Case Study
← Back to Technology Overview — This case study shows how the MASQUE relay was applied to a specific, complex problem: enforcing Azure tenant isolation on managed Apple devices.
Tenant-isolasjon
via MASQUE Omvei
Devices managed by a different organisation's MDM need access to Azure Virtual Desktop in a specific tenant, but can become neither Intune Compliant Device nor use GSA there — both require tenant membership the device cannot have. This case study describes a three-layer architecture — built on the MASQUE relay primitive — that provides secure, enforceable access restricted to exactly that one tenant.
Navigate with the arrows.
Contents
01
02
03
04
05
06
07
08
Problemet
Ukontrollert tenant-tilgang
Løsningen — tre lag
Hvert lag sin rolle
MASQUE Omvei
Tvinger trafikk inn i kontrollert vei
mTLS & ACME Device Attestation
Enhetsgodkjenning via hardware-bundet sertifikat
TLS-avskjæring
Implementert og verifisert
Tenant Restrictions v2
Konfigurert og header-verifisert
Fullstendig arkitektur
Ende-til-ende med animert diagram
Konklusjon & videre arbeid
Funn, begrensninger og neste steg