pass-through billing in the Microsoft 365 admin center. The SharePoint Embedded Administrator role alone doesn't grant access to this billing procedure.

Set up pass-through billing with [Set up billing in Microsoft 365 admin center](setup-billing-microsoft-365-admin-center.md).

Expand Down Expand Up @@ -194,7 +195,7 @@ Use this path when your tenant consumes a SharePoint Embedded app:
1. Assign or confirm the SharePoint Embedded Administrator role.
1. Install or approve the app in [Install a SharePoint Embedded app](install-sharepoint-embedded-app.md).
1. Grant admin consent when required.
1. Set up pass-through billing in [Set up billing in Microsoft 365 admin center](setup-billing-microsoft-365-admin-center.md).
1. Have a Billing Administrator or Global Administrator set up pass-through billing in [Set up billing in Microsoft 365 admin center](setup-billing-microsoft-365-admin-center.md).
1. Manage containers in the SharePoint admin center or with PowerShell.
1. Apply compliance controls in Microsoft Purview.

Expand Down
2 changes: 1 addition & 1 deletion docs/embedded/admin/consuming-tenant-admin.md
Original file line number Diff line number Diff line change
Expand Up @@ -78,7 +78,7 @@ SharePoint Embedded uses Microsoft's comprehensive compliance and data governanc

## Set up billing for pass-through container type

To use a pass-through billing SharePoint Embedded app, a Global Administrator needs to set up pay-as-you-go services in the [Microsoft 365 admin center](https://admin.microsoft.com/). The SharePoint Embedded Administrator role can't configure billing. No user can access any pass-through SharePoint Embedded apps before valid billing is set up for the SharePoint Embedded platform.
To use a pass-through billing SharePoint Embedded app, a Billing Administrator or Global Administrator needs to set up pay-as-you-go services in the [Microsoft 365 admin center](https://admin.microsoft.com/). The SharePoint Embedded Administrator role alone doesn't grant access to this billing procedure. No user can access any pass-through SharePoint Embedded apps before valid billing is set up for the SharePoint Embedded platform.

### Meters

Expand Down
6 changes: 3 additions & 3 deletions docs/embedded/admin/create-apps-sharepoint-admin-center.md
Original file line number Diff line number Diff line change
Expand Up @@ -39,7 +39,7 @@ Confirm these prerequisites.
- You know whether to create a new Microsoft Entra app or use an existing app registration.
- You know which owners should manage the app.
- You know which billing type applies to the app.
- For owner organization billing, you have owner or contributor access to the Azure subscription used for billing.
- For owner organization billing, you have [Owner](/azure/role-based-access-control/built-in-roles/privileged#owner) or [Contributor](/azure/role-based-access-control/built-in-roles/privileged#contributor) access to the Azure subscription used for billing.

For role details, see [SharePoint Embedded administrator](admin-overview.md).

Expand Down Expand Up @@ -103,7 +103,7 @@ Use one owning application for the SharePoint Embedded app that owns its contain

Add up to three owners in the **Owners** field.

Owners can manage app settings and billing configuration.
Owners can manage app settings. Billing permissions depend on the billing model. For standard billing, a container type owner can manage billing for the container type they own through the [SharePoint Embedded Visual Studio Code extension](../build/quickstart-vscode.md#configure-standard-billing) or [SharePoint Embedded Model Context Protocol (MCP) server](../build/sharepoint-embedded-mcp-server.md#available-tools). SharePoint Embedded Administrators and Global Administrators can manage any standard-billed container type in the developer tenant. For **User org** billing, a Billing Administrator or Global Administrator in the consuming tenant completes pass-through billing setup in the Microsoft 365 admin center.

Assign the developers who build the app as owners so you can hand the app off immediately after creation.

