Skip to content

Installing Smarter Visitor Registration

From the deployment in Azure to the first sign-in: which resources are created, which permissions are required and how you put the application into operation.

How the installation works

Smarter Visitor Registration runs in your own Azure subscription. A template creates all resources, then the application package is deployed and the solution is set up in the browser. Allow about one hour if the required permissions are in place.

You receive the template and the application package from us. If you wish, we carry out the installation together with your IT team in a remote session. Contact us to arrange this.

1

Prerequisites

AreaRequirement
AzureA subscription and a resource group in which you are Contributor or Owner.
Microsoft Entra IDRights to create an app registration, to assign Microsoft Graph roles to a managed identity and to grant admin consent. In practice: Global Administrator or Privileged Role Administrator.
Microsoft 365Exchange Online for the Outlook add-in and for sending emails, optionally Microsoft Teams.
Object ID of the first administratorThe Entra object ID of the person who carries out the initial setup. You find it in the user profile in the Entra admin center or with az ad signed-in-user show --query id -o tsv.
Session secretA random string of at least 32 characters, for example from openssl rand -hex 32.

No first sign-in without an object ID

As long as no admin group is set up, only the object IDs specified during deployment may open the settings. If the value is left empty, nobody can carry out the initial setup.

2

What is created in Azure

ResourcePurpose
App Service (Linux, Node.js 22)The web application with terminal, settings, analytics and the interface for the Outlook add-in. HTTPS only, TLS 1.2 or higher.
Azure Cosmos DB (Serverless)Database with the containers for planned appointments, visitor contacts, check-ins, settings, audit log and files.
Managed identityReads group memberships and users through Microsoft Graph (application roles Group.Read.All and User.Read.All). No client secret is required.
App registrationSign-in for browser, Outlook and Teams. Exposes the scope access_as_user; Outlook and Teams are already pre-authorised for it.
Application Insights (optional)Logs and telemetry for operations.
Key Vault (optional)Stores the database key and the session secret instead of keeping them in the app settings.

The running Azure costs depend on the pricing tier and on usage. In the smallest configuration (App Service B1, Cosmos DB Serverless) they are around 20 euros per month as a guide value. Microsoft bills these costs to you directly.

3

Deploying the resources

You deploy the template (main.json) in the Azure portal with Deploy a custom template or with the Azure CLI. These parameters are relevant:

ParameterMeaningDefault
deploymentNamePrefix for all resource names, 3 to 20 characters–
webAppNameName of the web app and therefore the address https://<name>.azurewebsites.net. Must be globally unique.<deploymentName>-webapp
appServicePlanSkuPricing tier of the App ServiceB1
adminBootstrapObjectIdsObject IDs of the people who may carry out the initial setup, separated by commasempty
jwtSecretSession secret, at least 32 characters–
azureAdClientIdClient ID of an existing app registration. Leave empty so that the template creates one.empty
enableAppInsightsCreate Application Insightstrue
enableKeyVaultStore secrets in a Key Vaultfalse
visitorsRetentionDaysAutomatic retention period for visitor contacts in days, 0 = no automatic deletion0
Example with the Azure CLI
az group create --name rg-visitor-registration --location westeurope

az deployment group create \
  --resource-group rg-visitor-registration \
  --template-file main.json \
  --parameters deploymentName=visitorreg \
               webAppName=besucher-contoso \
               adminBootstrapObjectIds=<object-id> \
               jwtSecret=<secret>

After the deployment, note the outputs webAppUrl and azureAdClientId. You need the address of the web app for all further steps.

The address is tied to the installation

Sign-in, the Outlook manifest and the Teams app use the address <name>.azurewebsites.net. Choose the name of the web app with care. A custom domain requires additional changes to the app registration. Please contact us about this.

4

Deploying the application

The template creates the infrastructure. You deploy the application itself as a ZIP package:

az webapp deploy \
  --resource-group rg-visitor-registration \
  --name besucher-contoso \
  --src-path deploy.zip --type zip

Then check the address https://<name>.azurewebsites.net/api/health in the browser. The response {"status":"ok", …} shows that the application is running.

