0% found this document useful (0 votes)
17 views39 pages

OrbusInfinity Installation Guide

The OrbusInfinity Installation Guide provides comprehensive instructions for integrating and installing the OrbusInfinity application, including prerequisites, requirements, and setup for Microsoft 365 and Azure environments. It details necessary configurations for SharePoint, user permissions, and the use of various tools like the Visio Add-in and Export/Import Tools. The guide is intended for administrators and project leads involved in the deployment of OrbusInfinity within their organizations.

Uploaded by

garbage
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
17 views39 pages

OrbusInfinity Installation Guide

The OrbusInfinity Installation Guide provides comprehensive instructions for integrating and installing the OrbusInfinity application, including prerequisites, requirements, and setup for Microsoft 365 and Azure environments. It details necessary configurations for SharePoint, user permissions, and the use of various tools like the Visio Add-in and Export/Import Tools. The guide is intended for administrators and project leads involved in the deployment of OrbusInfinity within their organizations.

Uploaded by

garbage
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

ORBUSINFINITY INSTALLATION

GUIDE
OrbusInfinity Installation Guide

Product Release Information


Product: OrbusInfinity®
Document Release Number: 2.11
Document Release Date: 11 June 2025
Copyright © 2025 by Orbus Software

All Rights Reserved


No part of this publication may be reproduced, distributed, or transmitted in any form or by
any means, including photocopying, recording, or other electronic or mechanical methods,
without the prior written permission of the publisher, except in the case of brief quotations
embodied in critical reviews and certain other noncommercial uses permitted by copyright
law.

If you have any queries, you can contact the Orbus Software by email:
support@[Link]

2
OrbusInfinity Installation Guide

Contents
1 How to use this guide .......................................................................... 5
2 Reference materials ............................................................................. 5
3 Application interaction overview ................................................ 6
3.1 Authentication........................................................................................................... 7

4 Prerequisites and requirements .................................................. 8


4.1 Application requirements ................................................................................ 8
Desktop browsers ................................................................................................................... 8
Visio Add-in ..................................................................................................................................9
Export and Import Tools ....................................................................................................10
4.2 Microsoft 365 and Azure requirements ............................................... 11
SharePoint Online ................................................................................................................... 12
Entra ID Enterprise App ....................................................................................................... 13
Power Automate connector........................................................................................... 15
OrbusInfinity Flow ................................................................................................................... 16
Orbus Professional Services access ........................................................................ 19
OrbusInfinity Knowledge Base access setup ..................................................20

5 Installation overview ........................................................................... 21


6 Customer environment setup ..................................................... 22
6.1 SharePoint site setup ........................................................................................ 22
6.2 SharePoint Webparts installation ........................................................... 22

7 Permission grants and Add-in setup .....................................26


7.1 Entra ID permissions .......................................................................................... 26
Bind SharePoint Site to OrbusInfinity ....................................................................... 28
7.2 OrbusInfinity site provisioning ................................................................... 30

3
OrbusInfinity Installation Guide

7.3 User provisioning................................................................................................... 31


Configure user provisioning using SCIM ............................................................... 31
Non-SCIM user provisioning .......................................................................................... 35
Manage OrbusInfinity users .......................................................................................... 36
7.4 Turn off Assignment required option .................................................. 36
7.5 Import and Export Tools installation ..................................................... 37

8 Solutions Hub installation .............................................................. 38

4
OrbusInfinity Installation Guide

1 How to use this guide


The OrbusInfinity Installation Guide contains reference on how OrbusInfinity interacts with
your environment and installation instructions to prepare for OrbusInfinity integration to
your systems.
This guide is intended for Project Lead, SharePoint Site Collection Administrator, Office 365
Administrator, and Entra ID Administrator.
Tips, information of special importance, and information that may apply only in special
cases can be found in Note . Information that is essential to the completion of a task or
to access the feature can be found in Important Note .

2 Reference materials
As OrbusInfinity is tightly integrated with Microsoft products, we recommend to get
acquainted with available guides and training on Office products:
 Microsoft 365 help and training
 Visio help center
 Word help center
 Excel help center
 SharePoint help center

5
OrbusInfinity Installation Guide

3 Application interaction overview


OrbusInfinity is a cloud-based application that provides seamless integration with your
existing Microsoft 365 application suite and Azure Active Directory using the following
integration points:

OrbusInfinity Visio Add-In To provide a modeling environment that


synchronizes data with the OrbusInfinity
repository.
OrbusInfinity Export Tool To enable the export of data from the
OrbusInfinity repository into a Word document.
OrbusInfinity Import Tool To enable the import of data into OrbusInfinity
from the Excel desktop.
Modern Web Browsers To use the OrbusInfinity application portal for
repository management.
Azure Active Directory To authenticate users, request Tokens, and
Enterprise Applications enable user and group management in
OrbusInfinity.
Other third-party applications Business tools that you can integrate with the
Solutions Hub to realize key use cases.

