Virtual machine provisioning and directory service management

By using batch tokens to automate the creation and configuration of tenant client virtual machines, the problem of time-consuming and insecure virtual machine provisioning in existing technologies is solved, and a fast and secure virtual machine provisioning process is achieved.

CN116134795BActive Publication Date: 2025-12-02MICROSOFT TECHNOLOGY LICENSING LLC
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202180055840.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-06-28
Publication Date
2025-12-02
Estimated Expiration
2041-06-28

AI Technical Summary

Technical Problem

In cloud-based computing environments, the process of creating and setting up virtual computers for tenants is time-consuming and insecure, requiring manual operation by system administrators, which increases network traffic and security risks.

Method used

By using bulk tokens, the creation, configuration, and federated tenant client virtual machines are automated, reducing system overhead and client burden, and enabling secure access.

Benefits of technology

It enables a fast, secure, and automated provisioning process for tenant client virtual machines, reducing the workload of system administrators and network security risks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116134795B_ABST
    Figure CN116134795B_ABST
Patent Text Reader

Abstract

A computer-implemented method includes: granting a tenant administrator client machine access to a cloud-hosted tenant service federated to a directory service. Responding to a request received from the tenant administrator client machine, a bulk token for the tenant is obtained. An identifier of an authorized tenant client of the cloud-hosted tenant service is received, causing a tenant client virtual machine to be provisioned in the cloud service for the authorized tenant client according to a specified provisioning package associated with the bulk token. The tenant client virtual machine is then federated to the directory service. Upon receiving an authorized client token from the tenant client machine at the cloud-hosted tenant service, a connection to the tenant client virtual machine is provided to the tenant client machine.
Need to check novelty before this filing date? Find Prior Art

Description

Background Technology

[0001] In a cloud-based computing environment, cloud-based computing services can be provided to tenants who do not have their own computing infrastructure. All services are managed within the cloud environment, where a cloud-based directory service manages the storage of information and access for tenant users. Many users utilize personal computers and other smart devices to access the cloud environment. Users provide credentials to obtain such access granted by the directory service.

[0002] Setting up or provisioning a virtual machine for a user can be a time-consuming task because system administrators must manually create and distribute provisioning packages, which can be insecure. End users still need to perform interactive operations before the virtual machine is ready for use.

[0003] From a system perspective, such interactions are inefficient, increase the volume of network information flow, require additional access control actions, and also increase security risks. Summary of the Invention

[0004] A computer-implemented method includes: granting a tenant administrator client machine access to a cloud-hosted tenant service federated to a directory service. Responding to a request received from the tenant administrator client machine, a bulk token for the tenant is obtained. An identifier of an authorized tenant client of the cloud-hosted tenant service is received, causing a tenant client virtual machine to be provisioned in the cloud service for the authorized tenant client according to a specified provisioning package associated with the bulk token. The tenant client virtual machine is then federated to the directory service. Upon receiving the authorized tenant client token from the tenant client machine at the cloud-hosted tenant service, a connection to the tenant client virtual machine is provided to the tenant client machine. Attached Figure Description

[0005] Figure 1 This is a block diagram of a system, according to an example embodiment, for providing a first cloud service to a tenant client and a corresponding tenant client virtual machine in a second cloud service to that client.

[0006] Figure 2 This is a flowchart of a method for providing a client virtual machine to an authorized client according to an example embodiment.

[0007] Figure 3 This is a block diagram flowchart of a system for provisioning client virtual machines for multiple tenant clients, according to an example embodiment.

[0008] Figure 4 This is a sequence diagram illustrating the data flow for creating, configuring, and concatenating client virtual computers according to an example embodiment.

[0009] Figure 5 It is a block diagram of a computer system for implementing one or more example embodiments. Detailed Implementation

[0010] In the following description, reference is made to the accompanying drawings, which form a part of the description and illustrate specific embodiments that can be practiced by way of example. These embodiments have been described in sufficient detail to enable those skilled in the art to practice the invention, and it should be understood that other embodiments can be utilized and structural, logical, and electrical changes can be made without departing from the spirit or scope of the presented concepts. Therefore, the following description of exemplary embodiments is not intended to be limiting, and the scope of the invention is defined by the appended claims.

