Quick Start
Get OrbisID running in under 5 minutes. There are three ways to do it — pick whichever fits:
| Method | Best for | What you fetch |
|---|---|---|
| Windows Installer | Windows without Docker | One .exe, installed as native Windows services |
| Docker Hub | Fastest path, always up to date | Three small config files; images are pulled live |
| Release Package | Air-gapped/offline installs, reproducible images | One tarball with the images bundled in |
All three converge on Log In and Get Started below. Deploying to Kubernetes, AWS, Azure, or GCP instead? See the Kubernetes, AWS, Azure, and GCP guides.
Option A: Windows Installer
A native Windows installer — no Docker required. It installs the backend, the frontend, and (unless you point it at a database you already run) PostgreSQL, each as its own Windows service.
Prerequisites
- Windows Server 2019+ or Windows 10/11, 64-bit
- Administrator rights to run the installer
- Ports 3000 (web UI) and 8080 (API) free on the machine — the installer opens inbound Windows Defender Firewall rules for both automatically
No separate Java, Node.js, or PostgreSQL installation is required — the installer bundles a JRE, a portable Node.js runtime, and (unless you point it at a database you already run) portable PostgreSQL binaries.
1. Download
Download OrbisID-Setup.exe directly, or see the OrbisID website.
2. Run the installer
- Run the downloaded
.exeas Administrator. - Accept the licence agreement.
- Choose an install directory (default:
C:\Program Files\OrbisID\). - Java Runtime page — use the bundled Temurin 17 JRE (default, no Java install needed) or point at an existing Java 17+ installation already on the machine.
- Database Configuration page — choose Install bundled PostgreSQL for me (default; recommended for a standalone or evaluation install), or Connect to an existing PostgreSQL server (enter host, port, database, username, and password, then click Test Connection — the database and user must already exist on that server; the installer does not create them for you on this path).
- Click Install. The installer registers and starts the Windows services listed below, and opens the firewall rules mentioned above.
- Once installation finishes, browse to https://localhost:8443 (the default port and HTTPS with a self-signed certificate — both configurable during setup). Accept the browser's certificate warning to continue.
Now continue at Log In and Get Started.
Services installed
| Service | Runs |
|---|---|
OrbisIDBackend | The Spring Boot backend (java -jar orbisid-backend.jar) |
OrbisIDFrontend | The Next.js web UI (node server.js) |
OrbisIDPostgres | Bundled PostgreSQL, if you chose the bundled-database option |
Verify they're running:
sc query OrbisIDBackend
sc query OrbisIDFrontend
sc query OrbisIDPostgres
Configuration and logs live under C:\ProgramData\OrbisID\: Backend\/Frontend\/Postgres\ for per-service working directories (Postgres\data\ is the actual database — back it up like any production PostgreSQL instance), and logs\backend\/logs\frontend\/logs\postgres\ for log files.
Updating
Download and run the newer version's installer over the existing install. It stops the running services, updates the installed files, and restarts them — C:\ProgramData\OrbisID\ (configuration, the generated encryption key and database password, and the PostgreSQL data directory) is preserved across the upgrade.
Uninstalling
Use Add or Remove Programs, or run the uninstaller from the install directory (unins000.exe). It stops and removes all installed services and deletes the install directory. C:\ProgramData\OrbisID\ — including the PostgreSQL data directory, if the bundled database was used — is preserved; delete it manually only once you're certain you no longer need the data.
Known limitations
- No AI/Intelligence Layer (OrbisAI). This installer doesn't bundle or configure Ollama — AI features are unavailable through this installation path. Use one of the Docker-based options below if you need AI features.
- Bundled PostgreSQL listens on the fixed port 5432, with no conflict-detection during setup. If another PostgreSQL instance already uses that port locally, the
OrbisIDBackendservice will fail to start — check the WinSW wrapper log underC:\ProgramData\OrbisID\logs\postgres\. - Single machine only. Backend, frontend, and (if used) the database all run on the same Windows box. For a multi-machine or containerised topology, use one of the Docker options below or a cloud deployment guide instead.
- Windows Defender Firewall only. The firewall rules the installer creates only cover Windows' own built-in firewall — a third-party firewall product needs its own rule added manually for ports 3000/8080 if the app needs to be reachable from other machines on the network.
Option B: Docker Hub
Pulls orbisid/orbisid-backend and orbisid/orbisid-frontend straight from Docker Hub — no release package to download first.
Prerequisites
- Docker 24+ and Docker Compose 2.20+ installed
1. Fetch the config files
- Linux
- macOS
- Windows
curl -O https://orbisid.com/releases/latest/docker-compose.yml
curl -O https://orbisid.com/releases/latest/.env.example
curl -O https://orbisid.com/releases/latest/nginx.conf
cp .env.example .env
curl -O https://orbisid.com/releases/latest/docker-compose.yml
curl -O https://orbisid.com/releases/latest/.env.example
curl -O https://orbisid.com/releases/latest/nginx.conf
cp .env.example .env
Invoke-WebRequest -Uri https://orbisid.com/releases/latest/docker-compose.yml -OutFile docker-compose.yml
Invoke-WebRequest -Uri https://orbisid.com/releases/latest/.env.example -OutFile .env.example
Invoke-WebRequest -Uri https://orbisid.com/releases/latest/nginx.conf -OutFile nginx.conf
Copy-Item .env.example .env
nginx.conf is required alongside docker-compose.yml — the compose file bind-mounts it, so don't skip that download.