6
OrbusInfinity Installation Guide

OrbusInfinity Export Tool To enable the export of data from the


OrbusInfinity repository into an online Word
document.
OrbusInfinity Import Tool To enable the import of data into OrbusInfinity
from your Excel files stored in the cloud.
SharePoint 365 Applications To provide OrbusInfinity functionality via web
parts, enhanced Visio Online document viewing,
and to enable interaction with documents
without the need to store them in OrbusInfinity.

3.1 Authentication
OrbusInfinity operates with Microsoft Azure technologies to best integrate into Microsoft 365
and your existing Azure infrastructure.
OrbusInfinity uses the OAuth 2.0 protocol to authenticate users against your existing Active
Directory to confirm that they are indeed valid and to allow OrbusInfinity to access
resources on their behalf. This means that the management of user access can remain in
the control of your Entra ID administrators.
Also, users can access OrbusInfinity using their existing Microsoft 365 accounts. This
removes the need for extra user accounts specific to OrbusInfinity itself.
Any controls and security measures that you have applied to your Active Directory will
apply to access OrbusInfinity, such as Two-Factor Authentication.
The application uses the authorization code with PKCE.

7
OrbusInfinity Installation Guide

4 Prerequisites and requirements


For smooth installation of OrbusInfinity, complete all of the below requirements first:
 Application requirements – Set up access to OrbusInfinity web application and
Office Add-ins
 Microsoft 365 and Azure requirements – Configure necessary integrations and
access permissions

4.1 Application requirements


The following are required to access the OrbusInfinity web application and use the ancillary
Office Add-ins for performing tasks such as Visio diagram creation, data export to Word,
and Excel data import.

Desktop browsers
The OrbusInfinity application is a web application that is fully supported on the following
desktop browsers:
 Google Chrome (latest)
 Microsoft Edge (Chromium, latest)

Requirement Description
Enable third-party When you log in to SharePoint, you log in to Azure. Webparts
cookies, pop-ups, and leverage this Azure log-in to provide silent SSO functionality.
redirects in your web That's why enabling third-party cookies, pop-ups, and redirects
browser in your web browser is required for the platform to work
properly.

8
OrbusInfinity Installation Guide

Visio Add-in
Important
Target audience of the below requirements is your organization’s Desktop Team.

Important
You can experience unexpected behavior with the Visio Add-in if the most recent
Windows updates are not installed. Ensure that your PC is fully up to date.

The OrbusInfinity Visio Add-in is an embedded Visio solution with custom commands and
features to visualize your repository data on diagrams.

Download Visio Add-in MSI installer


To be able to install Visio Add-in, you need to have the below in place.
Requirement Description
MSI installer  Visio Add-in requires installing locally on users' machine via
downloaded an MSI installer. Download this from your OrbusInfinity web
application (see the screenshot above).
 If your organization has blocked the ability to install
applications on user machines, the Visio Add-in will require
central distribution by your system administrator.
Supported Visio version  Visio 2016 (v16.0; Professional, Office 365)
 Visio Online Plan 2 (Desktop, Office 365)
 Visio 2019 (v16.0; Professional)
 Visio 2021 (Professional)

9
OrbusInfinity Installation Guide

Requirement Description
To obtain Microsoft 365 application's version number, select
File > Account. In the lower-right corner of the window in the
About panel, the current value is specified.
.NET Framework v4.8 Verify you have this version of software or higher installed to be
able to use the Add-in.
Visual Studio 2010 Tools To run the Visio Add-in, you need Visual Studio 2010 Tools for
for Office Runtime Office Runtime installed. You can download the latest version
installed from the Microsoft Download Center.
Your OrbusInfinity OrbusInfinity doesn’t support proxy authentication at the
environment added to moment. If you use a proxy server that requires authentication,
the Allow List add your company’s OrbusInfinity environment URL to your
organization’s Allow List for the Visio Add-in to communicate
with OrbusInfinity.

Export and Import Tools


Important
Target audience of the below requirements is your organization’s Office 365 Admin
Team.

The OrbusInfinity Export Tool (or Word Add-in) allows to insert OrbusInfinity data into
Microsoft Word documents. With the OrbusInfinity Import Tool (or Excel Add-in), you can
bulk import—create and update—data to OrbusInfinity, using the same file.

