The purpose of this article is to outline the technical and security requirements for installing, upgrading, and using Jint, as well as to detail the installation process.
This documentation is specifically intended for tenant-level installations.
If you want to consult the guide for site collection–level installation, please consult this guide.
Note: The installation steps require both an Entra ID administrator and a SharePoint administrator.
Table of contents
- Introduction
- List of prerequisites
-
Installation steps
- 3.1 Preparing the SharePoint tenant
- 3.2 Application consent (Configurator and Jint APIs)
- 3.3 Granting permissions to the app catalog
- 3.4 Providing information to Jint
- 3.5 Solution deployment by Jint
- 3.6 Approval of calls to Microsoft APIs
- 3.7 Approval of Jint API permissions
- 3.8 Authorizing Jint service addresses
- Using the Jint solution
1. Introduction
1.1 Jint solution architecture
The Jint solution consists of:
- A set of SharePoint packages,
- A management back office, referred to as the Jint Configurator throughout this document,
in the form of a web application whose authentication relies on your Microsoft account, - A set of APIs whose authentication relies on your Microsoft account.
1.2 Package deployment
Jint extends Microsoft SharePoint functionality. To do this, we deploy
packages in your SharePoint environment. These deployments take place automatically
whenever we publish a new version of the packages.
2. List of prerequisites
Summary
Here is a summary of the prerequisites for each component. They are detailed in the following sections.
2.1.1 At the SharePoint level
- Administrator access to the app catalog:
- Approval of an Entra ID application, Jint Deployment, requesting the
Sites.Selected application permission.
- Approval of an Entra ID application, Jint Deployment, requesting the
- Approval of the required calls to Microsoft APIs
- Approval of the required calls to Jint APIs
2.1.2 At the Entra ID level
- Approval of 5 Entra ID applications:
- Jint Deployment
- Jint Configurator
- Jint Administration
- Jint Site Engine
- Jint Contribution Center
2.1.3 At the network security level
Add the Jint service addresses to your allowlist
2.2 SharePoint package deployment
To deploy the SharePoint packages, our deployment automation requires app catalog
administrator rights, as Microsoft does not offer more granular permissions. These
rights must be granted to our Entra ID application, Jint Deployment.
2.3 Approval of calls to Microsoft APIs
In addition, in order to function correctly, our components call Microsoft APIs on
the user's behalf. For this purpose, a set of permissions for calls to Microsoft APIs must
be approved on your SharePoint tenant:
Calendars.Read
Calendars.ReadWrite
Group.Read.All
ChannelMessage.Send
Mail.Read
Sites.Read.All
User.Read.All
User.ReadBasic.All
Tasks.ReadWrite
Team.ReadBasic.All
Access_as_user
If these permissions have not already been approved, they must be approved once the Jint packages have been deployed.
3. Installation steps
Once the preceding prerequisites have been validated, the installation steps are as follows:
- Preparation of the SharePoint tenant,
Performed by the Global Administrator of the Customer - Approval of the applications required for Jint to function properly,
Performed by the Entra ID Administrator and Global Administrator of the Customer - Providing Jint with the information required for installation,
Performed by the Customer or the Integrator - Deployment of the solution by Jint,
Performed by Jint - Approval of calls to Microsoft APIs.
Performed by the Global and Entra ID Administrators of the Customer - Authorization of Jint service addresses
Performed by the Network Administrator of the Customer
Except for step 4, these steps must be performed by the Customer. Once these steps are complete, the
Jint solution can be used by the Customer and its Integrator.
3.1 Preparing the SharePoint tenant
Required access level for this step: Global Administrator.
Preparing your SharePoint tenant consists of ensuring that the global app catalog has been created.
Using a SharePoint administrator account, access the SharePoint admin center:
https://www.<your-tenant>-admin.sharepoint.com/
In the “More features” menu, click the “Open” button in the
“Apps” section:
3.2 Application consent for the Configurator and Jint APIs
Required access level for this step: Entra ID Administrator.
To authorize the Configurator and our APIs to authenticate your employees, you must approve
the following applications by clicking the corresponding links:
| Application |
| Mozzaik365 Deployment |
| Mozzaik365 Configurator |
| Mozzaik365 Administration |
| Mozzaik365 Site Engine |
| Mozzaik365 Contribution Center |
Here is a description of each application:
-
Jint Deployment is the application that performs installations and updates
of the Jint solution on your tenant. You will grant it
administrator rights to the app catalog in order to deploy the SharePoint packages. -
Jint Configurator is Jint's back office. It allows you
to administer the solution. It requests delegated permissions to identify
the user accessing the Configurator and configure Microsoft audiences:- User.Read
- GroupMember.Read.All
-
Jint Administration enables features of the “Unified
Experience.” It requests the following delegated permissions:- User.Read
- SharePoint AllSites.FullControl
-
Jint Site Engine allows you to duplicate and create fully
complete and populated sharing spaces from a template. It requests the following delegated permissions:- User.Read
- SharePoint AllSites.FullControl
- SharePoint TermStores.Read.All
-
Jint Contribution Center lets you create and share your content more simply and efficiently
- User.Read
- SharePoint AllSites.FullControl
Delegated permissions are permissions that authorize an application to access a specific
Microsoft 365 domain on behalf of a user. They allow Jint to display
all relevant information for each user. More information about delegated permissions
is available here.
