---
title: "Connect for ArcGIS - Prerequisites for ArcGIS Enterprise"
canonical: "https://help.cartinuum.com/space/GC1/4172710066/Connect%20for%20ArcGIS%20-%20Prerequisites%20for%20ArcGIS%20Enterprise"
format: markdown
---
This article describes the prerequisites required for using Connect for ArcGIS in **ArcGIS Enterprise**. The requirements are slightly different depending on whether you are using ArcGIS Online or ArcGIS Enterprise in your organisation.  
 

## ArcGIS Enterprise

1. **Access Rights**

When setting up Connect for ArcGIS, the first user must be an **ADMINISTRATOR** for the ArcGIS Enterprise organisation. Non-administrators will not be able to setup Connect for ArcGIS. Additional Connect for ArcGIS admins can be added later by adding them to an ArcGIS Enterprise user group.

2. **Firewall Access**

If your ArcGIS Enterprise is not available on the internet, the Connect for ArcGIS server will need to be given special access to your environment. There are a couple of options for this: -

- [PREFERRED] Install and run the Connect for ArcGIS Relay Service. The relay service runs as an agent to initiate a connection from inside the network to the Connect for ArcGIS servers. This is a common model for providing secure access between SaaS applications and business systems running inside the firewall. [Refer to this help article for installing the Connect for ArcGIS Relay Service](https://bgt-innovation.atlassian.net/wiki/spaces/GC1/pages/4172546173).
- [ALTERNATE] Open up access to your network from the Connect for ArcGIS servers.  
You will need to work with your network administrators to plan for this access. Some common options include IP Whitelisting and/or an API Gateway running in the DMZ.Note: The Connect for ArcGIS servers require access to any business system you intend to pull data from to display alongside the map or include in reports. The Connect for ArcGIS Relay Service can provide access to all internal business systems; using the alternate approach  may require network configuration for each system running inside the firewall.

3. **Organization Security Settings**

Some security settings on your ArcGIS Enterprise account can block access to Connect for ArcGIS.

- **Allow origins** - Limit the web application domains that can connect via Cross-Origin Resource Sharing (CORS) to the ArcGIS REST API. If your organization restricts the domains that can connect via CORS, you must add [https://connect.geovonic.com](https://connect.geovonic.com) and [https://app.cartinuum.com](https://app.cartinuum.com) to the list of allowed origins.  
[See this FAQ for more information](https://bgt-innovation.atlassian.net/wiki/spaces/GC1/pages/4173266976).
- **Approved apps** - Members can only sign in to external apps that are approved. If your organization limits the external apps that can be accessed, you must Connect for ArcGIS to the list of approved apps.  
[See this FAQ for more information](https://bgt-innovation.atlassian.net/wiki/spaces/GC1/pages/4173856786).