OrbusInfinity Installation Guide
OrbusInfinity Installation Guide
GUIDE
OrbusInfinity Installation Guide
If you have any queries, you can contact the Orbus Software by email:
support@[Link]
2
OrbusInfinity Installation Guide
Contents
1 How to use this guide .......................................................................... 5
2 Reference materials ............................................................................. 5
3 Application interaction overview ................................................ 6
3.1 Authentication........................................................................................................... 7
3
OrbusInfinity Installation Guide
4
OrbusInfinity Installation Guide
2 Reference materials
As OrbusInfinity is tightly integrated with Microsoft products, we recommend to get
acquainted with available guides and training on Office products:
Microsoft 365 help and training
Visio help center
Word help center
Excel help center
SharePoint help center
5
OrbusInfinity Installation Guide
6
OrbusInfinity Installation Guide
3.1 Authentication
OrbusInfinity operates with Microsoft Azure technologies to best integrate into Microsoft 365
and your existing Azure infrastructure.
OrbusInfinity uses the OAuth 2.0 protocol to authenticate users against your existing Active
Directory to confirm that they are indeed valid and to allow OrbusInfinity to access
resources on their behalf. This means that the management of user access can remain in
the control of your Entra ID administrators.
Also, users can access OrbusInfinity using their existing Microsoft 365 accounts. This
removes the need for extra user accounts specific to OrbusInfinity itself.
Any controls and security measures that you have applied to your Active Directory will
apply to access OrbusInfinity, such as Two-Factor Authentication.
The application uses the authorization code with PKCE.
7
OrbusInfinity Installation Guide
Desktop browsers
The OrbusInfinity application is a web application that is fully supported on the following
desktop browsers:
Google Chrome (latest)
Microsoft Edge (Chromium, latest)
Requirement Description
Enable third-party When you log in to SharePoint, you log in to Azure. Webparts
cookies, pop-ups, and leverage this Azure log-in to provide silent SSO functionality.
redirects in your web That's why enabling third-party cookies, pop-ups, and redirects
browser in your web browser is required for the platform to work
properly.
8
OrbusInfinity Installation Guide
Visio Add-in
Important
Target audience of the below requirements is your organization’s Desktop Team.
Important
You can experience unexpected behavior with the Visio Add-in if the most recent
Windows updates are not installed. Ensure that your PC is fully up to date.
The OrbusInfinity Visio Add-in is an embedded Visio solution with custom commands and
features to visualize your repository data on diagrams.
9
OrbusInfinity Installation Guide
Requirement Description
To obtain Microsoft 365 application's version number, select
File > Account. In the lower-right corner of the window in the
About panel, the current value is specified.
.NET Framework v4.8 Verify you have this version of software or higher installed to be
able to use the Add-in.
Visual Studio 2010 Tools To run the Visio Add-in, you need Visual Studio 2010 Tools for
for Office Runtime Office Runtime installed. You can download the latest version
installed from the Microsoft Download Center.
Your OrbusInfinity OrbusInfinity doesn’t support proxy authentication at the
environment added to moment. If you use a proxy server that requires authentication,
the Allow List add your company’s OrbusInfinity environment URL to your
organization’s Allow List for the Visio Add-in to communicate
with OrbusInfinity.
The OrbusInfinity Export Tool (or Word Add-in) allows to insert OrbusInfinity data into
Microsoft Word documents. With the OrbusInfinity Import Tool (or Excel Add-in), you can
bulk import—create and update—data to OrbusInfinity, using the same file.
10
OrbusInfinity Installation Guide
Note
MS Office versions older than 2021 (e.g., 2016, 2019)
are not supported.
Add-ins access policy Export Tool and Import Tool are supplied via the Office Add-in
interface and do not require a traditional installer. The add-
ins are added to your Office Add-in Store for users with the
correct Microsoft 365 licenses to access them in both Online
and supported Desktop clients.
