This article describes how to prepare your Microsoft Azure environment for a private SLASCONE deployment. It is primarily intended for the Azure administrator responsible for preparing the subscription, permissions, identity configuration, and related infrastructure prerequisites.
SCOPE
A private deployment means that SLASCONE is deployed into a Microsoft Azure subscription owned and controlled by your organization.
SLASCONE is a cloud-native Azure application. Traditional on-premise installations on customer-managed virtual machines, local servers, or non-Azure infrastructure are not supported.
SLASCONE deploys and maintains the required Azure resources using Infrastructure as Code (IaC) and automated Azure DevOps pipelines. Your organization retains ownership of the Azure subscription and all resources deployed into it.
WHAT YOU NEED TO PREPARE
Before SLASCONE can perform the initial deployment, the following items need to be prepared:
An Azure subscription for the SLASCONE resources
A dedicated human Azure administrative account with temporary Owner permissions
A Microsoft Entra External ID tenant for SLASCONE user authentication
Entra ID app registration(s) for SSO
Customer-specific DNS names for the SLASCONE portal and API
PHASE 1: AZURE PREREQUISITES
AZURE SUBSCRIPTION
SLASCONE requires an active Microsoft Azure subscription in which the application resources can be deployed.
The subscription can either be dedicated to SLASCONE or shared with other workloads.
We strongly recommend using a dedicated Azure subscription for SLASCONE. This provides clear isolation, simplifies permissions and cost allocation, and significantly reduces the complexity of both the initial deployment and subsequent updates and operations.
Please inform SLASCONE before deployment if subscription-level Owner permissions cannot be provided. The IaC configuration and bootstrap process must then be adapted accordingly.
AZURE ADMINISTRATIVE ACCOUNT
For the initial installation, SLASCONE requires a dedicated human Azure account with sufficient permissions to prepare the Azure environment and bootstrap the automated deployment process.
This account is used during the initial installation to:
Create the managed identities used by SLASCONE
Configure workload identity federation for the SLASCONE Azure DevOps pipelines
Perform and troubleshoot the initial Infrastructure as Code deployment
For the standard deployment model, this account requires the Owner role on the Azure subscription during the initial installation.
Owner access is required during this bootstrap phase because the installation needs to create Azure resources, managed identities, and Azure role assignments.
ACCOUNT OPTIONS
There are two possible approaches for the administrative account:
Invite operations@slascone.com as a guest user into your Microsoft Entra tenant and assign the required Azure role. This is the recommended option because the account is managed and protected by SLASCONE.
Alternatively, your organization can create a dedicated account such as
slascone-admin@yourdomain.comand provide SLASCONE with access to this account according to your organization's security procedures.
We recommend using a dedicated account rather than the personal account of an individual Azure administrator. This makes the deployment access clearly identifiable and avoids dependencies on individual employees.
OWNER ACCESS IS TEMPORARY
The Owner role is primarily required for the initial installation and bootstrap process. It is not intended to remain permanently assigned to the human SLASCONE administrative account.
During the initial installation, SLASCONE creates the managed identities and permissions required for automated deployments and subsequent updates.
Once this automated deployment mechanism has been successfully established, the Owner role should be removed from the human administrative account.
The account can then be assigned a less privileged role according to the agreed operating model. For example:
Contributor on the SLASCONE resource groups if SLASCONE should retain human operational access for troubleshooting and support.
The final permission level should follow the principle of least privilege and is agreed as part of the post-installation handover.
PHASE 2: MICROSOFT ENTRA EXTERNAL ID
EXTERNAL ID TENANT
SLASCONE uses Microsoft Entra External ID as the identity platform for users signing in to the SLASCONE portal.
A Microsoft Entra External ID tenant is a separate tenant specifically designed for customer and external application identities. It is different from your organization's normal Microsoft Entra workforce tenant used for employees, Microsoft 365, and Azure administration.
If your organization already operates a Microsoft Entra External ID tenant, it may be possible to use that tenant. Please provide the tenant details to SLASCONE so that the setup can be reviewed.
If your organization does not already have an External ID tenant, a new one needs to be created.
CREATE A NEW EXTERNAL ID TENANT
Sign in to the Microsoft Entra admin center.
Navigate to Entra ID > Overview > Manage tenants.
Select Create.
Select External as the tenant type.
Enter an appropriate tenant name and initial
onmicrosoft.comdomain.Select the appropriate country or region.
Complete the tenant creation process.
GRANT SLASCONE ADMINISTRATIVE ACCESS
SLASCONE requires administrative access to the External ID tenant during the initial identity configuration.
In the External ID tenant:
Navigate to Entra ID > Users.
Select New user > Invite external user.
Invite operations@slascone.com.
Assign the Global Administrator role.
Global Administrator access is used during the initial setup to configure the SLASCONE applications, authentication flows, identity providers, and related External ID settings.
As with the Azure subscription Owner role, this level of administrative access should be reviewed after the initial installation and reduced according to the agreed operating model.
