Tenantless Access Orchestration for Consumer Cloud Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional cloud access management systems are not designed to effectively support consumer user remote client devices without tenant information, leading to inefficiencies and usability issues in consumer contexts.

Innovation Solution

Implementing a tenantless access orchestration engine that allows remote client devices to operate on a cloud platform without a tenant association, using a bootstrap token and secure channel for identity management, enabling seamless access and provisioning in a consumer context.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If conventional cloud access management systems are used, then tenant-based access control is maintained, but consumer user remote client devices without tenant information cannot be effectively supported

Engineering Contradiction:
Improvesupport for consumer context devicesVSAvoidsystem architecture complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces a tenantless access orchestration engine as an intermediary component between remote client devices and the identity provider. This engine handles device registration, token generation, and certificate issuance for consumer context devices without tenant associations, thereby extending system adaptability without fundamentally altering the core tenant-based architecture.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the access management system into two distinct pathways: tenant-based access for business contexts and tenantless access for consumer contexts. This segmentation allows each pathway to be optimized independently, with the tenantless pathway handling consumer devices through simplified registration and token-based authentication, while maintaining the existing tenant-based infrastructure for organizational users.

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If tenant information is required for device registration, then security control is maintained, but consumer user devices cannot join the cloud platform

Engineering Contradiction:
Improvedevice join processVSAvoidsecurity control
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements preliminary action by having the tenantless access orchestration engine pre-generate authentication tokens and certificates for consumer devices during the device registration phase. This preliminary provisioning of security credentials enables devices to join the platform without tenant information while maintaining security controls through token-based authentication and certificate verification mechanisms.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent changes the authentication parameters for consumer context devices by transitioning from tenant-based authentication (requiring organizational credentials) to device-based authentication (using generated tokens and certificates). This parameter change allows consumer devices to establish secure connections with the cloud platform using device-specific credentials rather than tenant associations.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS20250238493A1Tenantless access orchestration engine in a cloud access management system
Publication Date: 2025.07.24 MICROSOFT TECHNOLOGY LICENSING LLC
  • US20250238493A1 patent drawing
  • US20250238493A1 patent drawing
  • US20250238493A1 patent drawing

AI summary

Methods, systems, and computer storage media for providing cloud access management using a tenantless access orchestration engine. Cloud access management supports tenantless access orchestration operations that allow users to use remote client devices in a consumer context. In particular, a remote client device can have an identity to operate on a cloud platform without having a tenant instance associated with the remote client device. In operation, a request is communicated to an identity provider to create identity provider data for a remote client device of a cloud platform. Based on communicating the request, a bootstrap token containing a remote client identifier is received. The remote client device is provisioned based on creating a set of cloud resources for the remote client device and installing the bootstrap token onto a virtual machine associated with the remote client device. The virtual machine is associated with a cloud-provider-managed environment of the cloud platform.