IP Library › Granted Patent US 12,603,871
Granted Patent B2
US 12,603,871 · App. 18/318,254 · Granted Apr 14, 2026

Access orchestration engine in a cloud access management system

Inventors: Zachary Cole Willson (Redmond, WA); Prasanna Chromepet Padmanabhan (Redmond, WA); Gaurav Raghu Dhawan (Seattle, WA); Yizhong Wu (Shanghai, CN); Ivaylo Detelinov Ivanov (Redmond, WA); Purna Venkata S Bodapati (Bothell, WA); Suyin Liu (Suzhou, CN); Wensheng Xu (Suzhou, CN); Alexis Jade Lambert (Apopka, FL); William Lee Wayne Weston (Snoqualmie, WA); Somesh Goel (Newcastle, WA); Sandeep Patnaik (Kirkland, WA)
Assignee: Microsoft Technology Licensing, LLC
H04L63/08
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,603,871
App. No.
18/318,254
Filed
May 16, 2023
Granted
Apr 14, 2026
Kind
B2
Art Unit
2436
USPC
726/7
Abstract

Methods, systems, and computer storage media for providing cloud access management using an access orchestration engine in a cloud access management system. Cloud access management provides access to a remote client of a consumer-identity-supported tenant environment of an organization. In operation, a consumer identity of a user is accessed. The consumer identity is approved for access to the consumer-identity-supported tenant environment. Based on accessing the consumer identity, access orchestration operations are executed for the remote client using remote client access resources, organization resources, and consumer identity resources. Executing the access orchestration operations comprises provisioning the remote client with remote access services for consumer identities; provisioning the remote client with organization resources; and priming the remote client with the consumer identity resources upon determining that the consumer identity is associated with the consumer-identity-supported tenant environment. The remote client is deployed, and the remote client is accessible based on the consumer identity.

Claims (68)

1 . A computerized system comprising:

one or more computer processors; and

computer memory storing computer-useable instructions that, when used by the one or more computer processors, cause the one or more computer processors to perform operations, the operations comprising:

accessing an organization identifier of an organization, wherein the organization identifier is associated with a request to configure the organization for a consumer-identity-supported tenant environment that provides access to remote clients of the organization based on consumer identities;

executing a first plurality of access orchestration operations to configure the consumer-identity-supported tenant environment, wherein the consumer-identity-supported tenant environment is configured to authorize consumer-identity-based access to the remote clients;

communicating an indication that the organization is configured with the consumer-identity-supported tenant environment;

accessing a consumer identity of a user, wherein the consumer identity is approved for access to the consumer-identity-supported tenant environment;

based on accessing the consumer identity, executing a second plurality of access orchestration operations for a remote client, wherein executing the second plurality of access orchestration operations are executed based on remote access client resources, organization resources and consumer identity resources; and

deploying the remote client, wherein the remote client is accessible using the consumer identity.

2 . The system of claim 1 , wherein the consumer-identity-supported tenant environment is generated based on a consumer-identity-supported tenant configuration that removes domain requirements for the organization when configuring the consumer-identity-supported tenant environment.

3 . The system of claim 1 , wherein the consumer-identity-supported tenant environment supports mapping of consumer identities to the consumer-identity-supported tenant environment and discovery of mappings of consumer identities to the consumer-identity-supported tenant environment.

4 . The system of claim 1 , wherein the organization is associated with the organization resources and the consumer identity is associated with the consumer identity resources, the organization resources and consumer identity resources are both accessible via the remote client associated with the consumer-identity-supported tenant environment.

5 . The system of claim 1 , wherein the remote client access resources comprise a plurality of remote access services that support accessing the remote client using the consumer identity.

6 . The system of claim 1 , wherein executing the first plurality of access orchestration operations further comprises:

generating a consumer-identity-supported tenant configuration that initializes the consumer-identity-supported tenant environment;

mapping a first consumer identity to the consumer-identity-supported tenant environment; and

assigning a license to the consumer identity in the consumer-identity-supported tenant environment.

7 . The system of claim 1 , wherein executing the second plurality of access orchestration operations further comprises:

provisioning the remote client with remote client access resources comprising a plurality of remote access services that support accessing the remote client using the consumer identity;

provisioning the remote client with the organization resources of the organization; and

priming the remote client with the consumer identity resources of the consumer identity.

