Overview
All resources live in your Azure account, and data never leaves your cloud. With Managed On-Premise, Paragon deploys, configures, and manages the Paragon installation in your Azure account. You own the infrastructure and resources. Paragon access to your environment is on-demand for support requests only, via a secure bastion. Other resources in your Azure account remain inaccessible.Security
We use a least-privilege access model through Azure tenants, subscriptions, and RBAC:- A new tenant for Paragon resources, separate from other resources
- A new subscription for all Paragon resources in that tenant
- An installer app registration with custom RBAC scoped to that subscription — narrower than Azure’s built-in Contributor role. During onboarding, your Azure admin runs a Paragon-provided role-setup script that assigns only the permissions needed to deploy and operate the installation.
Setup
We’ll need four values to install Paragon.- Tenant Id
- Subscription Id
- Client Id
- Client Secret
Directions
- Login to your Azure portal as an admin.
-
Create a tenant.
a. Search
Azure Active Directoryin the search bar, navigate to your Azure Active Directory, and click the Manage tenants tab. b. Click + Create. c. Select Azure Active Directory as the tenant type in the Basics tab. d. Click the Configuration tab. e. EnterParagonas the Organization name. f. Enter a domain name withparagonand your organization’s name, i.e.paragongoogle. The domain must be alphanumeric. g. Click the Review + create tab. h. Click the Create button to create the tenant. i. SearchAzure Active Directoryin the search bar, navigate to your Azure Active Directory. j. ⭐️ Copy the text in the Overview section next to Tenant ID. This is the Tenant Id. ⭐️ -
Create a subscription under the tenant.
a. Switch to your default Azure directory. You can do this by clicking your account in the top right corner and clicking Switch directory.
b. Search
Subscriptionsin the search bar, and navigate to your Subscriptions. c. Click +Add d. In the Basics tab, enterParagonfor the Subscription name. e. Click the Advanced tab and select the new tenant you created for the Subscription directory. f. Click the Review + create tab. g. Confirm the name of the subscription is correct in the Basics section and the correct tenant is selected in the Advanced section. h. Click Create. i. ⭐️ Copy the id of the subscription. This is the Subscription Id. ⭐️ -
Create credentials for the Paragon installer.
a. Switch to the new Paragon directory. You can do this by clicking your account in the top right corner and clicking Switch directory.
b. Search
Azure Active Directoryin the search bar, navigate to your Azure Active Directory, and click the App registrations tab. c. Click + New registration. d. EnterParagon Installerfor the name of the application. e. SelectAccounts in this organizational directory onlyfor the access type. f. Leave the Redirect URI (optional) field empty. g. Click Create to create the application. h. ⭐️ Save the text next to Application (client) ID. This is the Client Id. ⭐️ i. Click Add a certificate or secret next to Client credentials. j. Click + New client secret to create a new secret. k. EnterParagon Installerfor the description. l. Select24 monthsfor Expires. m. Click Add to create the secret. n. ⭐️ Save the text under the Value column. This is the Client Secret. ⭐️