Quick start
Office Sentry runs as two containers (the portal and a worker) from one image, with everything stored in one Docker volume.
Download docker-compose.yml, Caddyfile and env.example from the newest
release into a folder on a Linux server with Docker, then:
cp env.example .env # set OFFICESENTRY_BASE_URL, OFFICESENTRY_DOMAIN and OFFICESENTRY_TIMEZONE
docker compose --profile https up -d
The image is ghcr.io/jackd99/officesentry, for amd64 servers (arm64 too once the repository is public); each release lists what changed in
CHANGELOG.md. While this repository is private the image is too, so the server needs
docker login ghcr.io with a GitHub token that can read packages.
Leave out --profile https if you already have a reverse proxy, and point it at http://127.0.0.1:8000. Then:
- Run
docker compose logs weband open the link on the line starting No admin account yet to create the first admin (with two-step sign-in). - Open Settings → App connection and press Sign in to Microsoft. The page shows a code and Microsoft's
link: enter the code there and sign in as an admin of your own (MSP) tenant who can create app
registrations. Office Sentry then creates its multi-tenant, read-only app with a certificate and saves it, with
nothing to type on the server. (
docker compose run --rm worker python -m officesentry create-appdoes the same from the command line.) - Add your first tenant on the same page and follow its checklist: a Global Administrator of the client's tenant grants consent, you assign Global Reader, and the first collection runs.
Stuck? Troubleshooting covers the common errors, such as AADSTS50011 on the
consent page, mailboxes failing without Global Reader and the worker not running.
v2/DEPLOY.md covers HTTPS, the collection schedule, retention, backups and updating.