Home Support Documentation Privacy Terms Licenses

Overview

Introduction How it works

Get started

Prerequisites Marketplace install Entra prerequisites Admin authorization Setup wizard Hostname & TLS

Operate

Daily operations Updates & plans Restricted networks

Troubleshoot

Recover admin access

Legal

Open source notices

Support

Get help

Prerequisites

Last updated: 20 September 2026

Goal: Confirm your organization can deploy and configure Sandman before starting the Marketplace install.

You will need:

  • An Azure subscription where your VMs live, with permission to create a VM and assign network rules.
  • A Microsoft Entra ID app registration for user sign-in.
  • An SSH public key for the appliance VM (password login is disabled). Day-to-day administration can be done from the Azure Portal — see Recover admin access.

Network requirements

DirectionPort / endpointRequiredNotes
Inbound443 (HTTPS)YesDashboard and API from your allowlisted CIDR ranges
Inbound22 (SSH)RecommendedAdmin CIDR ranges only; break-glass access
Inbound8091Setup / maintenance onlySetup wizard; deny by default in the template
OutboundAzure Resource ManagerYesStart, stop, and discover VMs
OutboundMicrosoft Entra ID / GraphYesSign-in and directory sync
OutboundLet’s EncryptOptionalAutomatic TLS; upload a certificate if blocked
OutboundTeams Logic App URLOptionalShift-end notifications

Expected result: Your Azure admin can create the VM, reach HTTPS on port 443 from approved networks, and complete the Entra prerequisites.

© 2026 Sandman