[0011] In one embodiment, the functions or algorithms described herein can be implemented in software. The software can consist of computer-executable instructions stored on a computer-readable medium or computer-readable storage device, such as one or more non-transitory memories or other types of hardware-based local or networked storage devices. Furthermore, these functions correspond to modules, which can be software, hardware, firmware, or any combination thereof. Multiple functions can be performed in one or more modules as needed; the described embodiments are merely examples. The software can execute on a digital signal processor, ASIC, microprocessor, or other type of processor operating on a computer system (such as a personal computer, server, or other computer system), thereby turning such a computer system into a specially programmed machine.

[0012] Functionality can be configured to perform operations using, for example, software, hardware, firmware, etc. For example, the phrase "configured to" can refer to the logical circuit structure of hardware elements used to implement the associated functionality. The phrase "configured to" can also refer to the logical circuit structure of hardware elements used to implement the associated functionality of firmware or software through code design. The term "module" refers to a structural element that can be implemented using any suitable hardware (e.g., processor, etc.), software (e.g., application, etc.), firmware, or any combination of hardware, software, and firmware. The term "logic" encompasses any functionality used to perform a task. For example, each operation illustrated in a flowchart corresponds to the logic used to perform that operation. Operations can be performed using software, hardware, firmware, etc. The terms "component," "system," etc., can refer to computer-related entities, hardware, and executing software, firmware, or combinations thereof. A component can be a process, object, executable code, program, function, subroutine, computer, or a combination of software and hardware running on a processor. The term "processor" can refer to a hardware component, such as the processing unit of a computer system.

[0013] Furthermore, the claimed subject matter can be implemented as a method, apparatus, or article of art using standard programming and engineering techniques that generate software, firmware, hardware, or any combination thereof to control a computing device to implement the disclosed subject matter. As used herein, the term "article of art" is intended to cover a computer program accessible from any computer-readable storage device or medium. Computer-readable storage media may include, but is not limited to, magnetic storage devices such as hard disks, floppy disks, magnetic stripes, optical disks, compact discs (CDs), digital versatile discs (DVDs), smart cards, flash memory devices, etc. Conversely, computer-readable media (i.e., non-storage media) may additionally include communication media, such as transmission media for wireless signals, etc.

[0014] Some businesses leverage fully cloud-based IT infrastructure to provide computing services to users. These businesses can be any size enterprise, organization, or group with an online identity and are referred to as tenants. Tenants can contract with cloud-based service providers to create tenant cloud services accessible to users. Provisioning virtual machines for use by a business's users may involve a manual process for each employee. Virtual machines can be provided under a secondary license and are delivered by different cloud services. Each such virtual machine is manually set up by an administrator in a time- and labor-intensive manner. This setup typically involves logging into the current virtual machine without a trusted platform, then registering with a directory service, then with the tenant, and then obtaining a configuration package.

[0015] The subject of this invention utilizes bulk tokens for system use to create and serve virtual machines for tenant clients. After the bulk token is first obtained in association with configuring a client virtual machine for a first tenant client, it can be used by the system to: automatically initiate creation, configure using a specified configuration policy, and federate additional client virtual machines to a directory service, allowing tenant client machines to easily and securely access their respective virtual machines in a trusted manner, with minimal system overhead and minimal or no burden on the client.

[0016] Figure 1 This is a block diagram of a system 100 for providing cloud services 110 to one or more client machines 115 for use by tenant clients. Client machines 115 can be used by users of a subscriber organization called a tenant. Client machines 115 can also be used by a tenant administrator, who can be a user with system administration-level access permissions to perform typical system administration functions. A tenant can have licenses to subscribe to multiple services provided by cloud services 110. Cloud services 110 can provide tenants with their own domains.

[0017] Access to cloud service 110 by client machine 115 can be granted by directory service 120. Directory service 120 provides access control for services and stored data. An example of directory service 120 is Microsoft's Azure Active Directory (AAD). Client machine 115 can provide tokens (such as user identifiers and passwords) to gain access.

[0018] In one example, client machine 115 can be used by a tenant administrator who is responsible for assisting other users with setup to access cloud service 110 (such as Azure cloud service). The tenant administrator can receive requests for client virtual machine 125, which are provided by another cloud service 130 in the cloud service domain. Cloud service 130 can utilize a second license to provide a second subscription for one or more client virtual machines 125.