5

Granting consent in Microsoft Entra

The app registration is called Visitor Registration <deploymentName>. It uses delegated Microsoft Graph permissions, including Mail.Send for emails to visitors. So that the terminal can send emails without a prompt, grant admin consent once:

  1. In the Microsoft Entra admin center, open Applications › App registrations and select the app.
  2. Go to API permissions.
  3. Click Grant admin consent for <tenant> and confirm.
PermissionTypePurpose
User.Read, User.ReadBasic.All, People.ReaddelegatedSign-in and people search
Group.Read.AlldelegatedGroup selection in the settings
Mail.SenddelegatedEmails to visitors on behalf of the terminal account
Group.Read.All, User.Read.AllApplication (managed identity)Check group memberships, resolve contact persons for Teams calls

Emails from the Teams desktop app

If the terminal runs in the Teams desktop app, the server sends the emails on its behalf. For this, the app registration needs a client secret, which you store in the App Service as the setting AZURE_AD_CLIENT_SECRET. This is not necessary in the browser or in Teams on the web.

6

First sign-in and setup wizard

Open https://<name>.azurewebsites.net/admin and sign in with the account whose object ID you specified during deployment. As long as the solution has not been set up, the wizard starts.

Setup wizard with the first step, Basic Configuration
The wizard guides you through the initial setup in four steps.

1. Basic Configuration

Name and time zone of the first location. Optionally the admin group, which you can also set later.

2. Locations

Create further locations with terminal users and check-in behavior.

3. Branding

Company name, logo and colours of the terminal.

4. Timeouts

How long success messages stay on screen and when the terminal returns to the home screen.

With Complete Setup, the wizard saves your entries and opens the terminal. You can change all values later in the settings.

Do not forget the admin group

Under Settings › Security, enter an Entra group as the admin group and check that you are a member yourself. As soon as the group is set, the object IDs from the deployment no longer apply.

7

Next steps

  1. Set up locations: terminal users, guidelines and emails.
  2. Publish and roll out the Outlook add-in.
  3. Set up the terminal as a kiosk, in the browser or in Microsoft Teams.
  4. Test the first visit.
8

Updates and operations

  • Updating the application: Deploy the new ZIP package with az webapp deploy. Settings and data are stored in the database and are preserved.
  • Changes to the infrastructure: Deploy the template again, for example to change the pricing tier or to set a retention period.
  • Checking the version: The installed version is shown in the footer of the settings and the analytics.
  • Backup: Cosmos DB backs up the data automatically at regular intervals. For longer retention, adjust the backup policy of the database account.
  • Monitoring: The App Service checks the application through /api/health. You find errors and logs in Application Insights.

After an update

If the Outlook add-in or the Teams app has changed, the release notes say so. In that case, publish the manifest again or upload the new Teams package with a higher version number.

9

Troubleshooting

After sign-in, a message says that you are signed in but not authorised for this area.

Your account is neither an administrator nor a terminal user. During the initial setup: check whether your object ID is in the app setting ADMIN_BOOTSTRAP_OBJECT_IDS of the App Service. After that: check your membership of the admin group.

The deployment fails at the app registration or the Graph roles.

The deploying account lacks rights in Microsoft Entra. Run the deployment with an account that can create app registrations and assign application roles, or specify a prepared app registration with azureAdClientId.

The name of the web app is already taken.

Names under azurewebsites.net are globally unique. Choose a different value for webAppName.

Visitors do not receive emails.

Check whether admin consent has been granted for Mail.Send, whether the terminal account has a mailbox and whether sending is enabled at the location. In the Teams desktop app, the client secret is also required.

The application does not start or responds with error 500.

Open the log stream in the App Service. Common causes are an incompletely uploaded package or missing app settings after a manual change.

Questions about this product?

Our support team is happy to help with any questions about Smarter Visitor Registration.