Skip to main content
Version: 4.1 (2026 H2)

Complete configuration

Once the Azure services have been provided, the primedocs configuration still needs to be stored and the actual application deployed.

Create configuration​

The necessary primedocs.config will be created for you by our support team. We need the following information for this:

  • HostUrl: The URL of the app service.
  • StorageAccountName: The name of the storage account.
  • DbConnectionString: The ConnectionString from the productive database.
  • OperationDbConnectionString: The ConnectionString from the second database.
  • AzureAdClientId: The ClientId of the Entra App Registration
  • AzureAdClientSecret: The ClientSecret of the Entra App Registration
  • AzureAdDataSourceAdminAppClientId: The ClientId of the Entra App Registration for the DataSourceAdminApp
  • AzureAdDataSourceAdminAppClientSecret: The ClientSecret of the Entra App Registration for the DataSourceAdminApp
  • AllowedTenantId: The tenant ID of the Entra ID
  • KeyVaultUrl: The URL to the key vault key (e.g. https://CUSTOMER.vault.azure.net/keys/dataprotection/{keynumber})

A primedocs.config and a cert.pfx are then created, which are stored in the primedocs-customer container.

Find details to the primedocs.config here: primedocs.config

Deployment​

Deployment takes place via a ZipDeploy, which can be executed most easily via the advanced tools:

The supplied .zip can then be uploaded here:

Configure DataSourceAdminApp​

After deployment, further configuration is available here:

https://CUSTOMER.com/datasourceadminapp

Commissioning and operation test​

The actual commissioning (initialising the database, creating the encryption key) and the operation test work essentially the same as for an on-premises installation. Follow these pages:

  • Commissioning the primedocs server — initialise the database via the dashboard and generate the symmetric encryption key.
  • Operation test — call the server applications individually via the browser (using the app service domain instead of your-url.example.com).

Note the following Azure-specific deviations:

  • Restricting dashboard access: In Azure, access to the DataSourceAdminApp is controlled via the Entra ID app registration and the user assignment of the enterprise application, not via Windows authentication and a Web.config (see Entra ID Apps).
  • Background jobs: In Azure, background processing (e.g. user synchronisation) runs via Azure WebJobs rather than a Windows scheduled task. This requires the Always On option to be enabled (see App Service › Always On).