[0019] To establish client virtual machine 125, a tenant administrator can provide a token to the portal via client machine 115 to gain access to cloud service 110. The tenant administrator will then request a volume token 135 via client machine 115 and also create or otherwise obtain a provisioning package 140. The volume token 135 can be obtained from directory service 120 and is a unique binary number associated with the tenant. Once the volume token and provisioning package are obtained, the tenant administrator can identify one or more tenant clients, such as users authorized under a second subscription to the virtual machine. Cloud service 110 will then use the same volume token provisioning package to automatically create and provision client virtual machines for each authorized tenant client.

[0020] Each client virtual machine will then automatically federate with directory service 120. Federation can be done through a federated domain, so that clients logging into a domain will be able to access all federated domains. Federation domains were originally introduced in Microsoft Windows 7. Once a virtual machine is ready, it is assigned to a licensed client. When a client first logs in through the portal to access its virtual machine, the virtual machine is already ready and usable.

[0021] Figure 2 This is a flowchart of method 200, which provides a client virtual machine to an authorized tenant client in an effective manner. In operation 210, method 200 begins by receiving a tenant administrator token from the tenant administrator client machine. In response to receiving the tenant administrator token, access to the cloud-hosted tenant service is granted. The cloud-hosted tenant service is federated to a directory service, which manages access to the cloud-hosted tenant service. The directory service authenticates and grants access based on the token.

[0022] In operation 220, a request for a bulk token is received from the tenant administrator client machine. In one example, the request for a bulk token is used to request a bulk token from the directory service. In operation 230, the bulk token is obtained from the directory service.

[0023] In operation 240, the identifier of the authorized tenant client of the cloud-hosted tenant service is received. The tenant administrator may provide the identifier via the client machine in response to the tenant client having licenses for the cloud-hosted tenant service and licenses for the client virtual machine.

[0024] In Operation 250, client virtual machines are provisioned in the cloud service based on a specified provisioning package associated with a volume token. Tenant administrators can select or create specified provisioning packages. The cloud service can associate volume tokens with provisioning packages or include volume tokens within provisioning packages.

[0025] In Operation 260, the client virtual machine is federated to the directory service to provide tenant clients with access to the client virtual machine when the client machine accesses the cloud-hosted tenant service. The client virtual machine can be managed within the cloud service by being federated to the directory service. Furthermore, the directory service can be used to manage access to stored information and the deployment of services.

[0026] Federationing client virtual machines to a directory service can include providing a connection between the client virtual machines and the directory service to offer directory service functionality to the client virtual machines. Such a connection allows the directory service to be used to manage the client virtual machines.

[0027] In operation 270, once the client virtual machine is federated, an authorized client token can be received from the client machine at the cloud-hosted tenant service. In one example, the authorized client token includes a user identifier and a password. The authorized client token is used to grant the client device access to the cloud-hosted tenant service, provided that the user of the client device is authorized to use the cloud-hosted tenant service. In operation 280, with the client virtual machine already federated to the directory service, the client machine is granted a connection to the client virtual machine.

[0028] In one example, a bulk token comprises a unique binary string and can be used to authorize and provision multiple client virtual machines for multiple clients of a tenant. Such provisioning can be accomplished using an already created bulk token by receiving multiple additional identifiers. Each identifier corresponds to a specific one of multiple additional authorized tenant clients of the cloud-hosted tenant service. Then, based on a specified provisioning package associated with the bulk token, multiple additional corresponding client virtual machines are provisioned in the cloud service. Each client virtual machine is subsequently federated to the directory service, allowing each client machine to easily gain access to the cloud-hosted tenant service to access its client virtual machine.

[0029] Volume tokens can be encrypted within the cloud hosting platform. While volume tokens are only shared within the cloud-based system and used to provision client virtual machines, encrypting them is helpful in situations where unauthorized access or unauthorized access attempts are unlikely. Volume tokens can also be included in the provisioning package.

[0030] Receiving the authorized tenant client token at the cloud-hosted tenant server at operation 270 and providing a connection at operation 280 are performed in response to the client being confirmed to have permission to access the cloud-hosted tenant services. In one example, the authorized tenant client may use a client machine to provide an authorized client token for a user included in the license. The client machine may be coupled to a portal that provides access to the cloud-hosted tenant services.

[0031] Figure 3 This is a detailed block diagram of system 300, used to provision client virtual machines for multiple tenant clients. In one example, the elements of system 300 may be provided by cloud-based services. System 300 is suitable for enterprises (referred to as tenants) that do not have their own IT infrastructure.

