troubleshootingcorporateflipbook

SharePoint Says Embedding Isn't Allowed? How to Fix It for Flipbooks

SharePoint shows a blank frame or a warning when you paste a flipbook embed code. This article explains the real causes, the exact admin settings that allow trusted domains, a step by step fix, and what to do when your tenant policy cannot change.

SharePoint Says Embedding Isn't Allowed? How to Fix It for Flipbooks
Cristian Da Conceicao
Founder of Flipbooks AI

You paste the embed code, hit republish, and SharePoint answers with a grey box or a message saying embedding isn't allowed. It is a frustrating moment, especially when the interactive brochure you built in Flipbooks AI looks perfect everywhere else. The good news: this is almost never a bug. It is a security setting, and it can be changed by the right person in about five minutes.

This article walks through why SharePoint blocks the embed, who can fix it, the exact steps, and what to do if your IT team says no.

Why SharePoint Blocks Your Embed

A blank grey frame on a laptop screen where an embedded document should appear

SharePoint Online treats every external iframe as a possible risk. An iframe loads a page from another domain inside your page, so Microsoft lets site owners decide which domains are trusted. If the domain of your flipbook is not on that list, the Embed web part refuses to render it.

The result is one of three symptoms:

  • A blank or grey rectangle where the flipbook should be
  • A message that says the content can't be embedded or that embedding isn't allowed
  • An embed that works in edit mode but disappears for visitors

💡 Pro tip: If the frame is blank only for some visitors, suspect a browser extension or a firewall rule. If it is blank for everyone, suspect the SharePoint domain list.

The HTML Field Security Setting

The control behind this behavior is called HTML Field Security. It lives in the site collection settings and lets administrators choose between blocking all external iframes, allowing only listed domains, or allowing any domain.

Tenant Level Restrictions

Some organizations also apply restrictions at the tenant level. In that case, a site owner cannot override the policy from their own site, and a SharePoint administrator has to make the change.

Content Security Policy on the Host

Occasionally the problem is not SharePoint at all. The page you embed can send headers that forbid being framed. A reliable flipbook host allows embedding by design, which is the whole point of the format.

Who Can Fix It

A technician with a tablet in a tidy server room corridor

Not everyone can change the setting. Here is the quick map of who does what.

RoleCan add an Embed web partCan change allowed domainsCan change tenant policy
Site visitorNoNoNo
Site memberYes, if allowedNoNo
Site ownerYesSometimesNo
Site collection adminYesYesNo
SharePoint adminYesYesYes

If you are a site member and the option is greyed out, send the steps below to your site collection administrator. It saves a day of back and forth.

Step by Step: Allow the Domain

An overhead view of a conference table with printed policy documents and a laptop

These steps apply to modern SharePoint Online sites. Menu labels shift slightly between releases, so use them as a map rather than a script.

Open the Site Settings

  1. Open your SharePoint site and select the gear icon in the top right.
  2. Choose Site information, then View all site settings.
  3. Under Site Collection Administration, select HTML Field Security.

If you do not see that link, you are not a site collection administrator. Ask one to follow these steps.

Pick the Right Option

You will see a list of choices. The usual ones are:

  • Do not allow contributors to insert iframes from any external domain
  • Allow contributors to insert iframes only from the domains listed
  • Allow contributors to insert iframes from any domain

Choose the second option. It keeps the policy tight while letting your flipbook through.

Add the Flipbook Domain

Paste the domain that hosts your flipbook into the list, without the https:// prefix or any path. Save the page. Use the domain exactly as it appears in the iframe src attribute of your embed code.

⚠️ Warning: Never choose "any domain" just to make the error vanish. It opens the site to every third party iframe a contributor might paste.

Refresh and Retest

  1. Return to the page that holds the Embed web part.
  2. Reload with Ctrl + F5 to clear cached policy.
  3. Edit the web part, paste the embed code again, and republish.

Changes can take a few minutes to apply, so give it time before assuming it failed.

Get the Flipbook Embed Code Ready

A manager smiling while reading an interactive brochure on a tablet

The fix only matters if you have a flipbook to show. Here is how to create one in a few minutes.

How to Create a Flipbook with Flipbooks AI

  1. Open Flipbooks AI and create an account.
  2. Upload your PDF with the PDF to Flipbook Converter. Conversion happens automatically and keeps your layout and fonts.
  3. Customize the look: add your logo, pick brand colors, choose a page turn effect, and drop in audio or video where it helps.
  4. Open the sharing panel and copy the iframe code. The Embed Flipbook on Website tool explains each option.
  5. If the content is private, switch on password protection before you publish.

Every flipbook is mobile responsive and has no watermarks, which matters on an intranet where a polished look builds trust.

