myDRE Standard Services Specification
This document details the standard product features, identity workflows, and support services natively available within the myDRE platform. It serves as an audit-ready specification mapping directly to ISO 27001:2023 (A.05.20 - Requirements for Supplier Agreements, A.08.19 - Access Rights) and NIS 2 (Risk Management & Platform Governance) frameworks.
1. Research Support & Institutional Enablement
anDREa provides structural onboarding, ongoing validation, and technical tooling to empower the Tenant's decentralized Local Research Support (RS) Teams.
Support Infrastructure & Meetings
- Structured Training & Support: Includes comprehensive RS team onboarding, targeted specialized training modules, and ongoing ad-hoc advisory support.
- Bi-Weekly Support Architecture: Mandatory bi-weekly Support Team alignment meetings to track operational performance, framework updates, and platform anomalies.
- System Knowledge Base: Unrestricted access to the core repository, including restricted ("hidden") administrative profiles explicitly reserved for support infrastructure management.
Ticket & SLA Customization (Zoho Desk Matrix)
- Provisioning of specialized Agent and Light Agent credentials on
support.mydre.org. - Full structural autonomy to configure custom ticket forms, define organization-specific SLAs, generate automated compliance metrics, and curate Tenant-exclusive internal Knowledge Base sections.
Infrastructure Delegation & Control
- Dedicated access enabling the RS team to provision isolated Workspaces directly within the Tenant's Azure Subscriptions (capped at 100 Workspaces per individual subscription).
- Multi-subscription scalability support, allowing seamless link mapping to Tenant-specific on-premises infrastructure via dedicated network configurations.
- Decentralized management hooks to dynamically assign or modify the designated Workspace Accountable and manage cost center allocations.
- Administrative pathways to enroll new researchers into the centralized anDREa Entra ID ecosystem alongside myDRE Insights integration.
2. User Portal Operational Parameters (mydre.org)
The primary workspace environment operates under a zero-trust model where available dashboard actions scale dynamically based on the researcher’s role (Accountable, Privileged Member, or Member) as assigned by the Workspace Accountable.
Security, Identity, & Self-Service Boundary
- Enforced Access Matrix: Access to the portal is strictly gated via multi-factor authentication (MFA) utilizing the Microsoft Authenticator app with advanced contextual indicators.
- Granular Profile Control: Users retain direct self-service paths to initiate secure password resets, enroll new MFA profiles, provision physical FIDO2-compliant hardware security keys, and manage automated identity lifecycle synchronization via SCIM.
- Community Engagement: Universal access to the public Knowledge Base, automated system status announcements, and active participation in the dedicated myDRE Community section.
Virtual Machine (VM) Management
- Scale Constraints: Provisioning supports up to a default maximum of 11 concurrently active VMs per individual Workspace.
- Orchestration Matrix: Users can dynamically audit VM power states, deploy new instances using either vanilla base distributions (Windows Server / Linux) or custom organization-specific templates, utilize cost-optimized Azure Spot VMs, and rename active assets.
- Access Control: Facilitates secure Remote Desktop Protocol (RDP) file downloads for Windows workstations.
To maintain a secure network boundary, direct external access to Linux instances is restricted. Linux environments must be accessed securely via a Windows jump box VM.
- Hardware Adjustments: Enables hot-resizing of active OS disk volumes and machine SKUs (restricted to pre-approved, Tenant-specific Azure hardware subsets).
- Automated Shutdown Control: Users can toggle or customize specific automated de-allocation profiles (specifying exact execution times and time zones) to optimize budget burn rates.
- Workspace Replication: Enables users to capture a live VM state and mirror it as a master image available for clean deployments within that specific Workspace (broader platform-wide distribution can be executed via a standard support ticket).
File System, Ingress, & Egress Controls
- Shared Storage Fabric: All files are written directly to an isolated, encrypted network share accessible only by the VMs explicitly provisioned inside that specific Workspace.
- Forensic Resiliency: Enforces continuous 24-hour, 30-day rolling snapshot protection. Snapshots are self-service restorable by users; anDREa maintains a zero-knowledge stance and cannot view or access fileshare contents.
- Data Ingress Paths: Supports direct web-browser drag-and-drop actions for small files, enterprise-grade data moves via Azure Storage Explorer, or integration with the automated Upload API.
- Data Egress Gates: Outbound data transfers require a formal Download Request or Workspace-to-Workspace transfer loop.
Data transfers between Workspaces require the initiating researcher to hold active, verified memberships in both the source and target environments. Egress approvals require manual validation and download authorization from an explicitly assigned Privileged Member.
External Network & Budgetary Governance
- Outbound Domain Control: Researchers can explicitly configure and toggle outbound-only internet access using domain-level or static IP-address allowlisting (Access Control Lists).
- Financial Firewalls: Provides dashboard views of ongoing financial metrics paired with customizable automated multi-tiered budget alerts, including automated warning emails sent to pre-defined organizational contacts when spending thresholds are breached.
3. Administrative Portal Management (admin.mydre.org)
The Admin Portal is an isolated environment restricted exclusively to authorized Research Support members who have successfully completed onboarding. Authentications must originate from verified organizational email domains.
Workspace & Lifecycle Control
- Automated generation of fresh Workspace architectures upon authorized ticket ingestion.
- Full governance privileges to safely rename existing Workspaces, reassign the role of Accountable Member from a validated pool of verified privileged users, adjust organizational tracking metadata, and execute clean system archiving or decommissioning processes.
Automated Reporting & Log Inspection
Provides the RS team with access to detailed platform-wide telemetry streams for compliance verification:
- Workspace access logs and explicit user activity histories.
- Complete histories of VM operational cycles (Start/Stop/De-allocate).
- Real-time tracking of outbound domain access list (ACL) modifications.
- Financial usage distributions sorted by active organizational cost centers.
- System-generated Access Review tracking metrics and Entra ID sign-in logs.
User Lifecycle & Entitlement Access Reviews
- Provisioning Pipelines: Handles automated single or bulk account provisioning requests. The RS team validates pending user profiles, triggers Entra ID account generation, and issues encrypted activation invitations containing step-by-step myDRE registration parameters.
- Deprovisioning: Immediate administrative deactivation hooks and token management controls for SCIM connections.
- Access Review Governance: Enforces a multi-tiered validation cadence to eliminate entitlement creep:
┌────────────────────────────────────────────────────────────────────────┐ │ MANDATORY ACCESS REVIEW CADENCE │ ├────────────────────┬────────────────────┬──────────────────────────────┤ │ 📅 Monthly/Ad-hoc │ 📅 Quarterly │ 📅 Biannual (System Enforced)│ ├────────────────────┼────────────────────┼──────────────────────────────┤ │ Initiated by RS │ Initiated by RS │ Automated platform trigger; │ │ for high-turnover │ for standard │ forces universal validation │ │ project tracking. │ compliance audits. │ profiles across all systems. │ └────────────────────┴────────────────────┴──────────────────────────────┘
Initiating a review triggers automated notification emails to Accountables and Privileged Members containing encrypted reference links to complete pending token validations directly inside the User Portal.
4. Manual / Out-of-SLA Request Parameters
The following advanced architectural adjustments cannot be executed via self-service controls. They must be formally requested by authorized personnel through a standard support ticket:
- Provisioning independent high-speed scratch disks or auxiliary Azure Blob Storage instances.
- Bypassing outbound firewall restrictions to open unrestricted, full outbound internet pathways.