[0032] In one example, system 300 includes a cloud-hosted tenant service 310 that provides software services to tenants. The cloud-hosted tenant service 310 may include computing resources such as processors, memory, and programming to provide the services. Tenant clients 315 (such as information workers) with a subscription to the cloud-hosted tenant service 310 can utilize devices such as client machines (also indicated at 315) capable of running browsers or other software to access the tenant's web portal 320. The web portal 320 allows tenant clients with subscriptions (such as authorized users) to log in to their subscriber accounts using their devices 315. Login via the web portal 320 provides access to the services offered by the cloud-hosted tenant service 310.

[0033] System 300 may also include a cloud virtual machine service 325, which provides computing resources for generating client virtual machines 330 for each tenant client. When each client virtual machine is created and provisioned, it is federated with a directory service 335 (such as Microsoft's Azure Active Directory service). Tenant service 310 is also federated with directory service 335. The directory service can provide access control and other services (such as those provided by Azure Active Directory service). Since each cloud service can provide its own domain to tenants, federation can be done through domain federation, allowing tenant clients and tenant administrators to access each domain using a single token. In one example, the token could be a user or client ID and a password.

[0034] The above description of system 300 assumes that client virtual machine 330 has been provisioned and joined to directory service 335. Figure 3 The elements of the tenant cloud service 310 are also shown, and the operation of these elements is to assist in the initial provisioning of the client virtual machine 330 for the tenant client.

[0035] In one example, client 315 is a machine used by a tenant administrator. The tenant's tenant administrator is typically responsible for setting up computing resources for tenant clients (such as tenant employees, systems, or other authorized users). As mentioned above, each client 315 may have a subscription to the tenant cloud service 310 and issue an access token at 340 for access via portal 320.

[0036] Tenant administrators have access to a set of application services 345, which serve as a group of proxy resources that interface with directory service 335 to perform administrative tasks. In one example, application service 345 includes proxy service 350, proxy database 355 storing bulk tokens, and proxy storage 360.

[0037] A tenant administrator can request a bulk token from agent service 350 in response to the approval of a first tenant client to use client virtual machine 330. Agent service 350 can interface with directory service 335 to authenticate the tenant administrator and request the bulk token. Upon receiving the bulk token from directory service 335, the bulk token is encrypted using a key from encryption keystore 365 and stored in agent database 355. The bulk token can be a unique binary string, which, once created and provided, can be used to federate virtual machine 330 to directory service 335. A push notification is provided to event hub 368 upon receiving the bulk token. The same bulk token can also be used for attached tenant clients when creating, configuring, and federating attached client virtual machines.

[0038] Once a bulk token is created, the agent service 350 creates a provisioning package with the bulk token for the tenant. The provisioning package describes the computer resources used to create and provision the client virtual machine 330.

[0039] In response to a push notification provided to Event Hub 368, a provisioning package is provided to Provisioning Service 370. Event Hub 368 is a messaging service for Provisioning Service 370 to initiate provisioning once the bulk token is ready. Provisioning Service 370 continues to create and provision client virtual machines 330 and uses the bulk token to request Directory Service 335 to federate with client virtual machines 330. The provisioning package may also be encrypted. The provisioning package may be stored in Agent Storage 360 ​​for use in setting up additional client virtual machines for additional tenant clients.

[0040] In response to an additional client being added to a cloud virtual machine service 325 subscription, a provisioning package can be used to automatically create, provision, and federate the corresponding additional client virtual machine 330. In one example, the client virtual machine 330 can be provisioned to operate like a client's personal computer and can be considered a cloud personal computer (CPC). Provisioned services may include email, word processing software, office software, applications, and any other desired software that each tenant client can utilize when performing work for the tenant.

[0041] Once each client virtual machine is created, provisioned, and federated, tenant client machine 315 can be used to simply access the client virtual machine by providing a tenant client token via portal 320. In one example, tenant client machine 315 will be directly coupled to the client's client virtual machine 330 without any setup or provision of any additional credentials.

