You paste the embed code, hit republish, and SharePoint answers with a grey box or a message saying embedding isn't allowed. It is a frustrating moment, especially when the interactive brochure you built in Flipbooks AI looks perfect everywhere else. The good news: this is almost never a bug. It is a security setting, and it can be changed by the right person in about five minutes.
This article walks through why SharePoint blocks the embed, who can fix it, the exact steps, and what to do if your IT team says no.
Why SharePoint Blocks Your Embed

SharePoint Online treats every external iframe as a possible risk. An iframe loads a page from another domain inside your page, so Microsoft lets site owners decide which domains are trusted. If the domain of your flipbook is not on that list, the Embed web part refuses to render it.
The result is one of three symptoms:
- A blank or grey rectangle where the flipbook should be
- A message that says the content can't be embedded or that embedding isn't allowed
- An embed that works in edit mode but disappears for visitors
💡 Pro tip: If the frame is blank only for some visitors, suspect a browser extension or a firewall rule. If it is blank for everyone, suspect the SharePoint domain list.
The HTML Field Security Setting
The control behind this behavior is called HTML Field Security. It lives in the site collection settings and lets administrators choose between blocking all external iframes, allowing only listed domains, or allowing any domain.
Tenant Level Restrictions
Some organizations also apply restrictions at the tenant level. In that case, a site owner cannot override the policy from their own site, and a SharePoint administrator has to make the change.
Content Security Policy on the Host
Occasionally the problem is not SharePoint at all. The page you embed can send headers that forbid being framed. A reliable flipbook host allows embedding by design, which is the whole point of the format.
Who Can Fix It

Not everyone can change the setting. Here is the quick map of who does what.
| Role | Can add an Embed web part | Can change allowed domains | Can change tenant policy |
|---|
| Site visitor | No | No | No |
| Site member | Yes, if allowed | No | No |
| Site owner | Yes | Sometimes | No |
| Site collection admin | Yes | Yes | No |
| SharePoint admin | Yes | Yes | Yes |
If you are a site member and the option is greyed out, send the steps below to your site collection administrator. It saves a day of back and forth.
Step by Step: Allow the Domain

These steps apply to modern SharePoint Online sites. Menu labels shift slightly between releases, so use them as a map rather than a script.
Open the Site Settings
- Open your SharePoint site and select the gear icon in the top right.
- Choose Site information, then View all site settings.
- Under Site Collection Administration, select HTML Field Security.
If you do not see that link, you are not a site collection administrator. Ask one to follow these steps.
Pick the Right Option
You will see a list of choices. The usual ones are:
- Do not allow contributors to insert iframes from any external domain
- Allow contributors to insert iframes only from the domains listed
- Allow contributors to insert iframes from any domain
Choose the second option. It keeps the policy tight while letting your flipbook through.
Add the Flipbook Domain
Paste the domain that hosts your flipbook into the list, without the https:// prefix or any path. Save the page. Use the domain exactly as it appears in the iframe src attribute of your embed code.
⚠️ Warning: Never choose "any domain" just to make the error vanish. It opens the site to every third party iframe a contributor might paste.
Refresh and Retest
- Return to the page that holds the Embed web part.
- Reload with Ctrl + F5 to clear cached policy.
- Edit the web part, paste the embed code again, and republish.
Changes can take a few minutes to apply, so give it time before assuming it failed.
Get the Flipbook Embed Code Ready

The fix only matters if you have a flipbook to show. Here is how to create one in a few minutes.
How to Create a Flipbook with Flipbooks AI
- Open Flipbooks AI and create an account.
- Upload your PDF with the PDF to Flipbook Converter. Conversion happens automatically and keeps your layout and fonts.
- Customize the look: add your logo, pick brand colors, choose a page turn effect, and drop in audio or video where it helps.
- Open the sharing panel and copy the iframe code. The Embed Flipbook on Website tool explains each option.
- If the content is private, switch on password protection before you publish.
Every flipbook is mobile responsive and has no watermarks, which matters on an intranet where a polished look builds trust.
Which Embed Option Fits
| Option | Best for | Works in SharePoint |
|---|
| Iframe embed code | Intranet pages, news posts | Yes, after the domain is allowed |
| Direct link | Quick sharing in Teams or email | Yes, always |
| Link in a Quick Links web part | Locked down tenants | Yes, always |
| Downloadable PDF | Offline reading | Yes, as a file |
Common Mistakes That Look Like Blocks