If your organization blocked access to Office Add-in, refer to
the Centralized Deployment requirements below.
Configure Centralized You need to deploy Office Add-ins to users and groups within
Deployment your organization. For this, you need to make sure Centralized
requirements Deployment requirements are properly configured in your
tenant.
We recommend that your system administrator follows the
Microsoft guidelines to confirm the compatibility with this
deployment approach.
Access the Add-ins If you want to use the add-ins online too—via Word or Excel
online Online clients, ensure to have a Microsoft 365 license that
grants access to Microsoft 365 Online.
11
OrbusInfinity Installation Guide
SharePoint Online
Important
To complete the below requirements, you need to be assigned administrator rights
in your SharePoint tenant.
SharePoint is one of the OrbusInfinity integration points where you store documents and
collaborate with colleagues on repository data. It facilitates the collection and update of
data and makes it accessible for contributors across your organization.
To set up SharePoint integration with your OrbusInfinity repository, you must meet the
following requirements.
12
OrbusInfinity Installation Guide
OrbusInfinity uses enterprise application in your Entra ID tenant to authenticate users and
to request access to Microsoft 365 resources.
Permission request type Description
13
OrbusInfinity Installation Guide
[Link] OrbusInfinity
The following permission sets are requested by the OrbusInfinity enterprise application in
Entra ID tenant.
Permission request Permissions Description
type
Office 365 Access selected The delegated [Link] permission can
SharePoint Online: site collections be used to link your OrbusInfinity instance
Delegated and ([Link]) specifically to its SharePoint site created
Application during provisioning. This increases the ability
Permissions of admins to control application access to
specific site collections. It uses the minimal
intersection of application and user
permissions. The application [Link]
permission serves the same purpose, but is
used when OrbusInfinity accesses
SharePoint by one of its services, not users.
Microsoft Graph: Read all users' These enable your designated OrbusInfinity
Application full profiles Administrator to import users and groups
Permissions Read group from your Entra ID into the application. These
(optional) memberships are only requested if not using the Entra ID
user provisioning functionality.
Entra ID Permissions Enable interaction To enable interaction with your Microsoft 365
with your Microsoft environment, your Global Administrator
365 environment needs to consent to the Entra ID permissions.
Use the link below to provide the required
admin consent:
[Link]
adminconsent?client_id=
9898412d-bd6e-4f62-8173-
c8eb05ca4d02&redirect_uri=https://
[Link]/consented
Note
Due to the retirement of Azure ACS for SharePoint authentication,
[Link] permissions are not supported.
14
OrbusInfinity Installation Guide
Note
You need to enable the below permissions only if you use integration with the
Solutions Hub.
15
OrbusInfinity Installation Guide
Requirement Description
Author Licence account You must have access to at least one account with a
to OrbusInfinity currently active Author Licence to OrbusInfinity.
Enabled REST API Feature OrbusInfinity REST API Feature Permission must be ON.
Permission
Microsoft Power You must have access to at least one account with a
Automate Premium currently active Microsoft Power Automate Premium
Subscription Subscription.
Approval from Admin You have to request approval from Admin during the setup
(see image).
OrbusInfinity Flow
Note
This requirement is optional and only applies if you purchased the OrbusInfinity
Flow.
Flow offers a self-serve integrations builder experience that changes the way you connect
with your integrations. It's the fastest way to create integrations with other apps you use.
You can build, customize, and manage your own unique integrations using templates for
hundreds of systems through the native integration marketplace.
16
OrbusInfinity Installation Guide
To set up Flow integration with your OrbusInfinity repository, you must meet the following
requirements.
Requirement Description
Premium A premium license is required for access to Flow Designer and Premium
License Integrations in Marketplace. For assistance with purchasing, please
purchased contact your Account Manager or Customer Success Manager.
