Deploy an Identity Router Virtual Machine in Microsoft Azure
Identity router (IDR) supports deployment in Microsoft Azure. With this capability, you can build, deploy, and manage IDR on Azure using virtual hard disk (VHD) images, ensuring seamless authentication integration for a secure and efficient deployment.
This topic outlines the steps to deploy a virtual machine in Microsoft Azure using a VHD:
Before you begin
You must be a Super Admin in the Cloud Administration Console.
Obtain the required virtual hard disk (VHD) file to use as the base image for deployment in Azure. See Obtain the Identity Router Image
Ensure that you have the required Azure roles and permissions, including Contributor (or Virtual Machine Contributor), Network Contributor, and Storage Account Contributor in the relevant resource group or subscription.
Upload VHD Image to Azure
This section explains how to upload the virtual hard disk (VHD) file to Azure Blob Storage for virtual machine deployment.
Procedure
Sign in to the Azure Portal using your credentials.
Use an existing Storage account or create a new one if necessary.
Navigate to Storage browser > Blob containers, then click Add container to create a new container.
Upload the VHD file to the newly created container using the blob type "Page Blob."
In the CONTENT-MD5 field, enter the copied Checksum.
After the upload, click the VHD file and copy its URL.
Create VHD Image
This section explains how to generate or prepare a virtual hard disk (VHD) file that meets Azure’s requirements, ensuring compatibility for virtual machine deployment.
Procedure
Sign in to Azure Services.
Navigate to Images and click Create.
Enter the following details:
In the Region field, select your preferred region from the available options.
In the OS type field, select Linux.
In the VM generation field, select any generation.
In the Storage blob field, paste the copied VHD file URL.
In the Account type field, select Premium SSD.
In the Host caching field, select Read/write.
Click Review + create to validate the configuration.
Once validation is complete, click Create to generate the image.
After the image creation process finishes, navigate to Resource overview to verify the image.
Create a Virtual Machine (VM) from the VHD Image
This section explains how to create a virtual machine (VM) in Azure by converting the uploaded VHD into a managed disk and configuring the necessary settings for deployment.
Procedure
Sign in to Azure Services.
Select the image created from the VHD file in Azure, and then click Create VM.
In the Basics tab, enter the following details:
In the Image field, use the default option.
In the VM architecture field, select x64.
In the Size field, select a 'D' Family size (for example, D2s_v3, D2s_v4, or similar) with at least 2 vCPUs and 8 GiB RAM.
In the Authentication type field, select Password (recommended option).
In the Public inbound ports field, select Allow selected ports.
In the Selected inbound ports field, select SSH (22).
In the License type field, select Other.
In the Disks tab, enter the following details:
In the OS disk size field, select 50 GiB or larger, as the IDR disk size must be at least 50 GiB.
In the OS disk type field, select Premium SSD.
Select the Delete with VM checkbox.
In the Networking tab, enter the following details:
In the Virtual network field, select the appropriate Azure Virtual Network. This selection defines the network environment in which the identity router will be deployed.
In the Subnet field, select a subnet within the selected virtual network. This subnet determines where the identity router will be deployed. The subnet can be public or private, depending on how users and resources will connect to the identity router.
In the Public IP field, select None (recommended, as public access is unnecessary).
In the NIC network security group field, select Basic. Do not select "None," as SSH access will not work.
Select the Delete NIC when VM is deleted checkbox.
Review the configuration and click Review + create once validated. Wait for the VM deployment to complete.
Navigate to the Resource Overview page and verify the following:
Status: VM is running.
Agent status: Ready.
Private IP address: Available and ready to be copied for further configuration.
After you finish
Related Articles
Edit Cloud Authentication Service Connection 93Number of Views Configure Handling of Incorrect Passcodes 11Number of Views Test the RSA Authentication Manager Connection 61Number of Views Cloud Access Service POC Quick Setup Guide - Step 4: Add an Access Policy 28Number of Views Add an Administrative Role 18Number of Views
Trending Articles
RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide RSA Authentication Manager 8.9 Release Notes (January 2026) How to install the jTDS JDBC driver on WildFly for use with Data Collections in RSA Identity Governance & Lifecycle RSA Authentication Manager 8.8 Setup and Configuration Guide Artifacts to gather in RSA Identity Governance & Lifecycle