For more information about connecting your organization's Microsoft Entra ID or other identity providers to SLASCONE, see Identity Providers and Federation.
PHASE 3: INITIAL DEPLOYMENT
INFORMATION TO PROVIDE TO SLASCONE
Before the initial deployment, please provide SLASCONE with the following information:
Microsoft Entra tenant ID of the Azure subscription
Approved Azure region
External ID domain
INFRASTRUCTURE AS CODE
The initial SLASCONE infrastructure is deployed using Infrastructure as Code and automated Azure DevOps pipelines.
During this initial bootstrap deployment, the human Azure administrative account is used to create the required resources and managed identities.
The same Infrastructure as Code configuration is then used for subsequent infrastructure changes and updates, providing a reproducible deployment process and avoiding manual configuration drift between environments.
MANAGED IDENTITIES AND AUTOMATED DEPLOYMENTS
During the initial installation, SLASCONE creates the Azure managed identities required by the application and by the automated deployment process.
The deployment identity is connected to SLASCONE Azure DevOps using workload identity federation.
After this configuration has been completed, regular deployments and updates no longer depend on the human administrative account.
This also means that SLASCONE does not need to store customer Azure passwords, client secrets, or other long-lived deployment credentials in Azure DevOps.
PHASE 4: MICROSOFT ENTRA APP REGISTRATIONS
After the initial Azure deployment, Microsoft Entra application registrations need to be configured in your organization's workforce Entra tenant. This is the tenant associated with the Azure subscription in which SLASCONE has been deployed, not the separate External ID tenant.
These application registrations must be created and configured by an Entra administrator of your organization. SLASCONE will provide the deployment-specific values required for the configuration and assist your Entra administrator during the process.
The following application registrations are used:
SLASCONE Identity Graph Access: mandatory. Allows the SLASCONE API to securely access Microsoft Graph in the External ID tenant.
SLASCONE SSO (Federation - Private Deployment): optional. Required only if employees of your organization should be able to sign in to SLASCONE using their existing corporate Microsoft Entra ID accounts.
SLASCONE IDENTITY GRAPH ACCESS
This application registration allows the SLASCONE API running in your Azure subscription to access Microsoft Graph in the separate External ID tenant.
Authentication is based on workload identity federation. The Azure managed identity of the SLASCONE API is linked to this application registration as a federated credential. This allows the API to authenticate without using a client secret or certificate.
The application registration must be created in the workforce Entra tenant associated with the Azure subscription, because the application registration and the managed identity used as its federated credential must belong to the same Entra tenant. The application is configured as multitenant so that it can subsequently be provisioned into and used to access Microsoft Graph in the External ID tenant.
CREATE THE APPLICATION REGISTRATION
Sign in to the Microsoft Entra admin center and make sure you are working in the workforce tenant associated with the Azure subscription used for SLASCONE.
Navigate to Entra ID > App registrations > New registration.
Enter SLASCONE Identity Graph Access as the application name.
Under Supported account types, select Accounts in any organizational directory (Any Microsoft Entra ID tenant - Multitenant).
No Redirect URI is required.
Select Register.
Record the Application (client) ID and provide it to SLASCONE.
Microsoft documentation: Register an application in Microsoft Entra ID
CONFIGURE MICROSOFT GRAPH PERMISSIONS
The application requires Microsoft Graph application permissions in order to perform the identity operations required by SLASCONE. SLASCONE will provide the exact list of permissions required for the deployment.
Open the SLASCONE Identity Graph Access app registration.
Navigate to API permissions > Add a permission > Microsoft Graph.
Select Application permissions.
Add the Microsoft Graph permissions provided by SLASCONE.
Because Microsoft Graph will be accessed in the separate External ID tenant, the application is subsequently provisioned into that tenant and the required permissions must be granted administrator consent there.
SLASCONE will coordinate this step with the administrator of the External ID tenant after the application registration has been created.
Microsoft documentation: Grant tenant-wide admin consent to an application
CONFIGURE THE FEDERATED CREDENTIAL
The managed identity used by the SLASCONE API is created during the initial Azure deployment. This managed identity must now be configured as a federated credential of the SLASCONE Identity Graph Access application.
SLASCONE will provide the exact managed identity and deployment-specific values required for this configuration.
Open the SLASCONE Identity Graph Access app registration.
Navigate to Certificates & secrets > Federated credentials.
Select Add credential.
Under Federated credential scenario, select Managed Identity.
Select the user-assigned managed identity used by the SLASCONE API. SLASCONE will provide the name of the managed identity created during the deployment.
Enter a descriptive credential name, for example
slascone-api.Verify that the audience is
api://AzureADTokenExchangeand create the credential.
Once configured, the SLASCONE API can use its Azure managed identity to authenticate as the registered application and obtain the required Microsoft Graph access in the External ID tenant. No application client secret or certificate is required for this authentication.
Microsoft documentation: Configure an application to trust a managed identity
SLASCONE SSO (FEDERATION - PRIVATE DEPLOYMENT)
This second application registration is optional. It is only required if employees of your organization should be able to sign in to SLASCONE using their existing corporate Microsoft Entra ID accounts.
