You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit 71cf0c1
Browse filesBrowse the repository at this point in the historyBrowse files
Copy file name to clipboardExpand all lines: README.md
+13-3Lines changed: 13 additions & 3 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -25,9 +25,17 @@ The single-region request flow is:
25
25
2. App Service Authentication (Easy Auth) validates the caller before the Function runs.
26
26
3. The Function decrypts the request using a key stored in Azure Key Vault.
27
27
4. The selected provider adapter authenticates to the phone provider and submits the SMS or voice message.
28
-
5.The Function returns a success response after provider acceptance. Confirming delivery to the
28
+
5.For a live request, the Function returns a success response after provider acceptance. Confirming delivery to the
29
29
recipient is a separate validation step.
30
30
31
+
The diagram's delivery path describes **live requests**. An authorized, valid encrypted
32
+
**evaluation request (`mode: 2`)** returns the matching nonce without submitting a message to the
33
+
provider. Background credential refresh can still run independently. Authentication failures may
34
+
return **401 or 403**; neither is a successful evaluation.
35
+
36
+
**East US in the diagram is illustrative, not a required or guaranteed deployment location.**
37
+
Choose a region with available Linux Premium EP1 capacity and sufficient quota in your subscription.
38
+
31
39
Application Insights provides operational telemetry. Provider API keys stay in Key Vault; supported
32
40
OAuth integrations use managed identity. This guide covers only the single-region topology shown
33
41
above. Multi-region deployment, failover, and resiliency guidance are deferred.
@@ -44,15 +52,17 @@ Use a **dedicated nonproduction tenant and subscription** for your first deploym
44
52
| Azure permissions | An Azure user account permitted to deploy at subscription scope, register required resource providers, and create scoped role assignments. |
45
53
| Microsoft Entra permissions | A Privileged Role Administrator for the application and Microsoft Graph configuration. Setup uses the allowed-tenants preview and requires Microsoft Graph beta access. |
46
54
| Policy activation | An Authentication Policy Administrator to activate the endpoint after validation. Deployment alone does not activate it. |
47
-
| Region and hosting | A region supporting Linux Premium EP1. Deployed resources incur Azure charges; review the hosting plan before approval. |
55
+
| Region and hosting | A region supporting Linux Premium EP1 with sufficient EP1 quota for your subscription. Resource-provider registration does not grant quota. Deployed resources incur Azure charges; review the hosting plan before approval. |
48
56
| C# only | The .NET 8 SDK and NuGet access. Setup builds and publishes the selected .NET package automatically. |
49
57
50
58
Setup can install missing Microsoft Graph PowerShell modules and the Azure CLI Bicep component
51
59
after confirmation. Azure CLI itself must already be installed. JavaScript and Python do not
52
60
require a local build toolchain for this guided deployment; Python dependencies are built in Azure.
53
61
54
62
Review the complete [setup prerequisites](setup/docs/README.md#prerequisites-for-step-2) before
55
-
deploying.
63
+
deploying. If Azure reports `SubscriptionIsOverQuotaForSku`, follow the
0 commit comments