Deploy Onplana Projects
This guide is for the SharePoint or Microsoft 365 administrator who installs Onplana Projects. The package adds:
- An Onplana app page a site owner adds to a project site, where people work on the project’s tasks, milestones, issues, risks, ideas, files and members without leaving SharePoint.
- Six web parts for any page: project status, a timeline, a person’s tasks, issues and risks, portfolio health, and approvals.
- Two document-library commands, so people can link a file to an Onplana task or start a task from it.
- The Onplana bar, a thin bar at the top of a site’s pages that links to the site’s Onplana page.
It is free on every Onplana plan, including Free. Each person still needs their own Onplana account to sign in, and sees only what Onplana already lets them see.
If you want to use the web parts rather than install them, see Use Onplana in SharePoint.
What the package needs
Section titled “What the package needs”- One permission, on Onplana’s own API. The package asks for
access_as_useron Onplana’s sign-in app, an Entra app also named Onplana Projects. It lets a web part sign the person in to Onplana and nothing else. - A sign-in-only app. That app asks Microsoft for nothing but sign-in and
basic profile (
openid,profile,email,User.Read). It has no permission to your mail, files, calendars or sites. - No Microsoft Graph permission and no SharePoint permission in the package itself.
- No new lists or libraries. It adds web parts, one document-library command set and the Onplana bar. Pages and files are created only when a person asks for one, with that person’s own SharePoint rights (see What the package changes in SharePoint).
Onplana’s optional Microsoft integrations (Outlook, OneDrive, calendar and the others a person can connect inside Onplana) use a different Onplana app. Nothing in this guide grants their permissions.
Onplana stores links to SharePoint files, never copies of them, so your sensitivity labels, retention, permissions and audit keep applying to every file. The full statement is in Data and compliance below.
Upload the package to the App Catalog
Section titled “Upload the package to the App Catalog”-
Get the package file,
onplana-sharepoint.sppkg, by emailing support@onplana.com. -
Open your tenant App Catalog site. In the SharePoint admin center, go to More features > Apps > Open.
-
Upload
onplana-sharepoint.sppkg. It appears as Onplana Projects. -
When SharePoint asks whether to enable the app, tick Make this app available to all sites in the organization, then select Enable app. This is tenant-wide deployment: you install once and every site has the web parts and the library commands, with nothing to add site by site.
Grant admin consent, then approve the API permission
Section titled “Grant admin consent, then approve the API permission”Two one-time steps, both tenant-wide. SharePoint can approve Onplana’s request only once your tenant knows Onplana’s sign-in app, and admin consent is what adds it.
-
Grant admin consent. A Global Administrator or Application Administrator opens this link and accepts:
Grant consent to Onplana Projects
This registers Onplana’s sign-in app in your Microsoft Entra ID and lets it, for everyone in your organization, sign people in and read the signed-in person’s own profile (such as their name and email address). That is all the app asks for. It grants no access to mail, files, calendars, Teams or SharePoint content.
-
Approve the API permission. In the SharePoint admin center, go to Advanced > API access. Under Pending requests, find the request for Onplana Projects with the permission access_as_user, select it and choose Approve.
The approval grants access to Onplana only. It gives Onplana no access to anything in SharePoint or Microsoft 365.
Add a web part
Section titled “Add a web part”All six web parts are in the Advanced group of the web part toolbox, each named Onplana …. Edit a page, select +, and search for “Onplana”.
A web part works as soon as you add it, with nothing to set. Its settings pane opens on a line saying what the part shows, and the rest can be left as it is:
| Setting | What to do |
|---|---|
| Project | For the web parts that use one project. Leave it on This site’s connected project, or pick one of the projects you can read in Onplana. |
| Read-only link for people without Onplana (optional) | An Onplana read-only link, shown to people who cannot sign in. See Read-only links. |
| One workspace for everyone (optional) > Organization ID | Leave it empty and each visitor sees their own Onplana workspace, taken from their sign-in. Someone who belongs to several is asked once which to use, and their browser remembers it. To make a page show one workspace for everyone, paste its id here. |
| Advanced (staging and testing) > API base URL and App ID URI | Leave them as they are. |
To copy an organization’s id, open Organization Settings in Onplana (at
/org/settings), stay on the General tab, and select Copy beside
Organization ID. An id that is not 25 lowercase letters and digits is
refused with a message saying so.