Which Embed Option Fits

OptionBest forWorks in SharePoint
Iframe embed codeIntranet pages, news postsYes, after the domain is allowed
Direct linkQuick sharing in Teams or emailYes, always
Link in a Quick Links web partLocked down tenantsYes, always
Downloadable PDFOffline readingYes, as a file

Common Mistakes That Look Like Blocks

Hands typing at a desk next to a handwritten checklist

Before you escalate, run through this list. Half of all embed tickets come from one of these.

Pasting the Wrong Code

The Embed web part expects either a full iframe tag or a plain URL from a supported provider. Pasting a script tag will fail because scripts are filtered. Always use the iframe version.

Using Http Instead of Https

SharePoint is served over https, and browsers block mixed content. If your embed points to an http address, it will not load.

Typing the Domain with Extra Parts

The allowed list wants a domain, not a full address. Entering https://example.com/book/123 will not match. Enter example.com only.

Forgetting Subdomains

A domain such as view.example.com is not covered by example.com unless your policy allows suffixes. Add the exact host you see in the iframe.

Testing in the Wrong Browser Profile

An old cached session can keep serving the previous policy. Try a private window before you change anything else.

✅ Best practice: Keep a short document listing every approved embed domain, who approved it, and the date. Audits become painless.

When You Cannot Change the Policy

Colleagues gathered around a monitor in a glass walled meeting room

Some security teams refuse to allow external domains, and that is a valid decision. You still have working options.

Link Instead of Embed

A clear button or Quick Links tile that opens the flipbook in a new tab gives readers the same page turning experience. It also avoids the iframe rules completely. Readers on phones often prefer it because the flipbook fills the full screen.

Use Teams Tabs

Adding the flipbook link as a website tab inside Microsoft Teams is often allowed even where SharePoint iframes are not, because it follows a different policy path. Check with your administrator first.

Ask for a Narrow Exception

Security teams respond well to specific requests. Bring them a short case:

  • The exact domain you need
  • The business reason, such as an employee handbook or product catalog
  • The fact that you can protect content with a password
  • A proposal to limit it to one site collection

A narrow request is far easier to approve than a general one.

Comparing Your Choices

ApproachSetup timePolicy change neededReader experience
Embed with allowed domain10 minutesYes, one domainFlipbook sits inside the page
Quick Links tile2 minutesNoOpens in a new tab
Teams website tab5 minutesSometimesOpens inside Teams
Attach PDF only1 minuteNoStatic file, no page turning

Real World Examples

An HR specialist reviewing a digital employee handbook on a wide monitor

A few scenarios show how teams apply this.

An Employee Handbook

An HR team keeps its handbook as a PDF that nobody opens. They turn it into a flipbook with the Training Manual Flipbook tool, embed it on the onboarding page, and new hires can flip through it on any device. When policies change, they update the source and the embedded link stays the same.

A Sales Catalog

A sales director wants reps to browse the latest line during calls. The Digital Catalog Maker produces a flipbook, and the team pins it on the sales hub in SharePoint. Reps present it live on screen.

A Quarterly Report

Finance publishes results to leadership only. They use a Corporate Report Maker flipbook with a password, and share the embed with a protected site so only the right people see it.

Keep Private Content Safe

A padlock on a metal filing cabinet in an office

Allowing a domain does not mean opening the content to everyone. Layer your protection.

  • Password protect the flipbook so a leaked link is useless on its own
  • Limit the SharePoint site to the audience that needs it
  • Review analytics to see who opens documents and how long they stay, available on the Professional plan, listed on the pricing page
  • Allow offline downloads only for files that are safe to leave the intranet

This mix gives security teams what they want and gives readers a smooth experience.

Final Checklist Before You Escalate

A sales director presenting a digital catalog on a tablet in a boardroom

Run this list top to bottom. It resolves most cases.

  1. Is the code an iframe, not a script?
  2. Does the address start with https?
  3. Is the exact host listed in HTML Field Security?
  4. Did you reload with a hard refresh or a private window?
  5. Is a tenant policy overriding the site setting?
  6. Have you tried the link alternative while waiting for approval?

If every answer is yes and the frame is still blank, ask your SharePoint administrator to check tenant settings and the browser console for a blocked frame message. That message usually names the exact rule that stopped the embed.

Ready to Publish Your Flipbook

SharePoint blocks embeds on purpose, and with one approved domain you can show a polished flipbook right on your intranet page. Until then, a simple link works just as well.

Ready to create your first flipbook? Get started for free on Flipbooks AI. Browse all flipbook tools to find the right template for handbooks, catalogs, and reports, or compare pricing plans to pick the one that suits your team.

Share this article