Arctera™ Data Insight
- About Arctera Data Insight
- Dashboard
- Workspace
- Installing Collector Node
- Collector
- Data Sources
- Filers
- SharePoint Online
- OneDrive
- Directory Services
- Health and Monitoring
- Classification
- File Groups
- Reports
- Workflows
- Data Remediation
- Users and Access
Configuring application without user impersonation for Office 365
To set the property DisableCustomAppAuthentication,
- Open Windows Powershell as Administrator.
- Add Install-Module Microsoft.Online.SharePoint.PowerShell and press Enter.
- For importing NuGet file prompt, type Y and press Enter.
- For Untrusted repository prompt, type Y and press Enter.
- Add Connect-SPOService -url https://<your URL>-admin.sharepoint.com and press Enter.
- Provide username and password required to authenticate.
- Add Set-SPOTenant -DisableCustomAppAuthentication $false and press Enter.
After completing the steps, DisableCustomAppAuthentication property will be set to False. To verify, add get-spotenant in the same window and press Enter. A list will appear in the same window. Search the list and verify if DisableCustomAppAuthentication property is set as False.
After setting the property, you need to add the application to the lookup.
To add the application to the lookup,
- Copy the Client ID of the app created in the Azure portal App
- Navigate to https://<organization-name>-admin.sharepoint.com/_layouts/15/appinv.aspx
- Paste the Client ID copied from the Azure portal App in the App Id field
- Click Lookup
- Add localhost.com in the App Domain field
- Add https://localhost.com/default.aspx in the Redirect URL field
- Add following XML in the App's Permission Request XML
<AppPermissionRequests AllowAppOnlyPolicy="true">
<AppPermissionRequest Scope="http://sharepoint/content/tenant"
Right="FullControl"/>
</AppPermissionRequests>
- Click Create
- Click Trust It
You will be redirected to the SharePoint admin center.
Data Insight uses a Global administrator account to discover the site collections and scan metadata and a SharePoint administrator account to fetch the access events from the configured SharePoint Online account. Global administrator accounts must have full control over the site collections that you want Data Insight to monitor. You must configure the Global administrator, as owner for team site collections, on the Office 365 interface and assign the administrative privileges for the target site collections.
To add a SharePoint administrator
- Log on to Office 365 using the Global admin credentials.
- On the SharePoint admin center page, click Users > Active users > Add a user.
The New User pop-up windows opens.
- Enter the name of the user and other properties as appropriate.
- In the Roles section, select Customized administrator > SharePoint administrator.
- Click Add.
The SharePoint administrator account collects metadata about site collection content , and gathers audit data from SQL Server databases for SharePoint when it is assigned administrative privileges for the target site collections. It must also have full control permissions on the configured site collections and the site collections that are incrementally included to the SharePoint account. For team site collections, the SharePoint administrator should be an owner.
The Minimum Privilege user has access to all features in the Admin center and can perform all tasks in the Office 365 Admin center.
To assign owners for team site collections
- On the SharePoint admin center page, go to Groups > Groups, and select the Group Name to which you want to assign owners.
- In the Group details pane on the right-hand-side, click Edit for the Owners entry.
- In the Edit pane, click Add owner and select a user having Minimum Privilege user credentials.
- Click Save.