Starting with OfficeExpert 4.3.x , panagenda deploys and manages additional components in the customer's Azure tenant and therefore act as a service provider. This is completely done with Azure Lighthouse.
Customers need to execute an Azure Lighthouse template so that panagenda gets dedicated access on Resource Group level.
Note: These azure resources are needed in combination with the OfficeExpert appliance (the Appliance itself can run anywhere, On-Premises or Azure )
Important: if you have the need of setting up Azure Lighthouse in a different tenant which is not equal the tenant from where OfficeExpert gets the M365 data, please contact firstname.lastname@example.org
Table of Contents
What pieces will be deployed?
Following resources are part of the deployment
- Key Vault
- Function App (incl. App Service Plan - consumption based)
- Event Hub
- Storage Account
- App Insights + Log Analytics
Please make sure that the following Resource providers are registered in the Subscription you use.
1) Azure Lighthouse
An Owner of the Subscription (Owner via RBAC) has to perform the following steps in order to get the Azure Lighthouse template deployed.
This will connect panagenda with the specified azure resource group of the customers tenant (Note: panagenda gets Contributor access for the entire Resource Group) !
2) Graph API Subscription App Registration
A second Azure AD App registration in the customer tenants needs to be added (beside of the one which is being used by the OfficeExpert appliance).
This is a simple single tenant application with all the default settings
This should be the final result:
3) Microsoft Graph Change Tracking Object Id
The Graph Change Tracking Object Id is needed to finalize the deployment.
Open the Azure Portal / Azure AD / Enterprise Application and search for Microsoft Graph Change Tracking
4) Deployment Information - please provide this to panagenda
Make sure that the OfficeExpert appliance is fully deployed and up and running.
If so, please share the following information with panagenda so that all componentes can be deployed via Azure Lighthouse into your tenant.
Please download the following table as XLSX : https://files.panagenda.com/OfficeExpert/AzureLightHouse/panagenda-azure-light-house.xlsx
Tenant Id of the targeted Microsoft 365 tenant // Azure Tenant
Primary Domain name of the tenant. Please verifiy this on your Azure AD properties page
Azure AD App ID of "OfficeExpert Graph API Subscriptions"
Client secret of "OfficeExpert Graph API Subscriptions"
Azure AD App Enterprise Object ID of the App "panagenda OE Appliance". (Enterprise applications)
Microsoft Graph Change Tracking Object Id
Azure Location where the components should be deployed
e.g. eastus; westeurope;....
Resource Group Name where the components should be deployed
Subscription Id where the components should be deployed
Subscription name where the components should be deployed