3.3 Granting permissions to the app catalog
Permissions are granted to our Entra ID application exclusively through a set
of calls to the Microsoft Graph API. We provide a PowerShell script that can be downloaded here to make all these calls easier. This script grants administrator rights to our Jint Deployment application on your app catalog. When it runs, you will be prompted to sign in with a SharePoint administrator account. The script requires the delegated Sites.FullControl.All permission in order to grant the permission.
Once the archive has been downloaded, extract the script to the folder of your choice. Then open a
PowerShell command prompt and drag and drop the extracted file into the command prompt. Copy
and paste the app catalog URL after the script path and press Enter.
The command executed should have the following format:
CreateAzureAdAppPermissionOnSites.ps1<App catalog URL>
Reminder: You can find the app catalog URL by going to the SharePoint admin center > More features > Apps (Open).
Common error when running the PowerShell script
When running the CreateAzureAdAppPermissionOnSites.ps1 script, you may encounter the following error:
"cannot be loaded. The file is not digitally signed. You cannot run this script on the current system."
This means that the PowerShell execution policy on your machine is blocking scripts that are not digitally signed. Here's how to resolve it.
Option 1 — Unblock the file specifically (recommended)
This method targets only the downloaded script without modifying your system's global settings.
- Open PowerShell as administrator
- Run the following command, replacing the path with the path to your script:
Unblock-File -Path "C:\path\to\CreateAzureAdAppPermissionOnSites.ps1"
- Then run the script normally.
Option 2 — Temporarily change the execution policy
If option 1 does not work, you can allow the execution of unsigned local scripts for your session only:
Set-ExecutionPolicy -ExecutionPolicy RemoteSigned -Scope CurrentUser
Then run the script again. This change applies only to your user account and does not change the global system settings.
Option 3 — Run once without changing the policy
For a one-time run without making any configuration changes:
powershell.exe -ExecutionPolicy Bypass -File "C:\path\to\CreateAzureAdAppPermissionOnSites.ps1" <App catalog URL>
⚠️ Note: These operations require an account with local administrator rights on the machine. If you do not have these rights, contact your IT team.
3.4 Providing Jint with the information required for installation
Required access level for this step: Entra ID Administrator
To proceed with the installation of Jint, we need the following
information:
- Information about your Entra ID/SharePoint tenant:
- Entra ID tenant ID,
- Initial Entra ID/SharePoint tenant name,
- URL of the app catalog site identified in chapter 3.2,
- List of email addresses of users who administer the Jint solution.
Once this information has been collected, it must be provided to your Jint contact.
In the following chapters, we explain where to find some of this information.
3.4.1 Information about your Entra ID tenant
Go to the Overview section of the Entra ID portal. The tenant ID is called “Directory (tenant) ID” in the interface:
For the initial tenant name, go to the “Custom domain names” menu and look
for the entry ending in “.onmicrosoft.com.” You can use the filter bar. The initial name of
your tenant is what precedes “.onmicrosoft.com,” “Jint” in the example below.
3.5 Solution deployment by Jint
During this step, the Jint teams perform the initial deployment of the SharePoint packages,
as well as initialize your access to the Jint Configurator.
Once completed, you will be notified by your Jint contact.
3.6 Approval of calls to Microsoft APIs
Required access level for this step: SharePoint Administrator.
Go to Advanced > API access in the SharePoint admin center, or
directly via the URL:
https://<your-tenant> -admin.sharepoint.com/_layouts/15/online/AdminHome.aspx#/webApiPermissionManagement
and approve each pending request:
For more details about this step, please refer to Permission approval.
3.7 Approval of Jint API permissions
Authorizing access to Jint APIs allows you to use our services directly in SharePoint. These permissions are required to validate the user's identity and act with those permissions.
Required permission:
- API name: Jint Contribution Center
- Requested permission: Access_as_user
Optional permission:
- API name: Jint Translator
- Requested permission: user_impersonation
This authorization is only required for Translator features and is not necessary if you have not subscribed to this product.
Authorize an additional permission: Allow access to Jint Translator to access our translation service. To learn how to authorize the permission, see the article Permission approval.
3.8 Authorizing Jint service addresses
Required access level for this step: Network Administrator
This step is only necessary if you filter the addresses accessible from your Microsoft 365 tenant. Jint cannot be used if you are unable to access our services. If you filter allowed addresses, you must add the following addresses and all their subdomains to your allowlist:
Addresses:
- cdn-mozzaik.azureedge.net
- authentication-api-mozzaik.azurewebsites.net
- clientsettings-api-mozzaik.azurewebsites.net
- newshub-api-mozzaik.azurewebsites.net
- mozzaik365.net
Subdomains:
- cdn.mozzaik365.net
- config.mozzaik365.net
- translator.mozzaik365.net
- newshub.mozzaik365.net
- contribcent.mozzaik365.net
- api.mozzaik365.net
- clisettings.mozzaik365.net
Following our name change, you must also add the following addresses and subdomains:
Addresses:
- cdn-Jint.azureedge.net
- authentication-api-Jint.azurewebsites.net
- clientsettings-api-Jint.azurewebsites.net
- newshub-api-Jint.azurewebsites.net
- jint.io
Subdomains:
- cdn.jint.io
- config.jint.io
- translator.jint.io
- contribcent.jint.io
- newshub.jint.io
- api.jint.io
- clisettings.jint.io
4. Using the Jint solution
Jint has been correctly configured and deployed in your Microsoft environment! You can
now build your Digital Workplace experience using our components and
features.
The Jint Web Parts address business needs through configuration.
A single component can address different needs through its configuration.
Feel free to consult the Jint documentation in our help center to discover our
features and the various solutions we enable you to implement!
Comments
0 comments
Please sign in to leave a comment.