Prepare hosting and access for your shop
Who runs what
| Component | Runs where | Who pays | Who operates |
|---|---|---|---|
| Shop backend, search, cache | one virtual machine in your Azure subscription | you | we do, through delegated access |
| Storefront website | a Vercel team on your account | you | we do, as members of your team |
| Business Central | your existing Business Central environment | you | you, with the shop extension installed by us |
| Shopper sign-in, shop email delivery, monitoring | our operated services | included in our service | we do |
| Backend and administration web addresses | our domains, protected by our web security provider | included in our service | we do |
You do not need a Cloudflare account, you do not create any application registrations, and no passwords or secrets need to be exchanged. Our access to your Microsoft environment is limited to what you explicitly approve and can be withdrawn by you at any time.
What you provide
1. A virtual machine in Azure
Create a resource group in your Azure subscription and a virtual machine according to the specification we send you (size, disk, region). Then delegate that resource group to us with Azure Lighthouse using the template we provide. The delegation covers only that resource group, nothing else in your subscription, and you can remove it in the portal at any time. It lets us install, update, resize, back up and restore the shop without opening tickets with you for each step.
If your policies do not allow Lighthouse, we can work with SSH access only: install our public key on the machine and allow inbound SSH from the management address we name. In that case disk changes, resizing and machine-level backups stay with your team.
The machine needs outbound internet access. No inbound ports other than SSH from our management address are required; shop traffic reaches the machine through an outbound tunnel.
2. A Vercel team for the storefront
Create a Vercel team on the Pro plan under your own account, with your payment method. Invite the deployment user we name as a member with the developer role, and connect the storefront repository from the GitHub organisation we name. Add your shop domain to the project. Storefront traffic and image delivery are billed by Vercel to this team, so the cost stays under your control and visible to you.
3. Approvals in Microsoft Entra
We send your Microsoft Entra administrator a small number of approval links, usually three: two for the shop's connection to Business Central and one for the shop administration portal. Larger shops may receive one or two more for additional Business Central connections. Opening a link and accepting it creates an entry under Enterprise applications in your directory with exactly the permissions shown on the approval page. You can disable or delete these entries at any time, which immediately stops the shop's access.
After the approvals, your administrator assigns the shop manager role to the people who will maintain the shop in the administration portal.
4. Business Central
The shop connects to Business Central through the approved applications. They must be registered in Business Central with the permission sets we specify. If we are already your Business Central partner, we do this for you; otherwise we send a short step-by-step guide for your Business Central administrator.
5. DNS records
Your DNS administrator adds one record for the shop domain (pointing at Vercel) and the
verification and email-authentication records for the shop's sending subdomain, such as
shop.example.com. We send the exact values. Your existing corporate email
configuration stays untouched.
What we do
- Set up shopper sign-in, email delivery and monitoring for your shop on our side.
- Install and configure the shop backend on your virtual machine, connect it to Business Central, and connect the storefront in your Vercel team.
- Run the acceptance checks with you: catalog, prices, sign-in, cart, checkout, email.
- Operate, monitor and update the shop as agreed in your service agreement.
Order and timing
- Sign-off on this setup and the machine specification.
- Azure resource group, virtual machine and Lighthouse delegation.
- Vercel team and repository connection.
- Entra approvals, Business Central registration, DNS records. These can run in parallel with step 2 and 3.
- Installation, connection and acceptance checks by us with your test users.
Email sending limits for a new domain are raised through a request to Microsoft that can take several weeks, so the email records in step 4 should be added as early as possible.
Security notes
- The approval links are addressed to your directory only. Check that the application names on the approval page match the names we announced.
- Removing the Lighthouse delegation or disabling the approved applications stops our access but also stops the shop. Coordinate such changes with your implementation contact.