Expand Down Expand Up @@ -148,7 +148,7 @@ If you select **Owner org**, choose when to connect the Azure billing subscripti
*Figure 4: For Owner org billing, choose Setup now to attach an Azure subscription during creation, or Setup later to attach it from the app details panel afterward.*

> [!NOTE]
> **User org** billing isn't set up in this panel. For a User org app, a Global Administrator in the consuming tenant sets up billing in the Microsoft 365 admin center before users can access the app. Only a Global Administrator can set up billing.
> **User org** billing isn't set up in this panel. For a User org app, a Billing Administrator or Global Administrator in the consuming tenant sets up billing in the Microsoft 365 admin center before users can access the app. The SharePoint Embedded Administrator role alone doesn't grant access to this billing procedure.

## Configure advanced settings

Expand Down
4 changes: 2 additions & 2 deletions docs/embedded/admin/install-sharepoint-embedded-app.md
Original file line number Diff line number Diff line change
Expand Up @@ -154,7 +154,7 @@ Don't substitute a different application ID.

SharePoint Embedded supports standard and pass-through billing models.

For pass-through billing, a Global Administrator in the consuming tenant must set up billing in the Microsoft 365 admin center before users can access the app. Only a Global Administrator can set up billing; the SharePoint Embedded Administrator role can't.
For pass-through billing, a Billing Administrator or Global Administrator in the consuming tenant must set up billing in the Microsoft 365 admin center before users can access the app. The SharePoint Embedded Administrator role alone doesn't grant access to this billing procedure.

If billing is invalid or SharePoint Embedded is turned off, users can no longer create new containers, although existing containers and their content remain accessible.

Expand All @@ -166,7 +166,7 @@ If billing was skipped during app creation, you can attach it later from the app
1. Select the app to open its details panel.
1. In **Billing info**, attach a billing subscription or update the existing one.

For a **User org** app, billing isn't attached from this panel. A Global Administrator in the consuming tenant sets up billing in the Microsoft 365 admin center. See [Set up billing in Microsoft 365 admin center](setup-billing-microsoft-365-admin-center.md).
For a **User org** app, billing isn't attached from this panel. A Billing Administrator or Global Administrator in the consuming tenant sets up billing in the Microsoft 365 admin center. See [Set up billing in Microsoft 365 admin center](setup-billing-microsoft-365-admin-center.md).

Use [Set up billing in Microsoft 365 admin center](setup-billing-microsoft-365-admin-center.md) to configure billing for consuming-tenant scenarios.

Expand Down
20 changes: 10 additions & 10 deletions docs/embedded/admin/setup-billing-microsoft-365-admin-center.md
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,7 @@ ai-usage: ai-assisted

# Set up billing in Microsoft 365 admin center

**Applies to:** Consuming tenant admin — Billing admin / Global admin
**Applies to:** Billing Administrator or Global Administrator in a consuming tenant

<!-- agent:
task_type: how-to
Expand All @@ -19,12 +19,12 @@ outcome: Set up billing for SharePoint Embedded apps that are billed to the cons
next: manage-containers-sharepoint-admin-center.md
-->

Set up SharePoint Embedded billing in the Microsoft 365 admin center when your tenant uses an app with pass-through or user organization billing.
Set up SharePoint Embedded billing in the Microsoft 365 admin center when your tenant uses an app with pass-through billing, also called user organization billing.

No user can access a pass-through SharePoint Embedded app before valid billing is configured for the SharePoint Embedded platform in the consuming tenant.

> [!IMPORTANT]
> Only a Global Administrator can set up SharePoint Embedded billing in the Microsoft 365 admin center. The SharePoint Embedded Administrator role can't configure billing.
> A Billing Administrator or Global Administrator can set up pass-through billing in the Microsoft 365 admin center. The SharePoint Embedded Administrator role alone doesn't grant access to this billing procedure.

SharePoint Embedded billing is pay-as-you-go through Azure.

Expand All @@ -38,8 +38,8 @@ Charges are based on supported meters such as storage, archived storage, API tra
Confirm these prerequisites.

