Skip to content
English
  • There are no suggestions because the search field is empty.

How to deploy CAEVES in Hybrid Cloud?

In this article, we will show you how to deploy a CAEVES instance in an on-premises environment using the Hybrid Cloud deployment.

CAEVES Hybrid Cloud deployment requires a Service Principal (SPN) in the customer's Microsoft Entra ID tenant.

The SPN provides the application identity used by the CAEVES Hybrid Environment deployment to authenticate to the customer's Azure environment.

Before starting the CAEVES Hybrid Environment deployment, the required App Registration, Service Principal, and Client Secret must be created.

This article provides the following methods for creating the required application identity:

Method 1: Create the App Registration through the Azure Portal
Method 2: Create the App Registration using PowerShell and Bash scripts

Prerequisites  

Before starting the CAEVES Hybrid Cloud deployment, ensure the following are available:  

  • Access to the customer's Azure subscription and Microsoft Entra ID tenant.
  • Permission to create App Registrations and application credentials.
  • An Azure account with Application Administrator, Cloud Application Administrator, or equivalent permissions.
  • Azure CLI installed if using the Bash or PowerShell scripts.

           Required SPN 

           A Service Principal (SPN) is a prerequisite for the CAEVES Hybrid Cloud deployment.  
           The following information must be available before starting the deployment:  

           Parameter   Description 
           Tenant ID   Microsoft Entra Directory/Tenant ID 
           Client ID   Application (client) ID of the App Registration 
           Client Secret   Secret associated with the App Registration 
           Secret Expiry   Expiration date of the Client Secret 

          When an application is registered in Microsoft Entra ID, a corresponding service principal is created in the tenant. The service principal represents the application identity in that tenant. 

          Method 1: Create the App Registration through the Azure Portal

          Step 1: Open App Registrations  

          1. Sign in to the Azure Portal.
          2. Navigate to Microsoft Entra ID.
          3. Select App registrations.
          4. Select New registration.
            Screenshot 2026-05-19 at 10-45-30-png

          Step 2: Configure the App Registration  

          Enter the following details:

          Name: e.g., CAEVES-Hybrid-Environment
          Supported account types: Default (Single tenant)
          Redirect URI: Leave blank unless required 

          Click Register.

          Step 3: Record the Application IDs  

           After the App Registration is created, open the Overview page and record the following values:  

          • Application (client) ID
          • Directory (tenant) ID

               These values are required during the CAEVES Hybrid Environment deployment. Screenshot 2026-05-19 at 10-46-13-png

              Step 4: Create the Client Secret  

              In the App Registration:

              1. Go to Certificates & secrets
              2. Select Client secrets
              3. Select New client secret

                    Enter the following:
                    Description: e.g., CAEVES-Hybrid-Environment
                    Expiration: 24 months  
                        Screenshot 2026-05-19 at 10.46.53

                    Click Add.

                    Important:  The Client Secret value is displayed only when the secret is created. Make sure to copy and securely store the value before leaving the page.  

                    Step 5: Verify the App Registration and SPN  

                    Verify that the App Registration and its associated Service Principal are present in the customer's Microsoft Entra ID tenant.  

                    The following information should now be available:  

                    Tenant ID
                    Client ID
                    Client Secret
                    Client Secret expiry date

                    Screenshot 2026-05-19 at 10.47.06

                    Method 2: Create the App Registration using PowerShell and Bash scripts

                    The App Registration, Service Principal, and Client Secret can also be created automatically using the provided Bash or PowerShell script.  

                    Both scripts perform the same operation.  

                    1. Create an App Registration.
                    2. Create a Service Principal for the App Registration.
                    3. Create a Client Secret with a two-year expiration.
                    4. Display the Tenant ID, Client ID, and Client Secret.

                    Note: Use either the Bash script or the PowerShell script.  