10
OrbusInfinity Installation Guide

To integrate the tools with OrbusInfinity, review the below:


Requirement Description
Supported versions  Online clients (included as part of Microsoft 365
subscriptions)
 365 Edition 64bit or 32bit
 Office 2021 and above

Note
MS Office versions older than 2021 (e.g., 2016, 2019)
are not supported.
Add-ins access policy Export Tool and Import Tool are supplied via the Office Add-in
interface and do not require a traditional installer. The add-
ins are added to your Office Add-in Store for users with the
correct Microsoft 365 licenses to access them in both Online
and supported Desktop clients.
If your organization blocked access to Office Add-in, refer to
the Centralized Deployment requirements below.
Configure Centralized You need to deploy Office Add-ins to users and groups within
Deployment your organization. For this, you need to make sure Centralized
requirements Deployment requirements are properly configured in your
tenant.
We recommend that your system administrator follows the
Microsoft guidelines to confirm the compatibility with this
deployment approach.
Access the Add-ins If you want to use the add-ins online too—via Word or Excel
online Online clients, ensure to have a Microsoft 365 license that
grants access to Microsoft 365 Online.

4.2 Microsoft 365 and Azure requirements


In scope of Microsoft 365 and Azure requirements set, you need to configure below:
 SharePoint Online to set up one of the major OrbusInfinity integrations
 Entra ID Enterprise App to configure permissions for OrbusInfinity web application and
Solutions Hub
 Power Automate connector to allow you to build your own automations to OrbusInfinity
through Power Automate (optional)
 OrbusInfinity Flow to build, customize, and manage your integrations (optional – only
needed if you purchased OrbusInfinity Flow)
 Orbus Professional Services access to get ready your OrbusInfinity environment
 OrbusInfinity Knowledge Base access setup to enable users’ access to the Knowledge
Base

11
OrbusInfinity Installation Guide

SharePoint Online
Important
To complete the below requirements, you need to be assigned administrator rights
in your SharePoint tenant.

SharePoint is one of the OrbusInfinity integration points where you store documents and
collaborate with colleagues on repository data. It facilitates the collection and update of
data and makes it accessible for contributors across your organization.
To set up SharePoint integration with your OrbusInfinity repository, you must meet the
following requirements.

Requirement Description Purpose


Create a dedicated  This site must use the You and people in your
SharePoint Online Site Communication Site organization will use this
Collection within your template. Site Collection to publish
SharePoint Online Tenant  Make sure to add the and view documents,
“OrbusInfinity” string to the topics, events, and projects.
SharePoint Online Site With the SharePoint Online
Collection’s description or Site Collection, you will be
URL, for the Solutions Hub able to reach out to data
to identify your site contributors and keep your
collection correctly. data up-to-date, using
convenient methods.
Install OrbusInfinity This application allows you to OrbusInfinity Webparts App
Webparts from the embed content directly from enables integration
SharePoint Store the OrbusInfinity repository between OrbusInfinity and
into your SharePoint pages. SharePoint.
It also allows to install,
maintain, and update
SharePoint web parts and
extensions.
Add your OrbusInfinity Site collection administrators To be able to embed
environment to the Allow control whether you can content from the web
List embed content from external application, make sure to
websites using the embed add your company’s
web part. If your site isn't on OrbusInfinity environment
the list of sites that are URL to your organization’s
allowed, you will see an error Allow List.
message that says, For more information, see
“Embedding content from this Microsoft guidelines.
website isn't allowed.”

12
OrbusInfinity Installation Guide

*Exclusive for FedRAMP Contains some configuration To be able to use


customers* required by the OrbusInfinity OrbusInfinity Webparts on
Add SharePoint hidden list Webparts app to correctly FedRAMP environments.
with OrbusInfinity work on FedRAMP
configuration environments.

Entra ID Enterprise App


Important
Target audience of the below requirements is your organization’s Entra ID
administrator.

OrbusInfinity uses enterprise application in your Entra ID tenant to authenticate users and
to request access to Microsoft 365 resources.
Permission request type Description

Application Permissions Enables the OrbusInfinity Entra ID Enterprise App to perform


actions within the scope of the applied permissions set
requested by our App. These are granted by your Entra ID
Administrator at the point of installation.
Delegated Permissions Enables the OrbusInfinity Entra ID Enterprise App to perform
actions within the scope of the currently logged in user's
permissions set, on their behalf.
You need to grant different sets of permissions for the two below enterprise applications:
 OrbusInfinity web application
 Solutions Hub

13
OrbusInfinity Installation Guide

[Link] OrbusInfinity
The following permission sets are requested by the OrbusInfinity enterprise application in
Entra ID tenant.
Permission request Permissions Description
type
Office 365  Access selected The delegated [Link] permission can
SharePoint Online: site collections be used to link your OrbusInfinity instance
Delegated and ([Link]) specifically to its SharePoint site created
Application during provisioning. This increases the ability
Permissions of admins to control application access to
specific site collections. It uses the minimal
intersection of application and user
permissions. The application [Link]
permission serves the same purpose, but is
used when OrbusInfinity accesses
SharePoint by one of its services, not users.