- You can sign in to the [Microsoft 365 admin center](https://admin.microsoft.com/).
- You have the Global Administrator role.
- You have owner or contributor permissions on the Azure subscription used for billing.
- You have the Billing Administrator or Global Administrator role.
- You have [Owner](/azure/role-based-access-control/built-in-roles/privileged#owner) or [Contributor](/azure/role-based-access-control/built-in-roles/privileged#contributor) access to the Azure subscription used for billing.
- You have an Azure subscription in the tenant.
- You have a resource group attached to the subscription.
- The SharePoint Embedded app is installed or ready to use in the consuming tenant.
Expand Down Expand Up @@ -69,9 +69,9 @@ The following diagram shows pass-through billing, where consumption charges are

![Pass-through billing model, where the consuming tenant is billed for all consumption.](../images/2bill521.png)

For standard billing, a Global Administrator in the developer tenant sets up billing for the container type.
For standard billing, a [container type owner](../plan/authentication-permissions.md#container-type-owners) can manage billing for a container type they own through the [SharePoint Embedded Visual Studio Code extension](../build/quickstart-vscode.md#configure-standard-billing) or [SharePoint Embedded Model Context Protocol (MCP) server](../build/sharepoint-embedded-mcp-server.md#available-tools). SharePoint Embedded Administrators and Global Administrators can manage billing for any standard-billed container type in the developer tenant.

For pass-through billing, a Global Administrator in the consuming tenant sets up billing in the Microsoft 365 admin center.
For pass-through billing, a Billing Administrator or Global Administrator in the consuming tenant sets up billing in the Microsoft 365 admin center.

This article focuses on the consuming tenant pass-through path.

Expand Down Expand Up @@ -158,12 +158,12 @@ For detailed monitoring steps, see [Monitor usage, billing, and cost](monitor-us

Use these checks when setup fails.

- The admin doesn't have the Global Administrator role required to set up billing.
- The admin lacks owner or contributor permissions on the Azure subscription.
- The admin doesn't have the Billing Administrator or Global Administrator role required to set up billing.
- The admin lacks Owner or Contributor access to the Azure subscription.
- The subscription is disabled or unavailable.
- No resource group is available for billing setup.
- The app uses pass-through billing but the consuming tenant hasn't turned on SharePoint Embedded apps.
- The app uses owner organization billing, so the app owner must resolve billing instead.
- The app uses standard billing, so billing must be resolved in the developer tenant instead.
- Tenant policies restrict access to the Microsoft 365 admin center billing experience.

## Common access symptoms
Expand Down
27 changes: 14 additions & 13 deletions docs/embedded/build/create-container-type.md
Original file line number Diff line number Diff line change
Expand Up @@ -44,13 +44,13 @@ Choose the container type purpose when you create it.

You can't convert a trial container type to production later.

You can't convert a standard billing type to pass-through billing later.
You can't change a container type from standard billing to pass-through billing later.

| Use case | Container type |
|---|---|
| Local proof of concept | Trial container type |
| App owner pays | Standard container type with billing profile |
| Customer tenant pays | Standard container type with pass-through billing |
| Developer tenant pays | Container type with standard billing |
| Consuming tenant pays | Container type with pass-through billing |

> [!IMPORTANT]
> If you choose the wrong purpose or billing model, you must recreate the container type.
Expand All @@ -63,7 +63,8 @@ Before you create a container type, make sure you have:
- A Microsoft Entra ID app registration for the owning app.
- A non-guest member account in the owning tenant.
- For standard billing, an Azure subscription and resource group.
- For standard billing setup, owner or contributor permissions on the Azure subscription.
- To manage billing for an existing standard container type as a non-administrator, be an [owner of that container type](../plan/authentication-permissions.md#container-type-owners). SharePoint Embedded Administrators and Global Administrators can manage any standard-billed container type in the developer tenant.
- For standard billing setup, [Owner](/azure/role-based-access-control/built-in-roles/privileged#owner) or [Contributor](/azure/role-based-access-control/built-in-roles/privileged#contributor) access to the Azure subscription.

