Least privilege
Custom role scoped to a single resource group
BYOA
Bring your own Azure subscription
ARM-automated
Role assignment and onboarding handled by an ARM template
You stay in control
Networks and encryption keys remain under your control by default
What's Inside
How BYOA onboarding works: how you authorize the Tessell Azure AD application and assign it a custom role to bring your own Azure subscription onto the platform
The least-privilege access model: how Tessell's access is confined to a custom "Tessell Operator" role scoped to a single resource group rather than the whole subscription
What the custom role can and cannot do: the default permission set, plus the actions Tessell explicitly excludes, such as elevating access and changing blueprint assignments
Default versus additional permissions: the difference between the bare-minimum permissions Tessell needs to function and the optional permissions that let it automate network and encryption-key creation
The deployment and consent flow: how the Azure consent screen and ARM template provision the role assignment and resources, step by step
The resources Tessell creates and manages: which Azure resources are created during onboarding and which stay under your control
Download the Whitepaper