Microsoft Graph:  Read all users' These enable your designated OrbusInfinity
Application full profiles Administrator to import users and groups
Permissions  Read group from your Entra ID into the application. These
(optional) memberships are only requested if not using the Entra ID
user provisioning functionality.

Entra ID Permissions Enable interaction To enable interaction with your Microsoft 365
with your Microsoft environment, your Global Administrator
365 environment needs to consent to the Entra ID permissions.
Use the link below to provide the required
admin consent:

[Link]
adminconsent?client_id=
9898412d-bd6e-4f62-8173-
c8eb05ca4d02&redirect_uri=https://
[Link]/consented

Remember to substitute the {tenantId} with


the ID of your tenant.

For more information, see Entra ID


permissions.

Note
Due to the retirement of Azure ACS for SharePoint authentication,
[Link] permissions are not supported.

14
OrbusInfinity Installation Guide

[Link] Solutions Hub


The following permission sets are requested by the Solutions Hub enterprise application in
Entra ID tenant.

Note
You need to enable the below permissions only if you use integration with the
Solutions Hub.

Permissions type Permissions Description


Microsoft Teams:  Read the names and These enable Solutions Hub users
Delegated descriptions of teams to read the names and
Permissions  Read the names and descriptions of teams and
descriptions of channels channels, on behalf of signed-in
 Read users' relevant user and allows the app to read a
people lists scored list of people relevant to the
signed-in user. The list can include
local contacts, contacts from social
networking or your organization's
directory, and people from recent
communications (such as email
and Skype).
Microsoft Project Read items in all site This enables Solutions Hub to track
Online and collections documents and list items in all site
SharePoint: collections on behalf of the signed-
Delegated in user. It’s scoped to ensure user-
Permissions specific document permissions
within Project Online and SharePoint
are upheld.
Microsoft Planner: Read user’s tasks and task This enables Solutions Hub to read
Delegated lists (preview) the signed-in user’s tasks and task
Permissions lists, including any shared with the
user. Doesn't include permission to
create, delete, or update anything.

Power Automate connector


Note
This requirement is optional and only applies if you want to use the Power
Automate connector.
OrbusInfinity Premium Connector is available in the Power Automate connectors list. It gives
you the possibility to build your own integrations for any third-party applications to
OrbusInfinity.
To set up Power Automate integration with your OrbusInfinity repository, you must meet the
following requirements.

15
OrbusInfinity Installation Guide

Requirement Description

Author Licence account You must have access to at least one account with a
to OrbusInfinity currently active Author Licence to OrbusInfinity.
Enabled REST API Feature OrbusInfinity REST API Feature Permission must be ON.
Permission
Microsoft Power You must have access to at least one account with a
Automate Premium currently active Microsoft Power Automate Premium
Subscription Subscription.
Approval from Admin You have to request approval from Admin during the setup
(see image).

OrbusInfinity Flow
Note
This requirement is optional and only applies if you purchased the OrbusInfinity
Flow.
Flow offers a self-serve integrations builder experience that changes the way you connect
with your integrations. It's the fastest way to create integrations with other apps you use.
You can build, customize, and manage your own unique integrations using templates for
hundreds of systems through the native integration marketplace.

16
OrbusInfinity Installation Guide

To set up Flow integration with your OrbusInfinity repository, you must meet the following
requirements.
Requirement Description

Premium A premium license is required for access to Flow Designer and Premium
License Integrations in Marketplace. For assistance with purchasing, please
purchased contact your Account Manager or Customer Success Manager.

Author You must have access to at least one account with a currently active
Licence Author Licence to OrbusInfinity.
account to
OrbusInfinity
Enabled REST OrbusInfinity REST API Feature Permission must be ON.
API Feature
Permission
Approval You have to request approval from Entra ID Admin during the setup.
from Admin
There are two ways to trigger an approval request:

1) The easiest way is using the application. Given an instance of an


integration is provisioned, click connect on OrbusInfinity connection.
This is also possible if there are no premium integrations, but only an
access to designer. In that case, you need to choose any action from
OrbusInfinity connector. In both cases, you will see this screen.

Once the credentials are entered, an approval request screen will be


shown. A user will see a screen similar to the one below:

17
OrbusInfinity Installation Guide

Please click the Accept button if you have administrator permissions


or submit a request to your IT admin for approval. The name of the
app is “OrbusInfinity Flow Connector”.

