Skip to main content

Overview

All resources live in your Azure account, and data never leaves your cloud. With Managed On-Premise, Paragon deploys, configures, and manages the Paragon installation in your Azure account. You own the infrastructure and resources. Paragon access to your environment is on-demand for support requests only, via a secure bastion. Other resources in your Azure account remain inaccessible.

Security

We use a least-privilege access model through Azure tenants, subscriptions, and RBAC:
  • A new tenant for Paragon resources, separate from other resources
  • A new subscription for all Paragon resources in that tenant
  • An installer app registration with custom RBAC scoped to that subscription — narrower than Azure’s built-in Contributor role. During onboarding, your Azure admin runs a Paragon-provided role-setup script that assigns only the permissions needed to deploy and operate the installation.
You maintain full control over infrastructure access, can view all created resources, split billing, retain super-user access, and audit all Paragon activity through Azure Monitor.

Setup

We’ll need four values to install Paragon.
  • Tenant Id
  • Subscription Id
  • Client Id
  • Client Secret

Directions

  1. Login to your Azure portal as an admin.
  2. Create a tenant. a. Search Azure Active Directory in the search bar, navigate to your Azure Active Directory, and click the Manage tenants tab. b. Click + Create. c. Select Azure Active Directory as the tenant type in the Basics tab. d. Click the Configuration tab. e. Enter Paragon as the Organization name. f. Enter a domain name with paragon and your organization’s name, i.e. paragongoogle. The domain must be alphanumeric. g. Click the Review + create tab. h. Click the Create button to create the tenant. i. Search Azure Active Directory in the search bar, navigate to your Azure Active Directory. j. ⭐️ Copy the text in the Overview section next to Tenant ID. This is the Tenant Id. ⭐️
  3. Create a subscription under the tenant. a. Switch to your default Azure directory. You can do this by clicking your account in the top right corner and clicking Switch directory. b. Search Subscriptions in the search bar, and navigate to your Subscriptions. c. Click +Add d. In the Basics tab, enter Paragon for the Subscription name. e. Click the Advanced tab and select the new tenant you created for the Subscription directory. f. Click the Review + create tab. g. Confirm the name of the subscription is correct in the Basics section and the correct tenant is selected in the Advanced section. h. Click Create. i. ⭐️ Copy the id of the subscription. This is the Subscription Id. ⭐️
  4. Create credentials for the Paragon installer. a. Switch to the new Paragon directory. You can do this by clicking your account in the top right corner and clicking Switch directory. b. Search Azure Active Directory in the search bar, navigate to your Azure Active Directory, and click the App registrations tab. c. Click + New registration. d. Enter Paragon Installer for the name of the application. e. Select Accounts in this organizational directory only for the access type. f. Leave the Redirect URI (optional) field empty. g. Click Create to create the application. h. ⭐️ Save the text next to Application (client) ID. This is the Client Id. ⭐️ i. Click Add a certificate or secret next to Client credentials. j. Click + New client secret to create a new secret. k. Enter Paragon Installer for the description. l. Select 24 months for Expires. m. Click Add to create the secret. n. ⭐️ Save the text under the Value column. This is the Client Secret. ⭐️

Next Steps

Provide the four values, and we’ll set up your installation. Your Paragon team will share a role-setup script for an Azure admin to run; it grants the installer scoped access on the Paragon subscription, not the built-in Contributor role. If you have any questions, email enterprise@useparagon.com for help.