[0042] Figure 4 It is a sequence diagram illustrating the data flow used to create, provision, and associate client virtual computers. Figure 4 It also illustrates how easy it is for tenant client machines to access the corresponding client virtual computers. Figure 4 The top row illustrates devices that receive flowing data. These devices perform functions in response to the received data, including management interface 410, cloud hosting tenant service 412, cloud virtual machine service 414, and directory service 416. Portal 418, proxy service 420, and provisioning service 422 are also shown in cloud hosting tenant service 412. Directory service 416 includes access service 424 and federation service 426.

[0043] The data flow can begin at 432, where a tenant administrator access token is provided via portal 418 from tenant administrator client machine 430. Portal 418 then provides the access token at 434 to either access service 424 or directory service 416 to grant tenant administrator access via client machine 430 as a directory service audience to perform administrative functions. Finally, a directory service access token is granted to the audience at 436.

[0044] At 438, the tenant administrator will provide data via client machine 430 to retrieve the access token with audience granted at 440. Here, the tenant administrator is authorized at 442 to access proxy service 420 via client machine 430 by providing both the directory service access token and the access token with audience, and does so at 442 by invoking proxy service 420.

[0045] At 444, proxy service 420 retrieves a bulk token from access service 434 of directory service 416. At 446, proxy service 420 maintains the bulk token using a cryptographic ID such as a PKId and other metadata identifying the tenant. The created state is provided to portal 418 at 448, where it is visible to the tenant administrator via client 430. As indicated by shell 450, the aforementioned data flow thus creates a tenant-specific bulk token, which can be used to begin provisioning client virtual machines.

[0046] Once a bulk token is created, the tenant administrator can begin the process of identifying clients licensed to use the client virtual machine at 454 via client machine 452 and initiate the provisioning of such client virtual machines. At this point, the tenant administrator identifies the first tenant client and other clients licensed to use the cloud-hosted tenant service 412 at 455 via client machine 452 using the management interface 410.

[0047] At 456, the provisioning service 422 is notified of the identifier of the licensed client. Notification 456 may take the form of a policy change. At 458, the proxy service 420 sends a request to obtain the provisioning package for the client virtual machine. As described above, the provisioning package includes an identifier for the compute resource. The provisioning package is retrieved for the proxy service 420 at 458.

[0048] Agent service 420 adds a bulk token to the provisioning package and returns the provisioning package with the bulk token to provisioning service 422 at 460. Then, at 462, provisioning service 422 continues to provision the client virtual machine.

[0049] The data flow for federating the client virtual machine is outlined in shell 463. Once provisioned, the client virtual machine provides a bulk token to access service 424 of directory service 416 at 464. In return, access tokens for federation service 426 are provided at 466. Then, client virtual machine 414 provides access tokens for federation to federation service 426, which continues at 470 by providing device directory service certificates to client virtual machine 414 to federate client virtual machine directory service 416. This is then ready for use by the first tenant client. At 472, the metadata transmitted to the client virtual machine required for federation is removed.

[0050] The first tenant client's access via client device 478 is instantiated within shell 480, and begins at 482 when the first tenant client provides login credentials via client device 476 in the form of a tenant client access token using portal 418. Portal 418 provides connection 484 to client virtual machine 414. Connection 418 can be established without any further setup by the tenant administrator or tenant client machine 478. While creating, provisioning, and federating client virtual machines for the first tenant client involves obtaining a bulk token and adding it to a provisioning package, the addition of other tenant clients and their corresponding client virtual machines can occur automatically when the tenant administrator identifies other tenant clients at 455.

[0051] Figure 5 This is a block diagram of a computer system 500, which serves as a device and cloud computing resource for the provisioning and federation of virtual computers for service delivery and client applications. System 500 can also be used to execute methods and algorithms according to the described examples. Not all components are required in the various embodiments.

[0052] An example computing device in the form of a computer 500 may include a processing unit 502, a memory 503, removable storage 510, and non-removable storage 512. Although the example computing device is illustrated and described as computer 500, the computing device may take different forms in different embodiments. For example, the computing device may alternatively be a smartphone, tablet, smartwatch, smart storage device (SSD), or include... Figure 5 Other computing devices with the same or similar elements shown and described. Devices such as smartphones, tablets, and smartwatches are generally referred to as mobile devices or user equipment.

[0053] While various data storage elements are exemplified as part of computer 500, this storage may also, or alternatively, include cloud-based storage accessible via a network, such as Internet-based or server-based storage. It should also be noted that the SSD may include a processor on which a parser can run, thereby allowing parsed, filtered data to be transferred via the I / O channel between the SSD and main memory.