Author You must have access to at least one account with a currently active
Licence Author Licence to OrbusInfinity.
account to
OrbusInfinity
Enabled REST OrbusInfinity REST API Feature Permission must be ON.
API Feature
Permission
Approval You have to request approval from Entra ID Admin during the setup.
from Admin
There are two ways to trigger an approval request:
17
OrbusInfinity Installation Guide
2) Provide a link and share it with OI users so they can forward it to their
Entra ID admin for approval or for new customer installation, where we
already deal with Entra ID admins, provide the link to them and ask
them to approve it during the installation call.
18
OrbusInfinity Installation Guide
Claims: user_impersonation,offline_access
The application (client) id: 8021abd9-d5b1-4a5a-b8ba-6c7e0a0169e9
Feature Admins have access to Flow by default. Users with an Author license can
Permissions request access/be granted access by Admins adding them to a suitable
granted by role with the Flow Permissions enabled. For more information, see Flow
Admin Feature Permissions.
Note
SharePoint permissions may block guest accounts’ access to SharePoint
sites. Check with your SharePoint admin if external sharing to guest accounts
is blocked on your SharePoint tenant. If so, set up an organizational account
for the Consultant.
19
OrbusInfinity Installation Guide
Organizational account
An organizational account is the same type of account that the users in your
organization have. To set up an organizational account, create an Entra ID account for
the Consultant as if they are a member of your organization.
Note
Your organization may have an application or approval process to create an
organizational account.
Consult your Entra ID Admin to decide what option is best for your
organization.
For your users to access the KB, some Entra ID permissions must be granted to the KB by
each user.
With default Entra ID settings, the required permissions do not require Admin consent and
users are able to approve the permissions themselves when first logging in to the KB.
You may however choose to do the permission grant on behalf of all your users, thereby
preventing users from having to go through this process. Alternatively, your Entra ID settings
may have been modified to prevent users approving apps themselves, in which case you
will need to do this on their behalf.
To carry out the permission grant for all of your users:
1. Go to the Knowledge Base and log in using an account with Entra ID Global
Administrator rights.
2. Review and grant the permissions.
20
OrbusInfinity Installation Guide
5 Installation overview
There are four key stages to provision an OrbusInfinity instance and integrate it with your
Microsoft 365 environment which must occur sequentially:
1. Customer environment setup
Usually, SharePoint Administrator and Entra ID Global Administrator prepare your
SharePoint site with which OrbusInfinity will interact, and install the SharePoint Webparts
App.
2. Permission grants and Add-ins setup
Entra ID Global Administrator with guidance from our support engineers enables
the OrbusInfinity access to the required Entra ID permissions on your environment and
the deployment of Visio and Excel Add-ins. These steps can be completed in less than
thirty minutes offline or during a call with our engineers.
3. OrbusInfinity site provisioning
After receiving all prerequisite information from your Administrators our support
engineers create an OrbusInfinity instance that is configured to work with your users
and integrate into your Microsoft 365.
4. Solutions Hub installation
Solutions Hub is a cloud platform that provides Solutions to business challenges related
to common enterprise transformation. It presents a catalog of ready-made Solutions to
provide outcomes for various enterprise architecture and transformation use cases,
systems, and roles.
21
OrbusInfinity Installation Guide
Note
Once you complete the instructions in the next section, our engineers will proceed
with the creation of an OrbusInfinity instance. Ensure to gather all the required
information in the end of the section and send it to your Orbus account manager or
technical contact.
Remember that due to the retirement of Azure ACS for SharePoint authentication, the
[Link] persmission is no longer supported and you have to consent to the
[Link] permission.
1. Create a new SharePoint Site Collection using the Communication Site Modern
template.
2. Enable external site sharing for the newly created SharePoint site, so Orbus Professional
Services Consultants can access it. For more information, see this Microsoft guide.
Note
Make sure to add Orbus Consultants as Site Owner of the newly created SharePoint
site, so they are able to upload content and carry out configuration.