2) Provide a link and share it with OI users so they can forward it to their
Entra ID admin for approval or for new customer installation, where we
already deal with Entra ID admins, provide the link to them and ask
them to approve it during the installation call.

Flow Connector App Admin Consent URL. You must modify


{INSTANCENAME} to the actual client instance.
[Link]
ient_id=8021abd9-d5b1-4a5a-b8ba-
6c7e0a0169e9&state=12345&redirect_uri=[Link]
om&scope=[Link]
[Link]/user_impersonation%20offline_access
Moreover, this is a delegated permission that requires approval:

18
OrbusInfinity Installation Guide

Claims: user_impersonation,offline_access
The application (client) id: 8021abd9-d5b1-4a5a-b8ba-6c7e0a0169e9

Feature Admins have access to Flow by default. Users with an Author license can
Permissions request access/be granted access by Admins adding them to a suitable
granted by role with the Flow Permissions enabled. For more information, see Flow
Admin Feature Permissions.

Orbus Professional Services access


Important
To complete the below requirements, you need to be assigned administrator rights
in Entra ID and SharePoint.

To set up and customize your OrbusInfinity environment, provide an Orbus Professional


Services Consultant with access to:
 your OrbusInfinity environment, with the administrative role
 OrbusInfinity SharePoint site, with the Site owner role
OrbusInfinity and SharePoint use Entra ID for authentication/authorization. Because of this
the Consultant will either need a guest account or an organizational account in your Entra
ID tenant.
 Guest account
A guest account is an external account that, on behalf of a guest, accesses specific
resources in your Entra ID tenant.
To add a guest account, an Entra ID Administrator should send an invitation to the
Consultant. Then, the Consultant will be able to access your Entra ID tenant resources
with their Orbus Software Entra ID account.

Note
SharePoint permissions may block guest accounts’ access to SharePoint
sites. Check with your SharePoint admin if external sharing to guest accounts
is blocked on your SharePoint tenant. If so, set up an organizational account
for the Consultant.

19
OrbusInfinity Installation Guide

 Organizational account
An organizational account is the same type of account that the users in your
organization have. To set up an organizational account, create an Entra ID account for
the Consultant as if they are a member of your organization.

Note
Your organization may have an application or approval process to create an
organizational account.
Consult your Entra ID Admin to decide what option is best for your
organization.

Regardless of the account type set up for the Consultant:


1. In Entra ID, assign the Consultant the administrator role in OrbusInfinity enterprise
application created during the post-installation call with an Orbus Software Support
team member.
2. On SharePoint site used for OrbusInfinity, grant the Consultant with the Site Owner
permissions for the SharePoint site used for OrbusInfinity.

OrbusInfinity Knowledge Base access setup


Important
To complete the below requirements, you need to be assigned administrator or
global administrator rights in Entra ID.

For your users to access the KB, some Entra ID permissions must be granted to the KB by
each user.
With default Entra ID settings, the required permissions do not require Admin consent and
users are able to approve the permissions themselves when first logging in to the KB.
You may however choose to do the permission grant on behalf of all your users, thereby
preventing users from having to go through this process. Alternatively, your Entra ID settings
may have been modified to prevent users approving apps themselves, in which case you
will need to do this on their behalf.
To carry out the permission grant for all of your users:
1. Go to the Knowledge Base and log in using an account with Entra ID Global
Administrator rights.
2. Review and grant the permissions.

20
OrbusInfinity Installation Guide

5 Installation overview
There are four key stages to provision an OrbusInfinity instance and integrate it with your
Microsoft 365 environment which must occur sequentially:
1. Customer environment setup
Usually, SharePoint Administrator and Entra ID Global Administrator prepare your
SharePoint site with which OrbusInfinity will interact, and install the SharePoint Webparts
App.
2. Permission grants and Add-ins setup
Entra ID Global Administrator with guidance from our support engineers enables
the OrbusInfinity access to the required Entra ID permissions on your environment and
the deployment of Visio and Excel Add-ins. These steps can be completed in less than
thirty minutes offline or during a call with our engineers.
3. OrbusInfinity site provisioning
After receiving all prerequisite information from your Administrators our support
engineers create an OrbusInfinity instance that is configured to work with your users
and integrate into your Microsoft 365.
4. Solutions Hub installation
Solutions Hub is a cloud platform that provides Solutions to business challenges related
to common enterprise transformation. It presents a catalog of ready-made Solutions to
provide outcomes for various enterprise architecture and transformation use cases,
systems, and roles.

21
OrbusInfinity Installation Guide

6 Customer environment setup


This section describes the steps required by your Microsoft 365 and Entra ID Administration
Team to prepare your environment for the OrbusInfinity application interaction:
 SharePoint site setup
 SharePoint Webparts installation

Note
Once you complete the instructions in the next section, our engineers will proceed
with the creation of an OrbusInfinity instance. Ensure to gather all the required
information in the end of the section and send it to your Orbus account manager or
technical contact.