2. Configure and start
Edit .env and set two required values:
- Linux
- macOS
- Windows
# Generate an encryption key (do this once and keep it safe)
openssl rand -base64 32
# Generate an encryption key (do this once and keep it safe)
openssl rand -base64 32
# Generate an encryption key (do this once and keep it safe)
$bytes = New-Object byte[] 32
[System.Security.Cryptography.RandomNumberGenerator]::Fill($bytes)
[Convert]::ToBase64String($bytes)
ENCRYPTION_KEY=<paste your generated key here>
POSTGRES_PASSWORD=<choose a strong database password>
The ENCRYPTION_KEY is used to encrypt credentials stored in the database. If you lose this key, encrypted credentials cannot be recovered. Back it up securely.
- Linux
- macOS
- Windows
docker compose up -d
docker compose up -d
docker compose up -d
There's no docker load step — docker compose up -d pulls the images live instead of loading them from a bundled images.tar.gz.
Wait for all services to become healthy — this first start takes a few minutes longer than usual, since it also pulls the Ollama container image and default AI models over the internet in the background:
- Linux
- macOS
- Windows
docker compose ps
docker compose ps
docker compose ps
All services should show healthy or running. The ollama-init container will show Exited (0) once it finishes downloading the default AI models — that's expected, not a failure.
Now continue at Log In and Get Started.
Option C: Release Package
Downloads a self-contained tarball with the Docker images already bundled in — no internet access needed after the download, useful for air-gapped installs. Requires Docker 24+ and Docker Compose 2.20+ (see Option B).
1. Download and extract
Download orbisid-latest-all-in-one.tar.gz directly, or see the OrbisID website for other packages (including the External Database variant — see the Deployment Guide).
- Linux
- macOS
- Windows
tar -xzf orbisid-latest-all-in-one.tar.gz
cd orbisid-latest-all-in-one
tar -xzf orbisid-latest-all-in-one.tar.gz
cd orbisid-latest-all-in-one
tar -xzf orbisid-latest-all-in-one.tar.gz
cd orbisid-latest-all-in-one
Windows 10+ ships tar.exe natively, so this works unmodified from PowerShell.
2. Create the environment file
- Linux
- macOS
- Windows
cp .env.example .env
cp .env.example .env
Copy-Item .env.example .env
Edit .env and set two required values:
- Linux
- macOS
- Windows
# Generate an encryption key (do this once and keep it safe)
openssl rand -base64 32
# Generate an encryption key (do this once and keep it safe)
openssl rand -base64 32
# Generate an encryption key (do this once and keep it safe)
$bytes = New-Object byte[] 32
[System.Security.Cryptography.RandomNumberGenerator]::Fill($bytes)
[Convert]::ToBase64String($bytes)
ENCRYPTION_KEY=<paste your generated key here>
POSTGRES_PASSWORD=<choose a strong database password>
The all-in-one package uses sensible defaults for the other database settings (POSTGRES_DB=orbisid, POSTGRES_USER=orbisid). These only need to be changed if you want to customise the database name or username — see the Configuration Reference for the full list of environment variables.
The ENCRYPTION_KEY is used to encrypt credentials stored in the database. If you lose this key, encrypted credentials cannot be recovered. Back it up securely.
3. Load Docker images
- Linux
- macOS
- Windows
docker load -i images.tar.gz
docker load -i images.tar.gz
docker load -i images.tar.gz
This loads the bundled Docker images into your local Docker engine. It only needs to be run once per install — not on every start.
4. Start OrbisID
- Linux
- macOS
- Windows
docker compose up -d
docker compose up -d
docker compose up -d
Wait for all services to become healthy — this first start takes a few minutes longer than usual, since it also pulls the Ollama container image and default AI models over the internet in the background:
- Linux
- macOS
- Windows
docker compose ps
docker compose ps
docker compose ps
All services should show healthy or running. The ollama-init container will show Exited (0) once it finishes downloading the default AI models — that's expected, not a failure.
Now continue at Log In and Get Started.
Both Docker options start a local Ollama container automatically and pull its image and default models on first start (no manual setup) — see AI Runtime (Ollama). AI features themselves are still off until an administrator turns them on, either at the Initial Setup prompt on first login or later in Administration > Settings > OrbisAI. See AI Assistant (OrbisAI) for details. The Windows Installer does not include AI features at all — see Option A's Known Limitations above.
Log In and Get Started
Whichever option you used, the stack is now running the same way — pick up here (the Windows Installer serves the UI at https://localhost:8443 by default instead of http://localhost — accept the self-signed certificate warning; everything else below is identical).
Log in
Open http://localhost in your browser.
| Field | Value |
|---|---|
| Username | admin |
| Password | ChangeMe123! |
You will be prompted to change the default password on first login.
Add your first system
- Navigate to Systems in the sidebar
- Click Add System
- Enter connection details for an Active Directory domain controller or Linux server
- Click Test Connection to verify connectivity
- Save the system
Run your first scan
Scan Now (all editions):
- Navigate to Systems in the sidebar
- Find the system you added and click the Scan Now button (▶)
- The scan starts immediately and results appear once complete
Create a Scan Policy (Pro and Enterprise only):
- Navigate to Scanning in the sidebar
- Click Create Policy
- Select the system you just added and configure a schedule (or leave as on-demand)
- Click Save, then Scan Now to trigger the first run immediately
OrbisID will connect to the target system, discover accounts and entitlements, and classify privileges using the default policy rules.
View results
- Dashboard shows KRI summary cards and system statistics
- Accounts shows all discovered accounts with privilege levels
- Reports lets you generate compliance reports
Next Steps
- Deployment Guide - configure TLS, external database, and production settings
- Configuration Reference - all environment variables and settings
- Systems - learn about all supported system types