Skip to main content
Table of Contents
Print

Install eDig365 Reporter with standard profile

Use this guide to install eDig365 Reporter with the Standard deployment profile. This profile creates and manages the application network, uses public HTTPS ingress and direct App Service internet egress, and pulls the application image from the eDig365 publisher registry.

If your organization requires existing network resources, private ingress, customer-routed egress, an application outbound proxy, or a customer-managed registry, use Deploy eDig365 Reporter with customer network integration.

Understand the Standard profile

The Standard profile provides:

  • An application network created and managed by the deployment.
  • Public HTTPS access to the application.
  • Direct App Service internet egress.
  • Subnet-restricted Storage and Key Vault access through Azure virtual network service endpoints.
  • Container image pulls from the eDig365 registry.

The deployment doesn’t configure peering, VPN, ExpressRoute, custom route tables, NAT Gateway, firewalls, network virtual appliances, proxy infrastructure, or custom DNS resolvers. Use the customer network integrated profile when your environment requires these controls.

Prepare the prerequisites

Azure access

At the subscription or resource group where you will install the application, assign the installing identity:

  • Contributor, to deploy and manage the application resources.
  • Role Based Access Control Administrator, to create the Storage and Key Vault role assignments used by the application’s managed identity.

Owner at the same scope is an alternative. Contributor alone can’t create Azure role assignments.

Azure resource providers

Register these resource providers in the target Azure subscription before installation:

  • Microsoft.Authorization
  • Microsoft.Insights
  • Microsoft.KeyVault
  • Microsoft.ManagedIdentity
  • Microsoft.Network
  • Microsoft.Solutions
  • Microsoft.Storage
  • Microsoft.Web

Provider registration is subscription-scoped. If needed, ask a subscription Owner or Contributor to register them before installation.

Microsoft Entra app registration

Before deployment, create a single-tenant Microsoft Entra app registration for the single-page application and API.

  1. In the Microsoft Entra admin center, open Identity > Applications > App registrations, then select the app registration.
  2. Open Expose an API and select Add next to Application ID URI.
  3. Accept the default URI, api://<application-client-id>, and select Save.
  4. Under Scopes defined by this API, select Add a scope and enter the following values.
Setting Value
Scope name access_as_user
Who can consent? Admins and users
Admin consent display name Access eDig365 Reporter
Admin consent description Allow users to sign in to eDig365 Reporter and access its API.
User consent display name Access eDig365 Reporter
User consent description Allow me to sign in to eDig365 Reporter and access its API.
State Enabled

The completed scope is api://<application-client-id>/access_as_user. In Manifest, set api.requestedAccessTokenVersion to 2. This scope lets the single-page application request a token for the eDig365 API. It doesn’t grant access to Microsoft Graph, Microsoft Purview, or other customer data.

Record these values for the Marketplace installation:

  • Directory (tenant) ID
  • Application (client) ID

After deployment, add the App Service URL as a single-page application redirect URI.

Microsoft 365 permission administrator

Choose an administrator to grant Microsoft Graph and Microsoft Purview permissions after deployment. To complete the current eDig365 Configuration Tool workflow in one session, the same account must have:

  • Privileged Role Administrator or Global Administrator in Microsoft Entra ID, to grant tenant-wide consent and assign Microsoft Graph application permissions to the managed identity.
  • Organization Management in Microsoft Purview or the Compliance Administrator role, to register the managed identity and assign its eDiscovery roles.

These Microsoft 365 roles are separate from the Azure roles required to deploy the application. Activate eligible roles before opening the configuration tool.

Initial administrator

Choose the first eDig365 administrator’s email address. This person completes tenant setup and can add a Microsoft Entra ID security group and assign application roles.

Container registry credentials

Obtain a dedicated publisher-registry username and repository token from eDig365 support.

Support telemetry

Choose whether to share diagnostic telemetry with eDig365 support. App Service filesystem logging is enabled for all deployments.