What each web part does with Project:
| Web part | Project |
|---|---|
| Onplana project status | The project to show; by default the project connected to this site |
| Onplana timeline | The project to show; by default the project connected to this site |
| Onplana issues and risks | The project to show; by default the project connected to this site |
| Onplana my tasks | Optional. Pick one to turn on quick add; new tasks go to that project. |
| Onplana my approvals | The project whose change requests are listed; by default the project connected to this site |
| Onplana portfolio health | Not used. Portfolios need the Business plan or above. |
The project list shows once the web part has signed you in. A page set up with a typed Project ID before the list existed shows it as Project set by id; pick another choice to change it.
A web part says “Finish the web part settings to connect it to Onplana.” only
when API base URL has been changed to an address that is not Onplana’s.
Put https://api.onplana.com/api back.
Connect a site to a project once
Section titled “Connect a site to a project once”A web part that shows one project can follow the site instead of naming a project. Leave Project on This site’s connected project, and the web part shows the Onplana project that keeps its files in this site. If no project does yet, a site owner sees a Connect form in the web part: choose a project and select Connect. The site’s default document library becomes that project’s SharePoint folder, and every Onplana web part on the site follows it. Connecting needs the right to edit the project in Onplana.
The document-library commands
Section titled “The document-library commands”With tenant-wide deployment, every document library gets two commands when a person selects one file: Link to Onplana task and Create task from this file. They have no settings pane. They use Onplana’s own address and App ID URI, and take the organization from the person’s own sign-in.
If you need to point them somewhere else, change apiBaseUrl and appIdUri
in the extension’s Properties in the App Catalog’s Tenant Wide
Extensions list. Most tenants never need to.
The Onplana app page
Section titled “The Onplana app page”A site owner adds the app page from New > Page, then Onplana in the template gallery’s Full-page apps section, or with Set up Onplana in the Onplana bar. It has no settings of its own: it opens the project connected to the site, and the first time a site owner picks that project. See Open Onplana as a full page on your site.
The Onplana bar
Section titled “The Onplana bar”With tenant-wide deployment, every site shows a thin bar at the top of its pages:
- On a site that has an Onplana page, everyone sees “This site’s project plan is in Onplana.” with Open the project page.
- On a site without one, only people who can manage the site see “This site is not set up for Onplana yet.” with Set up Onplana, which creates the page, adds it to the site navigation and opens it. Everyone else sees nothing.
The bar reads only the site’s navigation. It makes no Onplana call and does not sign anyone in. Anyone can hide it for a site with Hide on this site.
To turn the bar off for the whole tenant, open the App Catalog’s Tenant Wide Extensions list and disable or delete the OnplanaBar entry. The web parts and the library commands keep working.
When the web parts say Onplana is not available
Section titled “When the web parts say Onplana is not available”Until Onplana turns sign-in from SharePoint on, every web part says “Onplana Projects is not available yet.” No setting on your side changes that. If you see it after the package has launched, contact support.
What the package changes in SharePoint
Section titled “What the package changes in SharePoint”Nothing on install. After that, it writes to SharePoint only when a person asks, and always as that person, with their own SharePoint permissions:
- Set up Onplana (site owners) creates the Onplana page and adds it to the site navigation.
- Upload from this device, in a task’s Files tab on the app page, uploads a file of up to 250 MB into the site, in the project’s folder or the site’s documents library, and links it to the task. With Replace, it overwrites a file of the same name.
The app page’s Documents tab and the bar only read: the site’s documents library and its navigation, as the person sees them.
Data and compliance
Section titled “Data and compliance”- What lives where. Projects, tasks, issues, risks and approvals live in Onplana. Files stay in SharePoint. Onplana keeps a file’s name and address, never its contents.
