Skip to main content

Quick Start

Get OrbisID running in under 5 minutes. There are three ways to do it — pick whichever fits:

MethodBest forWhat you fetch
Windows InstallerWindows without DockerOne .exe, installed as native Windows services
Docker HubFastest path, always up to dateThree small config files; images are pulled live
Release PackageAir-gapped/offline installs, reproducible imagesOne tarball with the images bundled in

All three converge on Log In and Get Started below. Deploying to Kubernetes, AWS, Azure, or GCP instead? See the Kubernetes, AWS, Azure, and GCP guides.

Option A: Windows Installer​

A native Windows installer — no Docker required. It installs the backend, the frontend, and (unless you point it at a database you already run) PostgreSQL, each as its own Windows service.

Prerequisites​

  • Windows Server 2019+ or Windows 10/11, 64-bit
  • Administrator rights to run the installer
  • Ports 3000 (web UI) and 8080 (API) free on the machine — the installer opens inbound Windows Defender Firewall rules for both automatically

No separate Java, Node.js, or PostgreSQL installation is required — the installer bundles a JRE, a portable Node.js runtime, and (unless you point it at a database you already run) portable PostgreSQL binaries.

1. Download​

Download OrbisID-Setup.exe directly, or see the OrbisID website.

2. Run the installer​

  1. Run the downloaded .exe as Administrator.
  2. Accept the licence agreement.
  3. Choose an install directory (default: C:\Program Files\OrbisID\).
  4. Java Runtime page — use the bundled Temurin 17 JRE (default, no Java install needed) or point at an existing Java 17+ installation already on the machine.
  5. Database Configuration page — choose Install bundled PostgreSQL for me (default; recommended for a standalone or evaluation install), or Connect to an existing PostgreSQL server (enter host, port, database, username, and password, then click Test Connection — the database and user must already exist on that server; the installer does not create them for you on this path).
  6. Click Install. The installer registers and starts the Windows services listed below, and opens the firewall rules mentioned above.
  7. Once installation finishes, browse to https://localhost:8443 (the default port and HTTPS with a self-signed certificate — both configurable during setup). Accept the browser's certificate warning to continue.

Now continue at Log In and Get Started.

Services installed​

ServiceRuns
OrbisIDBackendThe Spring Boot backend (java -jar orbisid-backend.jar)
OrbisIDFrontendThe Next.js web UI (node server.js)
OrbisIDPostgresBundled PostgreSQL, if you chose the bundled-database option

Verify they're running:

sc query OrbisIDBackend
sc query OrbisIDFrontend
sc query OrbisIDPostgres

Configuration and logs live under C:\ProgramData\OrbisID\: Backend\/Frontend\/Postgres\ for per-service working directories (Postgres\data\ is the actual database — back it up like any production PostgreSQL instance), and logs\backend\/logs\frontend\/logs\postgres\ for log files.

Updating​

Download and run the newer version's installer over the existing install. It stops the running services, updates the installed files, and restarts them — C:\ProgramData\OrbisID\ (configuration, the generated encryption key and database password, and the PostgreSQL data directory) is preserved across the upgrade.

Uninstalling​

Use Add or Remove Programs, or run the uninstaller from the install directory (unins000.exe). It stops and removes all installed services and deletes the install directory. C:\ProgramData\OrbisID\ — including the PostgreSQL data directory, if the bundled database was used — is preserved; delete it manually only once you're certain you no longer need the data.

Known limitations​

  • No AI/Intelligence Layer (OrbisAI). This installer doesn't bundle or configure Ollama — AI features are unavailable through this installation path. Use one of the Docker-based options below if you need AI features.
  • Bundled PostgreSQL listens on the fixed port 5432, with no conflict-detection during setup. If another PostgreSQL instance already uses that port locally, the OrbisIDBackend service will fail to start — check the WinSW wrapper log under C:\ProgramData\OrbisID\logs\postgres\.
  • Single machine only. Backend, frontend, and (if used) the database all run on the same Windows box. For a multi-machine or containerised topology, use one of the Docker options below or a cloud deployment guide instead.
  • Windows Defender Firewall only. The firewall rules the installer creates only cover Windows' own built-in firewall — a third-party firewall product needs its own rule added manually for ports 3000/8080 if the app needs to be reachable from other machines on the network.

Option B: Docker Hub​

Pulls orbisid/orbisid-backend and orbisid/orbisid-frontend straight from Docker Hub — no release package to download first.