Gather the installation inputs

Have these values ready before opening Microsoft Marketplace:

  • Azure subscription, resource group, and region
  • Application name, typically eDig365
  • App registration Directory (tenant) ID
  • App registration Application (client) ID
  • First eDig365 administrator email address
  • eDig365 publisher-registry username and repository token
  • Support telemetry choice

Complete the Marketplace installation

  1. Open the eDig365 Reporter offer in Microsoft Marketplace and select Create.
  2. On Basics, select the subscription, resource group, region, and application name.
  3. On Deployment profile, select Standard.
  4. On App registration configuration, enter the Directory (tenant) ID and Application (client) ID.
  5. On Registry access, enter the eDig365-issued publisher-registry credential.
  6. On Operations, enter the first administrator email address and select the support telemetry preference.
  7. Select Review + create. Review the application settings and telemetry choice.
  8. Select Create and wait for the Azure deployment to finish.

Validate the deployment

Complete Microsoft Entra configuration

Return to the previously created app registration:

  1. Add the App Service URL as a single-page application redirect URI.
  2. Add an approved custom-domain URL when one is configured.

Grant Microsoft Graph and Microsoft Purview permissions

Use the eDig365 Configuration Tool to grant the Marketplace-created Microsoft 365 managed identity access to customer data.

This process follows the two-part access model in Set up app-only access for Microsoft Purview eDiscovery by using Microsoft Graph APIs: assign Microsoft Graph application permissions, then register the service principal in Microsoft Purview and assign its eDiscovery roles. The Microsoft article uses an app registration with a client secret or certificate. eDig365 instead uses a user-assigned managed identity, which Azure represents in Microsoft Entra ID as a service principal. The managed identity obtains tokens from Azure, so you don’t create or manage a client secret or certificate for it.

The article demonstrates both read and write eDiscovery permissions. eDig365 Reporter assigns eDiscovery.Read.All, not eDiscovery.ReadWrite.All, as part of the application permission set listed in this procedure.

  1. Sign in with the Microsoft 365 permission administrator account identified during preparation.
  2. Grant tenant-wide admin consent when prompted. The tool requires delegated Directory.Read.All, Application.ReadWrite.All, and AppRoleAssignment.ReadWrite.All permissions for Microsoft Graph and Exchange.ManageV2 for Exchange Online.
  3. Enter the application name used for the Marketplace deployment. The tool locates the managed identity whose name starts with <application-name>-graph-mi-.
  4. Run the Microsoft Graph configuration step. The tool assigns eDiscovery.Read.All, User.Read.All, Sites.Read.All, Mail.ReadBasic.All, Directory.Read.All, AuditLogsQuery.Read.All, and AuditLog.Read.All application permissions to the managed identity.
  5. Run the Security & Compliance configuration step. The tool registers the managed identity in Microsoft Purview, adds it to the eDiscovery Manager role group, and makes it an eDiscovery administrator.
  6. Confirm that every configuration-tool check and action completes successfully.

Keep background processing disabled until these permissions are configured and verified.

Check application access and health

Open the App Service default URL and request /api/info/health over HTTPS. The first request after deployment or restart can take longer while App Service starts the container.

Verify operations

Confirm App Service Log Stream or downloaded logs contain recent output. The deployment keeps up to 100 MB of filesystem logs for up to three days. High volume removes older files sooner.

Sign in as the first administrator and complete tenant setup. Keep background processing disabled until permissions and application settings are verified.

To use a customer-managed encryption key for application Storage after installation, follow Configure a customer-managed key for eDig365 Reporter Storage.

Troubleshooting

Symptom First checks
Deployment can’t create a role assignment Confirm that the installing identity has Role Based Access Control Administrator or Owner at the deployment scope.
App Service returns 503 or doesn’t start Check App Service container logs, Key Vault reference status, and publisher-registry credentials.
Sign-in fails Check the app registration tenant and client IDs, API scope, token version, and single-page application redirect URI.
Configuration Tool consent or Graph configuration fails Confirm that the signed-in account has Privileged Role Administrator or Global Administrator and has granted the requested tenant-wide consent.
Configuration Tool Security & Compliance step fails Confirm that the signed-in account has Organization Management in Microsoft Purview or the Compliance Administrator role.
Application data operations fail Check the Microsoft.Storage and Microsoft.KeyVault service endpoints, Storage and Key Vault subnet firewall rules, and managed identity role assignments.
Publisher-registry pull fails Check the supplied username repository token, then confirm that the credential can access the approved image.

Related documentation