[0054] Memory 503 may include volatile memory 514 and non-volatile memory 508. Computer 500 may include various computer-readable media or a computing environment that can access various computer-readable media, such as volatile memory 514 and non-volatile memory 508, removable storage 510, and non-removable storage 512. Computer storage includes random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM) or electrically erasable programmable read-only memory (EEPROM), flash memory or other storage technologies, optical disc read-only memory (CD ROM), digital versatile disk (DVD) or other optical disc storage, cassette tape, magnetic tape, disk storage or other magnetic storage devices, or any other medium capable of storing computer-readable instructions.

[0055] Computer 500 may include or have access to a computing environment including input interface 506, output interface 504, and communication interface 516. Output interface 504 may include a display device, such as a touchscreen, which can also be used as an input device. Input interface 506 may include one or more of the following: touchscreen, touchpad, mouse, keyboard, camera, one or more device-specific buttons, one or more sensors integrated into computer 500 or coupled to computer 500 via a wired or wireless data connection, and other input devices. The computer can operate in a networked environment using a communication connection to connect to one or more remote computers, such as a database server. Remote computers may include personal computers (PCs), servers, routers, network PCs, peer-to-peer devices, or other public data stream network switches. Communication connections may include local area networks (LANs), wide area networks (WANs), cellular networks, Wi-Fi, Bluetooth, or other networks. According to one embodiment, various components of computer 500 are connected to system bus 520.

[0056] Computer-readable instructions stored on a computer-readable medium can be executed by a processing unit 502 of computer 500 (such as program 518). In some embodiments, program 518 includes software for implementing one or more methods described herein. Hard disk drives, CD-ROMs, and RAM are some examples of articles that include non-transitory computer-readable media such as storage devices. The terms computer-readable medium, machine-readable medium, and storage device do not include carrier waves or signals because carrier waves and signals are considered too transient. Storage may also include network storage, such as storage area networks (SANs). Computer program 518, together with workspace manager 522, can be used to cause processing unit 502 to execute one or more methods or algorithms described herein.

[0057] Example:

[0058] 1. A computer-implemented method comprising: granting a tenant administrator client machine access to a cloud-hosted tenant service federated to a directory service; receiving a request for a bulk token from the tenant administrator client machine; obtaining the bulk token from the directory service; receiving an identifier of an authorized tenant client of the cloud-hosted tenant service; provisioning a tenant client virtual machine in a cloud service for the authorized tenant client according to a specified provisioning package associated with the bulk token; and federating the tenant client virtual machine to the directory service. The bulk token can be used to automatically initiate creation, configure using a specified configuration policy, and federate additional guest virtual machines to a directory service to allow clients easy access to their respective virtual machines with minimal management overhead and minimal burden on the client.

[0059] 2. The method as described in Example 1, further comprising: receiving an authorized tenant client token from the tenant client machine at the cloud-hosted tenant service; and granting the tenant client machine a connection to the client virtual machine.

[0060] 3. The method as described in Example 2, wherein the tenant client token includes the identifier and password.

[0061] 4. The method as described in any one of Examples 1-3, wherein the tenant client virtual machine is managed within the cloud service.

[0062] 5. The method as described in any one of Examples 1-4, wherein the directory service is based on tokens for authentication and authorization of access.

[0063] 6. The method as described in any one of Examples 1-5, wherein the bulk token comprises a unique binary string.

[0064] 7. The method as described in any one of Examples 1-6, further comprising: receiving a plurality of additional identifiers, each identifier corresponding to a corresponding one of a plurality of additional authorized tenant clients of the cloud-hosted tenant service; provisioning a plurality of additional corresponding tenant client virtual machines in the cloud service according to a specified provisioning package associated with the bulk token; and federating the tenant client virtual machines to the directory service.

[0065] 8. The method as described in any one of Examples 1-7, wherein the bulk token is encrypted within the cloud hosting platform.

[0066] 9. The method as described in any one of Examples 1-8, wherein the provisioning package includes the bulk token.

[0067] 10. The method as described in any one of Examples 1-9, wherein the identifier of the authorized tenant client receiving the cloud-hosted tenant service is executed in response to the tenant client being confirmed to have permission for the service in the specified provisioning package.

[0068] 11. The method as described in Example 10, wherein the authorized tenant client includes a device that provides the authorized tenant client token for a user included in the license.