22
OrbusInfinity Installation Guide
23
OrbusInfinity Installation Guide
5. Add the app to the list of available apps. It is possible you need to request the App to
be added by the SharePoint Administrator.
Note
For FedRAMP customers, there is an additional step required: creating a new hidden
list containing some configuration required by the webparts to correctly work on
FedRAMP instances.
1. Download and install the SharePoint PnP cmdlets from here.
2. Run the following commands to create the mentioned hidden list:
$listTitle = "OrbusWebpartsConfiguration"
$fieldName = "orbusInfinityEnvironmentType"
$titleFieldName = "Title"
$titleFieldValue = "Configuration"
$environmentType = “fedRAMP”
24
OrbusInfinity Installation Guide
Note
It is possible that the OrbusInfiniy Webparts app is added to the App catalog
without access to external users by default. To give external users access to your
SharePoint site, you will need to share the App with them. To do so:
1. Go to:
{YourSharePointDomain}/sites/appcatalog/_layouts/15/[Link]
/manageApps
2. Search for “OrbusInfinity Webparts” app on the list, right click on it, select Share,
and include the group assigned to the external users with "Can view" access.
25
OrbusInfinity Installation Guide
To complete this stage of the installation, Orbus Support Engineers contact you to:
Grant Entra ID permissions for OrbusInfinity
Configure Site Provisioning
Configure User Provisioning
Turn off Assignment required option
Install the Import Tool (Excel Add-in) and Export Tool (Word Add-in)
This section describes the process of permission grants and Add-ins setup steps; however,
we can also offer this via an installation call if required.
To enable interaction with your Microsoft 365 environment, Orbus Support Engineers direct
the Global Administrator to the OrbusInfinity admin consent page where the permission
grant is complete:
1. Use the link below to open the OrbusInfinity admin consent page:
[Link]
4f62-8173-
c8eb05ca4d02&redirect_uri=[Link]
Remember to substitute the {tenantId} with the ID of your tenant.
26
OrbusInfinity Installation Guide
Accepting the requested permissions will enable all users under the OrbusInfinity instance
to use the app.
Once the scopes are requested and consented to, an Enterprise Application is created in
your Azure portal.
This is the application you will have to bind to your SharePoint site.
27
OrbusInfinity Installation Guide
After this, your SharePoint Administrator has to bind your Azure application to your
SharePoint site.
1. Go to [Link] and sign in.
2. Set the HTTP request method to POST.
3. In the request URL field, enter
[Link]
28
OrbusInfinity Installation Guide
Note
Remember to replace {site-id} with your actual site ID. If you don’t know it, you
can retrieve it by:
a. Go to your SharePoint site URL.
i. Example:
[Link]
b. Append the SharePoint site URL with /_api/site/id.
i. Example:
[Link]
/_api/site/id
c. Press Enter.
The site ID will be retrieved in the URL. Copy it and replace it with {site-id} in the
request URL field.
{
"roles": ["read", "write", "manage"],
"grantedToIdentities": [{
"application": {
"id": "9898412d-bd6e-4f62-8173-c8eb05ca4d02",
"displayName": "OrbusInfinity"
}
}]
}
Note
"id" = enterprise application id
"displayName" = enterprise application name
Note
The operation is successful when you receive the Created-201 response.
29
OrbusInfinity Installation Guide
Other responses (4XX, 5XX, etc.) may indicate insufficient privileges or missing
consent for required permissions. In such cases, please contact Support for
further assistance.
Once done, the OrbusInfinity instance will be bound to the SharePoint site under
[Link] scope.
30
OrbusInfinity Installation Guide
Your account manager passes this information to the Orbus Support Engineer responsible
for your installation so that they can proceed with creating an OrbusInfinity instance.
Azure User Provisioning uses SCIM—an industry-wide standard for managing user identities
in cloud-based applications.