Prerequisites​

  • Docker 24+ and Docker Compose 2.20+ installed

1. Fetch the config files​

curl -O https://orbisid.com/releases/latest/docker-compose.yml
curl -O https://orbisid.com/releases/latest/.env.example
curl -O https://orbisid.com/releases/latest/nginx.conf
cp .env.example .env

nginx.conf is required alongside docker-compose.yml — the compose file bind-mounts it, so don't skip that download.

2. Configure and start​

Edit .env and set two required values:

# Generate an encryption key (do this once and keep it safe)
openssl rand -base64 32
.env
ENCRYPTION_KEY=<paste your generated key here>
POSTGRES_PASSWORD=<choose a strong database password>
Important

The ENCRYPTION_KEY is used to encrypt credentials stored in the database. If you lose this key, encrypted credentials cannot be recovered. Back it up securely.

docker compose up -d

There's no docker load step — docker compose up -d pulls the images live instead of loading them from a bundled images.tar.gz.

Wait for all services to become healthy — this first start takes a few minutes longer than usual, since it also pulls the Ollama container image and default AI models over the internet in the background:

docker compose ps

All services should show healthy or running. The ollama-init container will show Exited (0) once it finishes downloading the default AI models — that's expected, not a failure.

Now continue at Log In and Get Started.

Option C: Release Package​

Downloads a self-contained tarball with the Docker images already bundled in — no internet access needed after the download, useful for air-gapped installs. Requires Docker 24+ and Docker Compose 2.20+ (see Option B).

1. Download and extract​

Download orbisid-latest-all-in-one.tar.gz directly, or see the OrbisID website for other packages (including the External Database variant — see the Deployment Guide).

tar -xzf orbisid-latest-all-in-one.tar.gz
cd orbisid-latest-all-in-one

2. Create the environment file​

cp .env.example .env

Edit .env and set two required values:

# Generate an encryption key (do this once and keep it safe)
openssl rand -base64 32
.env
ENCRYPTION_KEY=<paste your generated key here>
POSTGRES_PASSWORD=<choose a strong database password>

The all-in-one package uses sensible defaults for the other database settings (POSTGRES_DB=orbisid, POSTGRES_USER=orbisid). These only need to be changed if you want to customise the database name or username — see the Configuration Reference for the full list of environment variables.

Important

The ENCRYPTION_KEY is used to encrypt credentials stored in the database. If you lose this key, encrypted credentials cannot be recovered. Back it up securely.

3. Load Docker images​

docker load -i images.tar.gz

This loads the bundled Docker images into your local Docker engine. It only needs to be run once per install — not on every start.

4. Start OrbisID​

docker compose up -d

Wait for all services to become healthy — this first start takes a few minutes longer than usual, since it also pulls the Ollama container image and default AI models over the internet in the background:

docker compose ps

All services should show healthy or running. The ollama-init container will show Exited (0) once it finishes downloading the default AI models — that's expected, not a failure.

Now continue at Log In and Get Started.

AI features

Both Docker options start a local Ollama container automatically and pull its image and default models on first start (no manual setup) — see AI Runtime (Ollama). AI features themselves are still off until an administrator turns them on, either at the Initial Setup prompt on first login or later in Administration > Settings > OrbisAI. See AI Assistant (OrbisAI) for details. The Windows Installer does not include AI features at all — see Option A's Known Limitations above.

Log In and Get Started​

Whichever option you used, the stack is now running the same way — pick up here (the Windows Installer serves the UI at https://localhost:8443 by default instead of http://localhost — accept the self-signed certificate warning; everything else below is identical).

Log in​

Open http://localhost in your browser.

FieldValue
Usernameadmin
PasswordChangeMe123!

You will be prompted to change the default password on first login.

Add your first system​

  1. Navigate to Systems in the sidebar
  2. Click Add System
  3. Enter connection details for an Active Directory domain controller or Linux server
  4. Click Test Connection to verify connectivity
  5. Save the system

Run your first scan​

Scan Now (all editions):

  1. Navigate to Systems in the sidebar
  2. Find the system you added and click the Scan Now button (▶)
  3. The scan starts immediately and results appear once complete

Create a Scan Policy (Pro and Enterprise only):

  1. Navigate to Scanning in the sidebar
  2. Click Create Policy
  3. Select the system you just added and configure a schedule (or leave as on-demand)
  4. Click Save, then Scan Now to trigger the first run immediately

OrbisID will connect to the target system, discover accounts and entitlements, and classify privileges using the default policy rules.

View results​

  • Dashboard shows KRI summary cards and system statistics
  • Accounts shows all discovered accounts with privilege levels
  • Reports lets you generate compliance reports

Next Steps​