[0069] 12. The method as described in Example 11, wherein the device is coupled to a portal that provides access to the cloud-hosted tenant services.

[0070] 13. The method of any one of Examples 1-12, wherein associating the tenant client virtual machine with the directory service includes providing a connection between the client virtual machine and the directory service to provide directory service functionality to the tenant client virtual machine.

[0071] 14. A machine-readable storage device has instructions for execution by a processor of a machine to cause the processor to perform operations to execute a method. These operations include: granting a tenant administrator client machine access to a cloud-hosted tenant service federated to a directory service; receiving a request for a bulk token from the tenant administrator client machine; obtaining the bulk token from the directory service; receiving an identifier of an authorized tenant client of the cloud-hosted tenant service; provisioning a tenant client virtual machine in a cloud service for the authorized tenant client according to a specified provisioning package associated with the bulk token; and federating the tenant client virtual machine to the directory service.

[0072] 15. The device as described in Example 14, wherein the operation further comprises: receiving an authorized tenant client token from a tenant client machine at the cloud-hosted tenant service; and granting a connection to the client virtual machine to the tenant client machine.

[0073] 16. The device as described in any one of Examples 14-15, wherein the directory service authenticates and grants access based on a token, wherein the directory service manages the storage of information and the deployment of services, and wherein the bulk token comprises a unique binary string.

[0074] 17. The device as described in any one of Examples 14-16, wherein the operation further comprises: receiving a plurality of additional identifiers, each identifier corresponding to a corresponding one of a plurality of additional authorized tenant clients of the cloud-hosted tenant service; provisioning a plurality of additional corresponding tenant client virtual machines in the cloud service according to a specified provisioning package associated with the bulk token; and federating the tenant client virtual machines to the directory service.

[0075] 18. The device as described in any one of Examples 14-17, wherein the provisioning package includes the bulk token; wherein the identifier of the authorized tenant client receiving the cloud-hosted tenant service is executed in response to the tenant client being confirmed to have permission to the services in the specified provisioning package; wherein the authorized tenant client includes a device that provides the authorized tenant client token of the user included in the permission; and wherein the device is coupled to a portal that provides access to the cloud-hosted tenant service.

[0076] 19. The device as described in any one of Examples 14-18, wherein associating the tenant client virtual machine with the directory service includes providing a connection between the client virtual machine and the directory service to provide directory service functionality to the tenant client virtual machine.

[0077] 20. An apparatus comprising: a processor and a memory device coupled to the processor and having a program stored thereon for performing operations when executed by the processor. These operations include: granting a tenant administrator client machine access to a cloud-hosted tenant service federated to a directory service; receiving a request for a bulk token from the tenant administrator client machine; obtaining the bulk token from the directory service; receiving an identifier of an authorized tenant client of the cloud-hosted tenant service; provisioning a tenant client virtual machine in a cloud service for the authorized tenant client according to a specified provisioning package associated with the bulk token; and federating the tenant client virtual machine to the directory service.

[0078] While several embodiments have been described in detail above, other modifications are possible. For example, the logic flow described in the figures does not require the desired result to be achieved in the specific order or sequence shown. Other steps may be provided from the described flow, or steps may be eliminated, and other components may be added to or removed from the described system. Other embodiments are within the scope of the following claims.

Claims

1. A computer implementation method, comprising: Grant tenant administrator client machines access to cloud-hosted tenant services federated to the directory service; The cloud-hosted tenant service receives a request for a bulk token, the request being received from the tenant administrator client machine. In response to the request, obtain the bulk token from the directory service; Obtain the identifier of the authorized tenant client of the cloud-hosted tenant service from the cloud-hosted tenant service; In response to obtaining the identifier of the authorized tenant client, a tenant client virtual machine is provisioned for the authorized tenant client in the cloud service according to the specified provisioning package associated with the bulk token; and In response to the provisioning, the tenant client virtual machine is federated to the directory service.

2. The method as described in claim 1, characterized in that, Further includes: The authorized tenant client token is received from the tenant client machine at the cloud-hosted tenant service. as well as Grant the tenant client machine a connection to the client virtual machine.

3. The method as described in claim 2, characterized in that, The tenant client token includes the identifier and password.

4. The method as described in claim 1, characterized in that, The tenant client virtual machine is managed within the cloud service.

