WHITEPAPER

Tessell Security Architecture on Azure

A technical overview of how Tessell secures customer Azure subscriptions, covering the bring-your-own-Azure onboarding flow, the least-privilege custom role model, and the exact permissions Tessell requests and excludes.

AzureSecurityArchitecture
Tessell Security Architecture on Azure

Least privilege

Custom role scoped to a single resource group

BYOA

Bring your own Azure subscription

ARM-automated

Role assignment and onboarding handled by an ARM template

You stay in control

Networks and encryption keys remain under your control by default

What's Inside

  • How BYOA onboarding works: how you authorize the Tessell Azure AD application and assign it a custom role to bring your own Azure subscription onto the platform

  • The least-privilege access model: how Tessell's access is confined to a custom "Tessell Operator" role scoped to a single resource group rather than the whole subscription

  • What the custom role can and cannot do: the default permission set, plus the actions Tessell explicitly excludes, such as elevating access and changing blueprint assignments

  • Default versus additional permissions: the difference between the bare-minimum permissions Tessell needs to function and the optional permissions that let it automate network and encryption-key creation

  • The deployment and consent flow: how the Azure consent screen and ARM template provision the role assignment and resources, step by step

  • The resources Tessell creates and manages: which Azure resources are created during onboarding and which stay under your control

Download the Whitepaper

Tessell Security Architecture on Azure
Share
Ready to move?

Start with a free estate assessment