Overview
This guide takes a deployment engineer — with no prior CET2 exposure — from a blank environment to a
Prerequisites
Infrastructure
Azure App Registrations
You create two app registrations in the MSP/home tenant. (For a fully customer-owned deployment,
Microsoft Graph Permissions
These are assigned to App 2 (Data) as Application permissions, and admin-consented separately in
One-Click Deploy (Azure)
For Model A deployments, an ARM/Bicep template automates most of Server Installation —
Server Installation
Backend
Configuration
CET2's configuration has two real sections: AzureAd (JWT validation for user sign-in) and
White-Labelling
CET2's product name is a runtime setting, not something baked into the build. Any organisation
SSL and DNS
Public URL
Tenant Onboarding
This is the complete, per-customer process — run it once per new customer tenant, after the CET2
Validation Testing
Run this after every deployment and every new tenant onboarding.
Customer Deployment Package
| Folder | Contents | Customer-editable |
Deployment Runbook
A concise, linear checklist for an engineer to follow start to finish. Each step links back to the