5. The method as described in claim 1, characterized in that, The directory service uses tokens for authentication and authorization of access.

6. The method as described in claim 1, characterized in that, The bulk token consists of a unique binary string.

7. The method as described in claim 1, characterized in that, Further includes: Receive multiple additional identifiers, each identifier corresponding to one of multiple additional authorized tenant clients of the cloud-hosted tenant service; Based on the specified provisioning package associated with the bulk token, provision multiple additional corresponding tenant client virtual machines in the cloud service; and The tenant client virtual machine is fed into the directory service.

8. The method as described in claim 1, characterized in that, The bulk token is encrypted within the cloud-hosted tenant service.

9. The method as described in claim 1, characterized in that, The provisioning package includes the bulk token.

10. The method as described in claim 1, characterized in that, The identifier of the authorized tenant client receiving the cloud-hosted tenant service is executed in response to the tenant client being confirmed to have permission for the service in the specified provisioning package.

11. The method as described in claim 10, characterized in that, The authorized tenant client includes a device that provides the authorized tenant client token for the user included in the license.

12. The method as described in claim 11, characterized in that, The device is coupled to a portal that provides access to the cloud-hosted tenant's services.

13. The method as described in claim 1, characterized in that, Federation of the tenant client virtual machine to the directory service includes providing a connection between the client virtual machine and the directory service to provide directory service functionality to the tenant client virtual machine.

14. A machine-readable storage device having instructions for execution by a processor of a machine to cause the processor to perform operations to execute any one of the methods of claims 1-13, the operations comprising: Grant tenant administrator client machines access to cloud-hosted tenant services federated to the directory service; The cloud-hosted tenant service receives a request for a bulk token, the request being received from the tenant administrator client machine. In response to the request, obtain the bulk token from the directory service; Obtain the identifier of the authorized tenant client of the cloud-hosted tenant service from the cloud-hosted tenant service; In response to obtaining the identifier of the authorized tenant client, a tenant client virtual machine is provisioned for the authorized tenant client in the cloud service according to the specified provisioning package associated with the bulk token; and In response to the provisioning, the tenant client virtual machine is federated to the directory service.

15. The device as claimed in claim 14, characterized in that, The operation further includes: Receive authorized tenant client tokens at the cloud-hosted tenant service; and Grant the authorized tenant client a connection to the client virtual machine.

16. The device as claimed in claim 14, characterized in that, The directory service uses tokens to authenticate and grant access, and the directory service manages the storage of information and the deployment of services, wherein the bulk token includes a unique binary string.

17. The device as claimed in claim 14, characterized in that, The operation further includes: Receive multiple additional identifiers, each identifier corresponding to one of multiple additional authorized tenant clients of the cloud-hosted tenant service; Based on the specified provisioning package associated with the bulk token, provision multiple additional corresponding tenant client virtual machines in the cloud service; and The tenant client virtual machine is fed into the directory service.

18. The device as claimed in claim 14, characterized in that, The provisioning package includes the bulk token; wherein the identifier of the authorized tenant client receiving the cloud-hosted tenant service is executed in response to the tenant client being confirmed to have permission for the services in the specified provisioning package; The authorized tenant client includes a device that provides the authorized tenant client token for the user included in the license; and the device is coupled to a portal that provides access to the cloud-hosted tenant service.

19. The device as claimed in claim 14, characterized in that, Federation of the tenant client virtual machine to the directory service includes providing a connection between the client virtual machine and the directory service to provide directory service functionality to the tenant client virtual machine.

20. An apparatus comprising: processor; as well as A memory device coupled to the processor and having a program stored thereon to perform the following operations when executed by the processor: Grant tenant administrator client machines access to cloud-hosted tenant services federated to the directory service; The cloud-hosted tenant service receives a request for a bulk token, the request being received from the tenant administrator client machine. In response to the request, obtain the bulk token from the directory service; Obtain the identifier of the authorized tenant client of the cloud-hosted tenant service from the cloud-hosted tenant service; In response to obtaining the identifier of the authorized tenant client, a tenant client virtual machine is provisioned for the authorized tenant client in the cloud service according to the specified provisioning package associated with the bulk token; and In response to the provisioning, the tenant client virtual machine is federated to the directory service.

Citation Information

Patent Citations

  • Bulk Joining Of Computing Devices To An Identity Service

    US20180034817A1