The application registration is created in your organization's workforce Entra tenant and is used to establish an OpenID Connect (OIDC) federation between the workforce Entra tenant and the SLASCONE External ID tenant.
Microsoft documentation: Add a Microsoft Entra ID tenant as an OpenID Connect identity provider
CREATE THE APPLICATION REGISTRATION
In the Microsoft Entra admin center, make sure you are working in your organization's workforce Entra tenant.
Navigate to Entra ID > App registrations > New registration.
Enter SLASCONE SSO (Federation - Private Deployment) as the application name.
Under Supported account types, select Accounts in this organizational directory only.
Under Redirect URI, select Web.
-
Add the redirect URIs for your External ID tenant. SLASCONE will provide the exact values. They follow the Microsoft Entra External ID federation format:
https://<tenant-subdomain>.ciamlogin.com/<tenant-ID>/federation/oauth2and
https://<tenant-subdomain>.ciamlogin.com/<tenant-subdomain>.onmicrosoft.com/federation/oauth2 Select Register.
CREATE A CLIENT SECRET
The External ID tenant authenticates against this application registration using a client secret.
Open the newly created SLASCONE SSO (Federation - Private Deployment) application registration.
Navigate to Certificates & secrets > Client secrets > New client secret.
Create a client secret according to your organization's credential lifetime policy.
Copy the secret value immediately after creation. Please note that the secret value cannot be retrieved again later.
CONFIGURE API PERMISSIONS
Configure the Microsoft Graph delegated permissions required for the federation:
emailopenidprofileUser.Read
Navigate to API permissions > Add a permission > Microsoft Graph.
Select Delegated permissions.
Add
email,openid,profile, andUser.Read.Select Grant admin consent for your organization.
Microsoft documentation: Grant tenant-wide admin consent to an application
PROVIDE THE CONFIGURATION TO SLASCONE
After completing the application registration, provide SLASCONE with:
Directory (tenant) ID of your workforce Entra tenant
Application (client) ID
Client secret value, transferred through an agreed secure channel
SLASCONE will then configure your workforce Entra tenant as an OpenID Connect identity provider in the External ID tenant and add it to the SLASCONE sign-in flow. Employees can subsequently sign in to SLASCONE using their existing organizational Microsoft Entra ID credentials.
PHASE 5: POST-INSTALLATION CONFIGURATION
SUBDOMAIN CONFIGURATION
A private deployment normally uses customer-specific subdomains for the SLASCONE portal and API.
For example:
licensing.yourdomain.comfor the SLASCONE portallicensing-api.yourdomain.comfor the SLASCONE API
SLASCONE provides the required DNS targets after the corresponding Azure resources have been deployed. Your organization is responsible for creating the required DNS records in your domain.
EMAIL CONFIGURATION
SLASCONE sends system emails, user invitations, and notifications.
The sender domain and email configuration should be agreed during deployment preparation. Depending on the operating model, emails can use SLASCONE-managed settings or customer-managed email infrastructure.
Typical topics to clarify include:
Sender address and domain
Email service configuration
Required DNS records
Authentication requirements
Internal approval or security requirements
MONITORING AND BACKUP
Monitoring, backup, alerting, and operational responsibilities are agreed as part of the private deployment operating model.
Because the Azure resources are located in your Azure subscription, your organization retains full visibility into the deployed resources and their Azure consumption.
The exact division of operational responsibilities depends on the agreed support model.
UPDATES
SLASCONE updates are deployed using the same automated deployment infrastructure established during the initial installation.
Depending on your requirements, updates can be installed after explicit customer approval or according to an agreed maintenance process. Different rules can be defined for DEV, QA, and PROD environments.
We recommend validating relevant updates in a non-production environment before deploying them to production.
PHASE 6: POST-INSTALLATION ACCESS REVIEW
REDUCE HUMAN ADMINISTRATIVE ACCESS
After the initial deployment has been completed successfully, the permissions assigned to the human administrative account should be reviewed.
At this point, the managed identities and workload identity federation required for automated deployments are already in place.
The Owner role can therefore normally be removed from the human administrative account.
Depending on the agreed support and operating model, the account can subsequently be:
Reduced to Contributor on the SLASCONE resource groups
Reduced to Reader on the SLASCONE resource groups
Or have its Azure permissions removed completely
This provides elevated permissions only during the bootstrap phase while allowing normal SLASCONE operations and updates to continue through the dedicated managed identities.
PRE-DEPLOYMENT CHECKLIST
Azure subscription prepared
Azure region agreed
Dedicated SLASCONE administrative account prepared
Owner role assigned for the initial deployment
External ID tenant available or created
operations@slascone.com granted the required External ID administrative access
Desired portal and API DNS names provided
Email configuration requirements clarified
Subscription ID and tenant information provided to SLASCONE
Once these prerequisites are complete, SLASCONE can perform the initial deployment, create the required managed identities, configure automated access, and complete the private deployment setup.
Comments
0 comments
Please sign in to leave a comment.