- SharePoint’s controls keep applying. Sensitivity labels, retention, holds and permissions stay exactly as you set them. Opening a linked file opens its SharePoint address, and SharePoint decides whether that person may open it.
- Sessions. The Onplana session is kept in the page’s memory only, never in browser storage, so it ends when the page closes. The browser remembers only which Onplana organization a person picked, never a sign-in.
- Accounts. Onplana never creates an account from SharePoint. A person without one is told so and sent to Onplana to decide.
- Audit. Sign-ins, folder links and file links made from SharePoint appear in Onplana’s audit log with the channel SHAREPOINT. File activity stays in Microsoft Purview audit, as for any SharePoint file.
Uninstall
Section titled “Uninstall”-
In the App Catalog, select Onplana Projects and delete it. Its web parts and library commands disappear from every site.
-
Optional: in the SharePoint admin center, go to Advanced > API access and remove the Onplana Projects approval.
-
Optional: in Microsoft Entra ID, remove the Onplana Projects enterprise application that admin consent added. People in your organization can then no longer sign in to Onplana with Microsoft through that app.
What uninstalling does and does not do:
- In SharePoint, every file and folder stays where it is, with its permissions, labels and history, including files people uploaded from the app. The package created no lists or libraries. Onplana pages that site owners created stay too, but the app no longer loads on them; delete them like any page.
- In Onplana, nothing is deleted. Projects, tasks, folder links and file links stay, and each file link still opens the file in SharePoint from the Onplana web app. To remove a link, remove it from the task in Onplana; the file is never touched.
Troubleshooting
Section titled “Troubleshooting”| What you see | What it means | What to do |
|---|---|---|
| The Onplana Projects request cannot be approved, or SharePoint says it cannot find the resource or the app. | Admin consent has not been granted yet, so your tenant does not know the app the request is for. | Do step 1 in Grant admin consent, then approve the API permission, then approve again. |
| The consent link says you need an administrator. | Only a Global Administrator or Application Administrator can grant admin consent. | Ask one of them to open the link. |
| No request for Onplana Projects appears under API access. | The package was not enabled, or the upload did not finish. | Check the App Catalog shows Onplana Projects as enabled, then look again. |
| Only an old Onplana Production request or approval is listed. | The package installed is an earlier version. | Upload the current package, then approve the Onplana Projects request. |
Does approving the permission give Onplana access to our files? No. Admin consent covers sign-in and basic profile only, and the API approval allows sign-in to Onplana’s own API only. The package has no Microsoft Graph or SharePoint permission and never downloads a file.
Why does this need admin consent at all? SharePoint can approve a request only for an app your tenant already knows. Admin consent is what adds Onplana’s sign-in app to your tenant, and it covers sign-in and basic profile, nothing more.
Does the package cost extra? No. It is free on every Onplana plan, including Free. Each person’s Onplana plan decides what they can use, as in the browser.
Do we have to configure each web part? No. Added as they are, they sign each visitor in and show that person’s own organization. Set Organization ID or pick a Project only to fix what a page shows.
Do all our people need Onplana accounts? To work in Onplana, yes. To read one plan, no: give the web part a read-only link and people without an account see the plan read only.
Can guests on our sites use the web parts? Usually not. Onplana signs a guest in only when Microsoft has proved the guest’s email address, and Microsoft rarely does for guests. Guests see a message that says so, and the read-only link if the web part has one. This is deliberate, so nobody can claim an Onplana account with an address they do not own. A guest can still open Onplana directly and sign in there.
Does Onplana create anything in SharePoint? Not on its own. It creates no lists or libraries. A site owner’s Set up Onplana creates one page, and a person’s Upload from this device creates a file, each with that person’s own SharePoint permissions. Linking a file never changes it.
Related
Section titled “Related”- Use Onplana in SharePoint, the guide for page editors and everyone who uses the web parts
- Attach files from SharePoint, the file picker inside the Onplana web app
- Deploy Onplana for Microsoft Teams, the Teams app
- Understand roles and permissions, how Onplana decides what each person can see
Was this helpful?
Thanks for your feedback!