About This Architecture

Carestream IDMS enterprise asset access sequence orchestrates three-phase authentication and authorization across Sitecore Portal, Microsoft Entra External ID, Azure Functions, Cosmos DB, and Alibaba Cloud CDN. Phase 1 authenticates users via Entra ID; Phase 2 validates entitlements by querying RBAC Function App and Cosmos DB ProfileEntities against dealer historical product relationships; Phase 3 redirects authenticated, authorized requests to CDN-edge token-protected asset delivery. This architecture demonstrates secure multi-cloud asset distribution with asynchronous entitlement population and legacy Azure AD B2C deprecation handling. Fork and customize this sequence diagram on Diagrams.so to model your own identity federation and entitlement-driven access patterns across hybrid cloud infrastructure.

People also ask

How does Carestream IDMS orchestrate multi-cloud authentication and entitlement-driven asset delivery across Azure and Alibaba Cloud?

Carestream IDMS uses a three-phase sequence: Phase 1 authenticates via Microsoft Entra External ID; Phase 2 validates dealer entitlements by querying Azure RBAC Function App against Cosmos DB ProfileEntities; Phase 3 redirects authorized requests to Alibaba Cloud CDN for token-protected asset delivery. This pattern ensures secure, asynchronously-populated entitlement checks before asset access.

Carestream IDMS Access Sequence v2

MultiadvancedAzureAlibaba CloudIdentity ManagementRBACMulti-CloudSequence Diagram
Domain: Cloud MultiAudience: Enterprise identity and access management architects implementing multi-cloud authentication and entitlement workflows
4 views0 favoritesPublic

Created by

July 24, 2026

Updated

September 24, 2026 at 12:25 PM

Type

sequence

Need a custom architecture diagram?

Describe your architecture in plain English and get a production-ready Draw.io diagram in seconds. Works for AWS, Azure, GCP, Kubernetes, and more.

Generate with AI

AI-generated. Verify before production use. Learn more

Report this diagram