The process of building custom applications and tools that interact with Microsoft SharePoint, including SharePoint Online in Microsoft 365.
Based on Can't display SharePoint pages in iFrame - SharePoint | Microsoft Learn, SharePoint Online pages cannot be loaded inside an iFrame when they originate from a different domain. This is by design because SharePoint sets the X-FRAME-OPTIONS HTTP header to SAMEORIGIN.
Therefore, embedding the complete SharePoint site in an external webpage like this would not work:
<iframe src="https://contoso.sharepoint.com/sites/MySite"></iframe>
Microsoft also notes that overriding this behavior with AllowFraming is not recommended for security reasons, and some SharePoint functionality may not work correctly when loaded in an iFrame.
So, if your requirement is to embed the entire SharePoint Online site inside an external website on a different domain and retain normal SharePoint functionality, this is not a supported scenario.
As alternatives, you can:
- Link users directly to the SharePoint site so it opens normally in the browser.
- Build the required functionality into your external application using SharePoint APIs or Microsoft Graph APIs.
I hope this clarifies the limitation and the available alternatives.