Remember that due to the retirement of Azure ACS for SharePoint authentication, the
[Link] persmission is no longer supported and you have to consent to the
[Link] permission.

6.1 SharePoint site setup


Important
To perform the following procedure, you must be a SharePoint Administrator.

1. Create a new SharePoint Site Collection using the Communication Site Modern
template.
2. Enable external site sharing for the newly created SharePoint site, so Orbus Professional
Services Consultants can access it. For more information, see this Microsoft guide.

Note
Make sure to add Orbus Consultants as Site Owner of the newly created SharePoint
site, so they are able to upload content and carry out configuration.

6.2 SharePoint Webparts installation


Important
To complete the below requirements, you need to be assigned administrator rights
in your SharePoint tenant.

To enable integration between OrbusInfinity and SharePoint, install the SharePoint


Webparts App from the SharePoint Store. This allows OrbusInfinity to install, maintain, and
update its SharePoint web parts and extensions. To install the SharePoint Webparts App:

22
OrbusInfinity Installation Guide

1. Open your SharePoint site.


2. Go to Settings and select Add an app.

3. Search for ‘’OrbusInfinity Webparts’’.

4. Alternativity, navigate directly to the app’s page in the Store:


{YourSharePointSiteUrl}/_layouts/15/[Link]/appDetail/WA200008629
(e.g. [Link]
emea/_layouts/15/[Link]/appDetail/WA200008629)

23
OrbusInfinity Installation Guide

5. Add the app to the list of available apps. It is possible you need to request the App to
be added by the SharePoint Administrator.

6. Once added, go back to your Site Apps


({YourSharePointSiteUrl}/_layouts/15/[Link]/). OrbusInfinity Webparts should be
available in the list of Apps you can add. Select Add.

The OrbusInfinity Webparts App has been successfully installed.

Note
For FedRAMP customers, there is an additional step required: creating a new hidden
list containing some configuration required by the webparts to correctly work on
FedRAMP instances.
1. Download and install the SharePoint PnP cmdlets from here.
2. Run the following commands to create the mentioned hidden list:

$listTitle = "OrbusWebpartsConfiguration"
$fieldName = "orbusInfinityEnvironmentType"
$titleFieldName = "Title"
$titleFieldValue = "Configuration"
$environmentType = “fedRAMP”

Connect-PnPOnline -Url "SharePoint OrbusInfinity Site URL” -UseWebLogin

$list = New-PnPList -Title $listTitle -Template GenericList -OnQuickLaunch:$false

24
OrbusInfinity Installation Guide

Set-PnPList -Identity $listTitle -Hidden $true

Add-PnPField -List $listTitle -DisplayName $fieldName -InternalName $fieldName


-Type Text

Add-PnPListItem –List $listTitle –Values @{$titleFieldName = $titleFieldValue;


$fieldName = $environmentType}

Note
It is possible that the OrbusInfiniy Webparts app is added to the App catalog
without access to external users by default. To give external users access to your
SharePoint site, you will need to share the App with them. To do so:
1. Go to:
{YourSharePointDomain}/sites/appcatalog/_layouts/15/[Link]
/manageApps
2. Search for “OrbusInfinity Webparts” app on the list, right click on it, select Share,
and include the group assigned to the external users with "Can view" access.

25
OrbusInfinity Installation Guide

7 Permission grants and Add-in setup


Important
To complete the below requirements, you need to be assigned administrator or
global administrator rights in Entra ID.

To complete this stage of the installation, Orbus Support Engineers contact you to:
 Grant Entra ID permissions for OrbusInfinity
 Configure Site Provisioning
 Configure User Provisioning
 Turn off Assignment required option
 Install the Import Tool (Excel Add-in) and Export Tool (Word Add-in)
This section describes the process of permission grants and Add-ins setup steps; however,
we can also offer this via an installation call if required.

7.1 Entra ID permissions


Important
To perform the following procedure, you must be an Entra ID Global Administrator.

To enable interaction with your Microsoft 365 environment, Orbus Support Engineers direct
the Global Administrator to the OrbusInfinity admin consent page where the permission
grant is complete:
1. Use the link below to open the OrbusInfinity admin consent page:
[Link]
4f62-8173-
c8eb05ca4d02&redirect_uri=[Link]
Remember to substitute the {tenantId} with the ID of your tenant.

26
OrbusInfinity Installation Guide

2. Review and grant permissions.


Below you will find the user flow for the [Link] SharePoint permission provisioning.

Accepting the requested permissions will enable all users under the OrbusInfinity instance
to use the app.
Once the scopes are requested and consented to, an Enterprise Application is created in
your Azure portal.

