myDRE is designed to work with one or more Microsoft Azure subscriptions of the Tenant (=client); all the Workspaces and related resources of the Tenant are deployed in those Subscriptions.
This document describes the full process, which is in part an interaction between the Tenant and anDREa BV and will take about one (1) hour. Other than stipulated in the requirements, there is no other preparation needed from the client.
Subscription Placement
For Subscription enrolment for Tenants with already existing Support Team, please jump to
Add Subscription section.
When a new tenant needs to be onboarded a new management group should be created under the path Dre Workspaces -> Production Stage Workspaces
To add a new management group, follow the below steps:
- Navigate to the desired parent management group. In this case Production Stage Workspaces
- Create a new management group by clicking on the Add Management Group button as shown below
- Complete the form presented to create a new management group.
- Management Group ID: This should be of the form mg-andrea-<tenant_abbreviation
- Management Group Display Name: This can be any display name of your choice. It is recommended to use complete tenant name e.g. OrganizationX University Medical Center
Create Security Group
When a new tenant is onboarded an Azure Active Directory security group needs to be created. To add a new security group follow the below steps
- Navigate to the group sections of Azure Active Directory by clicking here
- Create a new group by clicking on New group as shown below
Complete the form presented
Field | Value |
Group Type | Security |
Group Type | A name of the form: ST-<tenant_abbreviation> The name of the security group should match the exact tenant_abbreviation used in the previous step while creating the management group. |
Group description | A |
Azure AD roles can be assigned to the group (Preview) | No |
Membership type | Assigned |
Owners | One or more owners for the group. These are users who can add or remove members of the support team. You can add or remove members later as well. |
Members | One or more members of the group. These are the support team members of the tenant. You can add or remove members later as well. |
Add Subscription
This part, till the 'green' section takes between 10-20 minutes. If a subscription was already created, it might be done quicker.
- Decide on Microsoft Azure region
- All storing and processing of data takes place in the chosen region
- See: Multi-Region Implementation
- Check requirements
- Subscription must be Pay-As-You-Go (not free tier subscription like Microsoft Partner Network)
- Subscription cannot be of the type:
MS-AZR-0015P
MS-AZR-0144P
MS-AZR-0145P
MS-AZR-0146P
MS-AZR-0159P
- Create subscription and add Owner role
- Create a Subscription in the EA Portal of your tenant or request a subscription via the CSP Vendor.
- Select the Subscription from Azure Portal.
- Go to IAM -> Role Assignments
- Add role assignment (good practice: is to have 2 Owners)
- Role: Owner
- Assign access to Azure AD user, group, or service principle
- Select: <(Core) Support Team member>
- Click: Save
If the (Core) Support Team member(s) already have an anDREa account go to step 3, otherwise: - Email the email addresses of (Core) Support Team Members to support@mydre.org
- Inform (Core) Support Team Members they will receive an email with instructions from anDREa
A. anDREa adds the user to anDREa AAD
User will be added to anDREa AAD
The User will get in anDREa the Owner role of the target Subscription(s)-
B. Add Subscription Owners to anDREa AAD (only needed when they don't have an anDREa account already)
The Subscription Owners get a personalized message from anDREa
Click: Accept
Sign up for MFA when asked (MFA is always required)
Best to do this non on your phone for then you can use the QR-code to register in Microsoft Authenticator
- Prepare Subscription
- Click on Subscription
- Press: Change Directory
- Select: mydre.org
- Rename the Subscription: PX<xxxxx>-DRE-<tenant>-WORKSPACES (will be provided by anDREa)
- Be patient, this might take a while
- Change directory to: mydre.org
- Be patient, the move can take up to 25 minutes to be complete
Based on experience, this is a good point to stop the online meeting.
The additional steps can be dealt with by anDREa, once completed we'll contact the Support Team member and do a Workspace creation test to verify everything went okay.
- Associate Subscription
- Click on the Subscription
- Click on: IAM
- Click on: Add, Role Assignments
- Role: Owner
- Assign access to: Azure AD user, group, or service principle
- Select: licenseadmin@mydre.org
- Click: Save
Workspace Subscription Configuration
It is now time to configure the subscription for workspace creation. Please contact the DevOps team with the below details. After the below details are received by the DevOps team a new configuration is created in Azure DevOps Library for this subscription and the Andrea.Environment pipeline is executed that prepares your subscription for workspace provisioning.
Field | Value |
Subscription Id | This is the GUID of the subscription you added to the tenant management group. |
Subscription Name | This is the name of the subscription you added to the tenant management group. |
TBD
- Ensure Azure AD Security group for Everyone is added as a Management Group Reader to root workspace management group. This should happen automatically when the subscription is placed under the correct management group.
- Ensure that that Azure AD Security group Everyone-<Tenant> to the Everyone Security group as a member.
- Image Gallery:
- Ensure that ST-<Tenant> has read permissions on the gallery image(s) for the tenant or the common images.