Before you escalate, run through this list. Half of all embed tickets come from one of these.
Pasting the Wrong Code
The Embed web part expects either a full iframe tag or a plain URL from a supported provider. Pasting a script tag will fail because scripts are filtered. Always use the iframe version.
Using Http Instead of Https
SharePoint is served over https, and browsers block mixed content. If your embed points to an http address, it will not load.
Typing the Domain with Extra Parts
The allowed list wants a domain, not a full address. Entering https://example.com/book/123 will not match. Enter example.com only.
Forgetting Subdomains
A domain such as view.example.com is not covered by example.com unless your policy allows suffixes. Add the exact host you see in the iframe.
Testing in the Wrong Browser Profile
An old cached session can keep serving the previous policy. Try a private window before you change anything else.
✅ Best practice: Keep a short document listing every approved embed domain, who approved it, and the date. Audits become painless.
When You Cannot Change the Policy

Some security teams refuse to allow external domains, and that is a valid decision. You still have working options.
Link Instead of Embed
A clear button or Quick Links tile that opens the flipbook in a new tab gives readers the same page turning experience. It also avoids the iframe rules completely. Readers on phones often prefer it because the flipbook fills the full screen.
Use Teams Tabs
Adding the flipbook link as a website tab inside Microsoft Teams is often allowed even where SharePoint iframes are not, because it follows a different policy path. Check with your administrator first.
Ask for a Narrow Exception
Security teams respond well to specific requests. Bring them a short case:
- The exact domain you need
- The business reason, such as an employee handbook or product catalog
- The fact that you can protect content with a password
- A proposal to limit it to one site collection
A narrow request is far easier to approve than a general one.
Comparing Your Choices
| Approach | Setup time | Policy change needed | Reader experience |
|---|
| Embed with allowed domain | 10 minutes | Yes, one domain | Flipbook sits inside the page |
| Quick Links tile | 2 minutes | No | Opens in a new tab |
| Teams website tab | 5 minutes | Sometimes | Opens inside Teams |
| Attach PDF only | 1 minute | No | Static file, no page turning |
Real World Examples

A few scenarios show how teams apply this.
An Employee Handbook
An HR team keeps its handbook as a PDF that nobody opens. They turn it into a flipbook with the Training Manual Flipbook tool, embed it on the onboarding page, and new hires can flip through it on any device. When policies change, they update the source and the embedded link stays the same.
A Sales Catalog
A sales director wants reps to browse the latest line during calls. The Digital Catalog Maker produces a flipbook, and the team pins it on the sales hub in SharePoint. Reps present it live on screen.
A Quarterly Report
Finance publishes results to leadership only. They use a Corporate Report Maker flipbook with a password, and share the embed with a protected site so only the right people see it.
Keep Private Content Safe

Allowing a domain does not mean opening the content to everyone. Layer your protection.
- Password protect the flipbook so a leaked link is useless on its own
- Limit the SharePoint site to the audience that needs it
- Review analytics to see who opens documents and how long they stay, available on the Professional plan, listed on the pricing page
- Allow offline downloads only for files that are safe to leave the intranet
This mix gives security teams what they want and gives readers a smooth experience.
Final Checklist Before You Escalate

Run this list top to bottom. It resolves most cases.
- Is the code an iframe, not a script?
- Does the address start with https?
- Is the exact host listed in HTML Field Security?
- Did you reload with a hard refresh or a private window?
- Is a tenant policy overriding the site setting?
- Have you tried the link alternative while waiting for approval?
If every answer is yes and the frame is still blank, ask your SharePoint administrator to check tenant settings and the browser console for a blocked frame message. That message usually names the exact rule that stopped the embed.
Ready to Publish Your Flipbook
SharePoint blocks embeds on purpose, and with one approved domain you can show a polished flipbook right on your intranet page. Until then, a simple link works just as well.
Ready to create your first flipbook? Get started for free on Flipbooks AI. Browse all flipbook tools to find the right template for handbooks, catalogs, and reports, or compare pricing plans to pick the one that suits your team.