1. In the Azure Portal, on the Azure Active Directory Enterprise Application blade,
select New application. Alternatively, select the following link to go to the correct
location:
[Link]
egory/topapps
2. Under Add your own app, select Non-gallery application and enter a name for the new
application and select Add.
Orbus recommends using OrbusInfinity – User Provisioning as the application’s name.
31
OrbusInfinity Installation Guide
3. When the application is created, in the Provisioning section, select Get started.
32
OrbusInfinity Installation Guide
33
OrbusInfinity Installation Guide
9. In the Edit Attribute dialog box, in the Source attribute list, select objectId, and select
OK.
34
OrbusInfinity Installation Guide
[Link]
bd6e-4f62-8173-
c8eb05ca4d02&scope=[Link]
[Link]/[Link]&redirect_uri=[Link]
Note
Remember to replace {tenantId} with the ID of your tenant.
35
OrbusInfinity Installation Guide
Note
The synchronization engine runs on a schedule and changes can take up to
40 minutes to synchronize across to OrbusInfinity.
Note
To be able to modify the Assignment required? option, you must be an Entra ID
Global Administrator and have an Entra ID Premium P1 or P2 license.
36
OrbusInfinity Installation Guide
Note
This step is optional and only required if the Office 365 Store is disabled for Users.
The tools use the new cross-platform Office JS API. Unlike the older Office COM Add-Ins, the
add-ins do not require an installer to the user’s machine. Microsoft recommends
managing all new application deployments via Office 365 Centralized Deployment. This
guarantees the easiest and cleanest integration with your copy of Office, both Online
and Desktop.
1. Deploy the add-ins to your Microsoft 365 Admin Center:
a. Log into the Microsoft 365 Admin Center.
b. In the navigation menu, select Settings > Integrated Apps.
a. At the top of the page, select Add-ins.
b. On the Add-ins page, select Deploy Add-in > Next.
c. On the Deploy a new add-in page, select Choose from the Store.
d. In the search box, type OrbusInfinity Import Tool or OrbusInfinity Export Tool, and in
the search results, select Add > Continue.
e. Select who can have access to the add-ins and select Deploy. It’s strongly
recommended that the person deploying the add-ins adds themselves to the list of
users to help simplify deployment validation. The add-ins are now available to the
users you selected.
2. Validate deployment:
a. Open Excel or Word (either desktop or online) and start a new workbook or
document.
b. On the Insert tab, select My Add-ins (or Add-ins for online).
If the installation is successful and all the requirements are met, the Add-In is now
available under the Admin Managed section.
37
OrbusInfinity Installation Guide
Note
Replace the <InstanceName> placeholder with your organization’s instance of
Solutions Hub. Orbus Support will communicate the URL of your Solutions Hub
instance during the OrbusInfinity installation.
2. Once logged in, in the upper-right corner of the page, select your account drop-down
and select Admin Centre.
38
OrbusInfinity Installation Guide
3. In the navigation pane, select Tenant Management > List of Pages, and then select
Granting Admin Consent for the Microsoft Graph Permissions.
4. The page that opens provides an overview of how Solutions Hub interacts with Microsoft
Graph and the list of the Microsoft Graph permissions required for using certain
integration solutions with the Microsoft365 applications. Review the permissions and
select GRANT CONSENT for each application. This will grant admin consent to the
Solutions Hub for the specific delegated Graph permissions on behalf of all users of
your organization.
In practice, the Microsoft Graph permissions used by the Solutions Hub do not require
admin consent. Users that will activate and run solutions can grant those permissions
individually for most organizations. In some particular cases, certain organizations, in the
Entra ID settings, have disabled the ability for the end users to directly grant consent for
any Graph permissions to third-party applications. They then require an Entra ID Global
Administrator to grant admin consent instead. In that case, the Entra ID Global
Administrator can grant admin consent for all permissions needed to the Solutions Hub
using this page in the Admin Centre.
39