Home Support Documentation Privacy Terms Licenses

Overview

Introduction How it works

Get started

Prerequisites Marketplace install Entra prerequisites Admin authorization Setup wizard Hostname & TLS

Operate

Daily operations Updates & plans Restricted networks

Troubleshoot

Recover admin access

Legal

Open source notices

Support

Get help

Marketplace install

Last updated: 20 September 2026

Goal: Deploy the Sandman appliance VM with a secure network posture.

  1. Find Sandman in the Azure Marketplace and click Create.
  2. Select your plan: Startup, Scaleup, or Corporate (see plan limits).
  3. Complete VM details — resource group, region, VM size, and SSH public key.
  4. Enter CIDR ranges allowed to reach the HTTPS dashboard (port 443) and, separately, SSH (port 22). Keep these lists as narrow as practical.
  5. Click Create and wait for the deployment to finish.
Azure Marketplace Create blade for Sandman — plan selection, networking allowlists, and SSH key.
Figure 1. Azure Marketplace — create the Sandman appliance and configure inbound allowlists.

Verify: The deployment succeeds, the VM has a public IP (or your chosen access path), and the NSG allows HTTPS from your admin network.

For IT admins: what the template deploys
  • One VM on Azure Linux 3 (ARM64) with deny-by-default NSG: HTTPS 443 from allowed ranges, SSH 22 from admin ranges only.
  • A separate data disk for the database and application state — survives VM replacement and plan upgrades.
  • A system-assigned managed identity with Virtual Machine Contributor at subscription scope.
  • Port 8091 (setup wizard) is denied unless you explicitly allow it during setup or maintenance.

© 2026 Sandman