                    Using Bash  

                    Prerequisites  

                    Before running the Bash script:

                    1. Install Azure CLI.
                    2. Sign in to the customer's Azure tenant:     az login
                    3. Verify the active Azure account and tenant:    az account show
                    4. Ensure your account has the required Microsoft Entra permissions.

                        Bash Script  

                          Save the following script as:    Register-CaevesHybridApp.sh

                          #!/usr/bin/env bash
                          #
                          # Register-CaevesHybridApp.sh
                          #
                          # Registers an Azure AD application in YOUR tenant and creates a client secret
                          # (valid for 2 years) so the CAEVES Hybrid Environment deployment can
                          # authenticate as this application. Run this in Azure Cloud Shell (or any
                          # shell with the Azure CLI installed and "az login" already done) BEFORE
                          # filling out the CAEVES Hybrid Environment Marketplace deployment wizard.
                          #
                          # Prerequisites:
                          #   - You must be signed in to the Azure CLI ("az login") against the tenant
                          #     where the Hybrid Environment will be deployed.
                          #   - Your account needs the "Application Administrator" (or higher, e.g.
                          #     "Cloud Application Administrator" / Global Administrator) Azure AD
                          #     role in that tenant to create app registrations and credentials.
                          #
                          # What this script does:
                          #   1. Creates an Azure AD app registration.
                          #   2. Creates a service principal for that app registration.
                          #   3. Creates a client secret on the app registration with a 2-year expiry.
                          #   4. Prints the Tenant ID, Client ID, and Client Secret for you to copy
                          #      into the CAEVES Hybrid Environment deployment wizard.
                          #
                          # This script does NOT assign any Azure RBAC roles or Microsoft Graph API
                          # permissions to the application - it only creates the identity and secret.

                          set -euo pipefail

                          APP_DISPLAY_NAME="${1:-CAEVES-Hybrid-Environment}"

                          echo "Checking Azure CLI login..."
                          TENANT_ID="$(az account show --query tenantId -o tsv)"
                          echo "Using tenant: ${TENANT_ID}"

                          echo "Creating app registration '${APP_DISPLAY_NAME}'..."
                          CLIENT_ID="$(az ad app create --display-name "${APP_DISPLAY_NAME}" --query appId -o tsv)"
                          echo "Created app registration with Client ID: ${CLIENT_ID}"

                          echo "Creating service principal for the app registration..."
                          az ad sp create --id "${CLIENT_ID}" >/dev/null

                          echo "Creating client secret (expires in 2 years)..."
                          SECRET_END_DATE="$(date -u -d '+2 years' +%Y-%m-%dT%H:%M:%SZ)"
                          CLIENT_SECRET="$(az ad app credential reset \
                            --id "${CLIENT_ID}" \
                            --append \
                            --end-date "${SECRET_END_DATE}" \
                            --query password -o tsv)"

                          echo ""
                          echo "=================================================================="
                          echo " Registration complete. Copy these values into the CAEVES Hybrid"
                          echo " Environment deployment wizard. The Client Secret is shown only"
                          echo " once - it cannot be retrieved again after you close this shell."
                          echo "=================================================================="
                          echo " Tenant ID:      ${TENANT_ID}"
                          echo " Client ID:       ${CLIENT_ID}"
                          echo " Client Secret:   ${CLIENT_SECRET}"
                          echo "=================================================================="

                          Run the Bash Script:

                          ./Register-CaevesHybridApp.sh

                          The script displays:

                          Tenant ID
                          Client ID
                          Client Secret

                          Important: The Client Secret is displayed only once. Copy and securely store it immediately.


                          Using PowerShell  

                          The PowerShell script performs the same operation as the Bash script.  

                          Prerequisites  

                          Before running the PowerShell script:

                          1. Install Azure CLI.
                          2. Open PowerShell.
                          3. Sign in to the customer's Azure tenant: az login
                          4. Verify the active Azure account and tenant: az account show
                          5. Ensure your account has the required Microsoft Entra permissions.