This is the application you will have to bind to your SharePoint site.

27
OrbusInfinity Installation Guide

Bind SharePoint Site to OrbusInfinity


Before you do that, the Entra ID Admin will need to consent to the [Link]
permissions, which can be done directly within the Microsoft Graph Explorer:
1. Go to your profile.

2. Select Consent to permissions.

3. Search for Sites.


4. Select Consent for [Link].

After this, your SharePoint Administrator has to bind your Azure application to your
SharePoint site.
1. Go to [Link] and sign in.
2. Set the HTTP request method to POST.
3. In the request URL field, enter
[Link]

28
OrbusInfinity Installation Guide

Note
Remember to replace {site-id} with your actual site ID. If you don’t know it, you
can retrieve it by:
a. Go to your SharePoint site URL.
i. Example:
[Link]
b. Append the SharePoint site URL with /_api/site/id.
i. Example:
[Link]
/_api/site/id
c. Press Enter.
The site ID will be retrieved in the URL. Copy it and replace it with {site-id} in the
request URL field.

4. Paste the following json script into the request body:

{
"roles": ["read", "write", "manage"],
"grantedToIdentities": [{
"application": {
"id": "9898412d-bd6e-4f62-8173-c8eb05ca4d02",
"displayName": "OrbusInfinity"
}
}]
}

Note
 "id" = enterprise application id
 "displayName" = enterprise application name

5. Select Run query.

Note
The operation is successful when you receive the Created-201 response.

29
OrbusInfinity Installation Guide

Other responses (4XX, 5XX, etc.) may indicate insufficient privileges or missing
consent for required permissions. In such cases, please contact Support for
further assistance.

Once done, the OrbusInfinity instance will be bound to the SharePoint site under
[Link] scope.

7.2 OrbusInfinity site provisioning


Important
Target audience of the below requirements is your organization’s Project Lead.

To enable OrbusInfinity support engineers to create an application instance integrated to


your Microsoft 365 environment, collect the following information and send it to your Orbus
account manager:
 Entra Tenant ID
 Entra Tenant Name
 URL of the SharePoint site OrbusInfinity will integrate with
 Confirmation that the SharePoint Webparts App has been deployed
 Whether you have an Entra ID Premium P1 or P2 license
This determines the ability to use Entra ID user provisioning for user management in
Entra ID. This lowers the permission demands of the application and is the preferred
approach to user management.
 Confirmation of Entra ID Guest User Accounts for Orbus Consultants
If you can’t assign Guest users to Orbus Consultants, then we need temporary users in
your Entra ID instead and the following information:
 Entra ID
 Username
 Temporary Passwords

30
OrbusInfinity Installation Guide

 SharePoint Site ID.

Your account manager passes this information to the Orbus Support Engineer responsible
for your installation so that they can proceed with creating an OrbusInfinity instance.

7.3 User provisioning


Important
To complete the below requirements, you need to be assigned administrator or
global administrator rights in Entra ID.

Azure User Provisioning uses SCIM—an industry-wide standard for managing user identities
in cloud-based applications.

Configure user provisioning using SCIM


Note
To perform the following procedure, you must be an Entra ID Global Administrator
and have an Entra ID Premium P1 or P2 license.

1. In the Azure Portal, on the Azure Active Directory Enterprise Application blade,
select New application. Alternatively, select the following link to go to the correct
location:
[Link]
egory/topapps
2. Under Add your own app, select Non-gallery application and enter a name for the new
application and select Add.
Orbus recommends using OrbusInfinity – User Provisioning as the application’s name.

31
OrbusInfinity Installation Guide

3. When the application is created, in the Provisioning section, select Get started.

4. To view additional fields, in the Provisioning Mode list, select Automatic.


5. Under Admin Credentials, in the Tenant URL and Secret Token fields, enter details
provided by Orbus and select Test Connection.

32
OrbusInfinity Installation Guide

6. After the test is run successfully, on the toolbar, select Save.


7. Under Mappings, select Provision Azure Active Directory Users.

8. In the Attribute Mapping window, select the mailNickname attribute that is


set to externalId.

33
OrbusInfinity Installation Guide

9. In the Edit Attribute dialog box, in the Source attribute list, select objectId, and select
OK.

10. To save attribute mappings, on the toolbar, select Save.


11. Set the Provisioning Status to On, and on the toolbar, select Save.

Entra ID is now ready to provision users into OrbusInfinity.

