Encryption Service Deployment on Azure for Group Provisioning

Introduction

This article explains how to set up Group Provisioning in the NordPass Admin Panel step by step. Group Provisioning allows NordPass to synchronize groups securely by using an encryption service that preserves the zero-knowledge architecture.

 

Before you start:

  • The User Provisioning must already be enabled.
  • You should have a valid Azure subscription with billing and a resource container.

 

Here's what to do

  1. Log in to the NordPass Admin Panel.
  2. Select "Integrations" > "Microsoft Entra ID or Okta".
    If you haven’t set up User Provisioning yet, follow the User Provisioning guide first and then return to these steps.
  3. Select "Create Configuration" under the Group provisioning tab.
  4. You will receive a configuration file. Save it for later.
  5. Log in to Microsoft Azure.
  6. Find the "Deploy Custom Template" page and select "Build your own template in the editor".
  7. In the template editor, insert the configuration script you received from the NordPass Admin Panel in step 4, then select "Save".
  8. In the "Basics" tab, select an existing "Resource group" or create a new one, then select "Next".
  9. Wait for the system to validate the deployment. This may take some time. Once validation is complete, select "Create".
  10. You will be redirected to the deployment page. Wait until the deployment process completes. The progress appears under "Revision".
  11. When you see the notification "Deployment succeeded", select "Go to resource group".
  12. Confirm that the deployment status is "Succeeded".
     

How to verify the provisioning status

  1. Go to the "Resource group" where you created the deployment.
  2. Open "nordpass-eec-container".
  3. Select "Revisions".
  4. Check the status. If provisioning is running successfully, the status will show "Provisioned" and "Running".

 

Additional tips

  • Always confirm that the deployment status shows "Succeeded" before proceeding to verification.
  • Save the configuration file securely in case you need to redeploy later.

Was this article helpful?