                          PowerShell Script  

                          Save the following script as: Register-CaevesHybridApp.ps1

                          # Register-CaevesHybridApp.ps1
                          #
                          # Registers an Azure AD application in YOUR tenant and creates a client secret
                          # (valid for 2 years) so the CAEVES Hybrid Environment deployment can
                          # authenticate as this application. Run this in Azure Cloud Shell, PowerShell
                          # mode (or any PowerShell session with the Azure CLI installed and "az login"
                          # already done) BEFORE filling out the CAEVES Hybrid Environment Marketplace
                          # deployment wizard.
                          #
                          # This is a PowerShell equivalent of Register-CaevesHybridApp.sh - same Azure
                          # CLI commands, same result. Use whichever shell you have available.
                          #
                          # Prerequisites:
                          #   - You must be signed in to the Azure CLI ("az login") against the tenant
                          #     where the Hybrid Environment will be deployed.
                          #   - Your account needs the "Application Administrator" (or higher, e.g.
                          #     "Cloud Application Administrator" / Global Administrator) Azure AD
                          #     role in that tenant to create app registrations and credentials.
                          #
                          # What this script does:
                          #   1. Creates an Azure AD app registration.
                          #   2. Creates a service principal for that app registration.
                          #   3. Creates a client secret on the app registration with a 2-year expiry.
                          #   4. Prints the Tenant ID, Client ID, and Client Secret for you to copy
                          #      into the CAEVES Hybrid Environment deployment wizard.
                          #
                          # This script does NOT assign any Azure RBAC roles or Microsoft Graph API
                          # permissions to the application - it only creates the identity and secret.

                          param(
                              [string]$AppDisplayName = "CAEVES-Hybrid-Environment"
                          )

                          $ErrorActionPreference = "Stop"

                          function Invoke-AzCli {
                              param([string]$Description)
                              if ($LASTEXITCODE -ne 0) {
                                  throw "Failed: $Description (az exited with code $LASTEXITCODE)"
                              }
                          }

                          Write-Host "Checking Azure CLI login..."
                          $TenantId = az account show --query tenantId -o tsv
                          Invoke-AzCli "az account show"
                          Write-Host "Using tenant: $TenantId"

                          Write-Host "Creating app registration '$AppDisplayName'..."
                          $ClientId = az ad app create --display-name $AppDisplayName --query appId -o tsv
                          Invoke-AzCli "az ad app create"
                          Write-Host "Created app registration with Client ID: $ClientId"

                          Write-Host "Creating service principal for the app registration..."
                          az ad sp create --id $ClientId | Out-Null
                          Invoke-AzCli "az ad sp create"

                          Write-Host "Creating client secret (expires in 2 years)..."
                          $SecretEndDate = (Get-Date).ToUniversalTime().AddYears(2).ToString("yyyy-MM-ddTHH:mm:ssZ")
                          $ClientSecret = az ad app credential reset `
                              --id $ClientId `
                              --append `
                              --end-date $SecretEndDate `
                              --query password -o tsv
                          Invoke-AzCli "az ad app credential reset"

                          Write-Host ""
                          Write-Host "=================================================================="
                          Write-Host " Registration complete. Copy these values into the CAEVES Hybrid"
                          Write-Host " Environment deployment wizard. The Client Secret is shown only"
                          Write-Host " once - it cannot be retrieved again after you close this shell."
                          Write-Host "=================================================================="
                          Write-Host " Tenant ID:      $TenantId"
                          Write-Host " Client ID:       $ClientId"
                          Write-Host " Client Secret:   $ClientSecret"
                          Write-Host "=================================================================="

                          Run the PowerShell Script:

                          .\Register-CaevesHybridApp.ps1

                          The script displays:

                          Tenant ID
                          Client ID
                          Client Secret

                          Important: The Client Secret is displayed only once. Copy and securely store it immediately.  

                          Note: The Bash and PowerShell scripts create the App Registration, Service Principal, and Client Secret automatically. When using the Azure Portal, the App Registration and Client Secret are created manually.