Onboarding myDRE Subscriptions for the First Time
Overview
myDRE requires at least two Microsoft Azure subscriptions from your organization (the Tenant) to deploy workspaces and related resources. This process is a collaborative effort between your organization and anDREa B.V. To maintain a consistent security baseline, anDREa manages these resources using its own directory: anDREa B.V. Entra ID.
Phase 1: Preparation & Subscription Requirements
Before starting, ensure your Azure subscriptions meet the following strict criteria. You can create these yourself in the Microsoft Azure portal or request them through your Cloud Solution Provider (CSP).
1. Allowed Subscription Types
Subscriptions must be one of the following types:
- EA (Enterprise Agreement)
- MCA (Microsoft Customer Agreement)
- PAYG (Pay-As-You-Go)
Critical Restriction: Free tier subscriptions (like the Microsoft Partner Network) are not supported. The following specific subscription types are strictly disallowed:
- MS-AZR-0015P, MS-AZR-0144P, MS-AZR-0145P, MS-AZR-0146P, MS-AZR-0159P
2. Required Naming Convention
You must name your two subscriptions using the following formats (replace [XYZ] with your specific organizational acronym):
ANDREA-Shared-[XYZ]-0001ANDREA-Workspaces-[XYZ]-0001
Phase 2: Step-by-Step Onboarding Process
Step 1: Invite the Subscription Owner to the anDREa Entra ID
- Identify Owners: Choose the user(s) who will own the Azure subscriptions. Best Practice: Assign at least two (2) owners for redundancy.
- Share Details: Send the owner identity details to anDREa.
- Accept Invitation: anDREa will invite the owner(s) as Guest users to the anDREa B.V. directory. The owners must check their email and accept the invitation before proceeding to the next steps.
Step 2: Assign anDREa Permissions in Azure
For each of the two newly created subscriptions, perform the following actions in the Microsoft Azure Portal:
- Navigate to the subscription and select Access control (IAM) from the left-hand menu.
- Click Add -> Add role assignment.
- Select the Owner role (this grants the highest privileges required for deployment) and click Next.
- Under members, choose Select members and search for:
licenseadmin@mydre.org - Select the user, click Review + assign, and then Save.
Step 3: Change the Subscription Directory
Still within the Azure Portal for each subscription:
- Look at the top banner of the subscription overview page and click the Change directory button.
- In the To dropdown pane that appears, select the anDREa B.V. directory.
- Check the confirmation box acknowledging the impact of the directory change.
- Click the Change button.
💡 If you cannot see the anDREa B.V. directory in the dropdown list, ensure you have successfully accepted the Guest invitation sent in Step 1.
Next Steps
Once the directory change is complete for both subscriptions, notify support.mydre.org immediately. The anDREa team will then take over to finalize the onboarding and deployment process.