Quick start

Office Sentry runs as two containers (the portal and a worker) from one image, with everything stored in one Docker volume.

Download docker-compose.yml, Caddyfile and env.example from the newest release into a folder on a Linux server with Docker, then:

cp env.example .env           # set OFFICESENTRY_BASE_URL, OFFICESENTRY_DOMAIN and OFFICESENTRY_TIMEZONE
docker compose --profile https up -d

The image is ghcr.io/jackd99/officesentry, for amd64 servers (arm64 too once the repository is public); each release lists what changed in CHANGELOG.md. While this repository is private the image is too, so the server needs docker login ghcr.io with a GitHub token that can read packages.

Leave out --profile https if you already have a reverse proxy, and point it at http://127.0.0.1:8000. Then:

  1. Run docker compose logs web and open the link on the line starting No admin account yet to create the first admin (with two-step sign-in).
  2. Open Settings → App connection and press Sign in to Microsoft. The page shows a code and Microsoft's link: enter the code there and sign in as an admin of your own (MSP) tenant who can create app registrations. Office Sentry then creates its multi-tenant, read-only app with a certificate and saves it, with nothing to type on the server. (docker compose run --rm worker python -m officesentry create-app does the same from the command line.)
  3. Add your first tenant on the same page and follow its checklist: a Global Administrator of the client's tenant grants consent, you assign Global Reader, and the first collection runs.

Stuck? Troubleshooting covers the common errors, such as AADSTS50011 on the consent page, mailboxes failing without Global Reader and the worker not running.

v2/DEPLOY.md covers HTTPS, the collection schedule, retention, backups and updating.