34
OrbusInfinity Installation Guide

Non-SCIM user provisioning


If you don’t use SCIM for provisioning, your Entra ID Global Administrator will need to
consent to additional User and Group Member permissions after accepting the previous
ones, using the link below. The additional permissions are necessary to enable adding
users and groups to OrbusInfinity from your Active Directory:
 [Link]
 [Link]

[Link]
bd6e-4f62-8173-
c8eb05ca4d02&scope=[Link]
[Link]/[Link]&redirect_uri=[Link]

Note
Remember to replace {tenantId} with the ID of your tenant.

35
OrbusInfinity Installation Guide

Manage OrbusInfinity users


After you configured the user provisioning, you can add users to OrbusInfinity. To do this,
open the enterprise application created in the previous procedure (Configure user
provisioning) and in Users and groups section, add or remove users and groups.
The changes are then synchronized over to OrbusInfinity by the Azure Active Directory
provisioning engine.

Note
The synchronization engine runs on a schedule and changes can take up to
40 minutes to synchronize across to OrbusInfinity.

7.4 Turn off Assignment required option


For applications created in Entra ID the Assignment required? option defines whether all
users (both members and guests) and apps or services can access them. By default, this
option is set to No which we recommend not to change.
For security reasons, some customers set the option to Yes which might cause unexpected
issues. Among others, preventing connected applications, such as Solutions Hub, from
authenticating in to OrbusInfinity.
Therefore, this is highly recommended to keep this setting default.

Note
To be able to modify the Assignment required? option, you must be an Entra ID
Global Administrator and have an Entra ID Premium P1 or P2 license.

36
OrbusInfinity Installation Guide

7.5 Import and Export Tools installation


Important
To perform the following procedure, you must be an Office 365 Administrator.

Note
This step is optional and only required if the Office 365 Store is disabled for Users.

The tools use the new cross-platform Office JS API. Unlike the older Office COM Add-Ins, the
add-ins do not require an installer to the user’s machine. Microsoft recommends
managing all new application deployments via Office 365 Centralized Deployment. This
guarantees the easiest and cleanest integration with your copy of Office, both Online
and Desktop.
1. Deploy the add-ins to your Microsoft 365 Admin Center:
a. Log into the Microsoft 365 Admin Center.
b. In the navigation menu, select Settings > Integrated Apps.
a. At the top of the page, select Add-ins.
b. On the Add-ins page, select Deploy Add-in > Next.
c. On the Deploy a new add-in page, select Choose from the Store.
d. In the search box, type OrbusInfinity Import Tool or OrbusInfinity Export Tool, and in
the search results, select Add > Continue.
e. Select who can have access to the add-ins and select Deploy. It’s strongly
recommended that the person deploying the add-ins adds themselves to the list of
users to help simplify deployment validation. The add-ins are now available to the
users you selected.
2. Validate deployment:
a. Open Excel or Word (either desktop or online) and start a new workbook or
document.
b. On the Insert tab, select My Add-ins (or Add-ins for online).
If the installation is successful and all the requirements are met, the Add-In is now
available under the Admin Managed section.

37
OrbusInfinity Installation Guide

8 Solutions Hub installation


Important
To complete the below requirements, you need to be assigned administrator or
global administrator rights in Entra ID.

OrbusInfinity comes with a catalogue of ready-made Solutions to accelerate the


realization of key use cases in OrbusInfinity, called Solutions Hub. The Solutions can be
deployed into your OrbusInfinity environment by repository administrators and authors in a
self-service manner.
To set up access to the Solutions Hub:
1. Go to [Link] and sign in using your Microsoft
account.

Note
Replace the <InstanceName> placeholder with your organization’s instance of
Solutions Hub. Orbus Support will communicate the URL of your Solutions Hub
instance during the OrbusInfinity installation.

2. Once logged in, in the upper-right corner of the page, select your account drop-down
and select Admin Centre.

38
OrbusInfinity Installation Guide

3. In the navigation pane, select Tenant Management > List of Pages, and then select
Granting Admin Consent for the Microsoft Graph Permissions.

4. The page that opens provides an overview of how Solutions Hub interacts with Microsoft
Graph and the list of the Microsoft Graph permissions required for using certain
integration solutions with the Microsoft365 applications. Review the permissions and
select GRANT CONSENT for each application. This will grant admin consent to the
Solutions Hub for the specific delegated Graph permissions on behalf of all users of
your organization.

In practice, the Microsoft Graph permissions used by the Solutions Hub do not require
admin consent. Users that will activate and run solutions can grant those permissions
individually for most organizations. In some particular cases, certain organizations, in the
Entra ID settings, have disabled the ability for the end users to directly grant consent for
any Graph permissions to third-party applications. They then require an Entra ID Global
Administrator to grant admin consent instead. In that case, the Entra ID Global
Administrator can grant admin consent for all permissions needed to the Solutions Hub
using this page in the Admin Centre.

39

You might also like