> [!NOTE]
> - Creating a container type through Microsoft Graph requires only the `FileStorageContainerType.Manage.All` delegated permission. Any non-guest user in the owning tenant can create one and is automatically assigned as an [owner of that container type](../plan/authentication-permissions.md#container-type-owners). For tenant-wide administrative operations, see [Create apps with PowerShell](../admin/create-apps-powershell.md).
Expand All @@ -88,15 +89,15 @@ The following restrictions apply to trial container types:
- The developer must permanently delete all containers of an existing container type in trial status to create a new container type for trial. This includes containers in the deleted container collection.
- The container type is restricted to work in the developer tenant. It can't be deployed in other consuming tenants.

## Create a standard container type with app-owner billing
## Create a container type with standard billing

Use standard billing when the developer or app owner tenant pays for consumption.
Use standard billing when the developer tenant pays for consumption.

Each tenant can create up to 25 container types in total. One of these can be a free trial container type; the rest are standard (billed) container types.

1. Create or identify the owning Microsoft Entra ID application.
1. Create the container type with the `standard` billing classification.
1. Attach an Azure billing profile with the SharePoint Embedded Visual Studio Code extension or an administrator-managed billing flow.
1. [Manage billing](../plan/choose-billing-model.md#manage-standard-billing-as-a-container-type-owner) on the container type. The SharePoint Embedded Visual Studio Code extension and the [SharePoint Embedded Model Context Protocol (MCP) server](sharepoint-embedded-mcp-server.md#available-tools) enable billing management for standard-billed container types. SharePoint Embedded Administrators and Global Administrators can also [use PowerShell to manage billing](../plan/choose-billing-model.md#manage-standard-billing-as-an-administrator).
1. Record the container type ID.
1. Continue to registration in the consuming tenant.

Expand All @@ -110,12 +111,12 @@ Use pass-through billing when the consuming tenant pays for consumption.
1. Create or identify the owning Microsoft Entra ID application.
1. Create the container type with the `directToCustomer` billing classification.
1. Register the container type in the consuming tenant.
1. Have the consuming tenant admin activate pay-as-you-go services.
1. Have a Billing Administrator or Global Administrator in the consuming tenant activate pay-as-you-go services.

> [!IMPORTANT]
> The consuming tenant must complete billing setup before a pass-through application can be used successfully.

The consuming tenant admin activates pay-as-you-go services in the Microsoft 365 admin center. In **Setup** > **Billing and licenses**, select **Activate pay-as-you-go services**.
A Billing Administrator or Global Administrator in the consuming tenant activates pay-as-you-go services in the Microsoft 365 admin center. In **Setup** > **Billing and licenses**, select **Activate pay-as-you-go services**.

![Microsoft 365 admin center Billing and licenses section with the Activate pay-as-you-go services option.](../images/SyntexActivatePAYGSetup.png)

Expand Down Expand Up @@ -144,7 +145,7 @@ For auth details, see [Configure authentication and authorization](configure-aut
| Container type name | Use a durable name that maps to your workload. |
| Owning application ID | Use the app registration that owns this type. |
| Application redirect URL | Use the URL where files from this app should redirect. |
| Billing model | Choose trial, standard, or pass-through at creation time. |
| Billing model | Choose trial, standard billing, or pass-through billing at creation time. |

> [!CAUTION]
> The container type ID and owning application ID can't be updated later.
Expand All @@ -168,9 +169,9 @@ Use the Microsoft Graph [Update fileStorageContainerType](/graph/api/filestorage

Use Microsoft Graph to list and update container types.

A non-administrator container type owner can update the container types they own.
A non-administrator container type owner can update container types they own. They can also [create and manage the standard billing profile](../plan/choose-billing-model.md#manage-standard-billing-as-a-container-type-owner).

You need owner or contributor access to billing subscriptions for billing changes.
The owner needs Owner or Contributor access to the Azure subscription for billing changes.

### Manage container types with Microsoft Graph

Expand All @@ -189,7 +190,7 @@ You can delete only trial container types; deletion of standard container types

## Understand billing dependency

For app-owner billing, the developer tenant attaches an Azure subscription and resource group.
For standard billing, the developer tenant attaches an Azure subscription and resource group.

For pass-through billing, the consuming tenant activates pay-as-you-go services.

Expand Down
Loading