8 . The system of claim 1 , the operations further comprising:

accessing the consumer identity of the user, wherein the consumer identity is licensed for access to the consumer-identity-supported tenant environment;

initiating a discovery operation to identify the consumer-identity-supported tenant environment associated with the consumer identity;

based on the consumer identity, providing access to the consumer-identity-supported tenant environment;

communicating an indication of the remote client that is accessible based on the consumer identity;

accessing credentials associated with the consumer identity; and

based on the credentials associated with the consumer identity, providing access to the remote client.

9 . The system of claim 8 , wherein the discovery operation further comprises communicating with a tenant directory to identify the consumer-identity-supported tenant environment that is mapped directly to the consumer identity of the user in the tenant directory.

10 . The system of claim 1 , the operations further comprising:

communicating the consumer identity from a client device to access the remote client;

based on communicating the consumer identity, receiving an identifier associated with the remote client;

accessing a user selection of the identifier that causes initialization of a user session on the remote client; and

signing into the user session on the remote client.

11 . One or more computer-storage media having computer-executable instructions embodied thereon that, when executed by a computing system having a processor and memory, cause the processor to perform operations, the operations comprising:

accessing an organization identifier of an organization, wherein the organization identifier is associated with a request to configure the organization for a consumer-identity-supported tenant environment that provides access to remote clients of the organization based on consumer identities;

executing a first plurality of access orchestration operations to configure the consumer-identity-supported tenant environment, wherein the consumer-identity-supported tenant environment is configured to authorize consumer-identity-based access to the remote clients;

communicating an indication that the organization is configured with the consumer-identity-supported tenant environment;

accessing a consumer identity of a user, wherein the consumer identity is approved for access to the consumer-identity-supported tenant environment;

based on accessing the consumer identity, executing a second plurality of access orchestration operations for a remote client, wherein executing the second plurality of access orchestration operations are executed based on remote access client resources, organization resources and consumer identity resources; and

deploying the remote client, wherein the remote client is accessible using the consumer identity.

12 . The media of claim 11 , wherein the consumer-identity-supported tenant environment is generated based on a consumer-identity-supported tenant configuration that removes domain requirements for the organization when configuring the consumer-identity-supported tenant environment.

13 . The media of claim 12 , wherein the consumer-identity-supported tenant environment supports mapping of consumer identities to the consumer-identity-supported tenant environment and discovery of mappings of consumer identities to the consumer-identity-supported tenant environment.

14 . The media of claim 11 , wherein executing the first plurality of access orchestration operations further comprises:

generating a consumer-identity-supported tenant configuration that initializes the consumer-identity-supported tenant environment;

mapping a first consumer identity to the consumer-identity-supported tenant environment; and

assigning a license to the consumer identity in the consumer-identity-supported tenant environment.

15 . The media of claim 11 , wherein executing the second plurality of access orchestration operations further comprises:

provisioning the remote client with remote client access resources comprising a plurality of remote access services that support accessing the remote client using the consumer identity;

provisioning the remote client with the organization resources of the organization; and

priming the remote client with the consumer identity resources of the consumer identity.

16 . A computer-implemented method, the method comprising:

accessing an organization identifier of an organization, wherein the organization identifier is associated with a request to configure the organization for a consumer-identity-supported tenant environment that provides access to remote clients of the organization based on consumer identities;

executing a first plurality of access orchestration operations to configure the consumer-identity-supported tenant environment, wherein the consumer-identity-supported tenant environment is configured to authorize consumer-identity-based access to the remote clients;

communicating an indication that the organization is configured with the consumer-identity-supported tenant environment;

accessing a consumer identity of a user, wherein the consumer identity is approved for access to the consumer-identity-supported tenant environment;

based on accessing the consumer identity, executing a second plurality of access orchestration operations for a remote client, wherein executing the second plurality of access orchestration operations are executed based on remote access client resources, organization resources and consumer identity resources; and

deploying the remote client, wherein the remote client is accessible using the consumer identity.

17 . The method of claim 16 , wherein the consumer-identity-supported tenant environment is generated based on a consumer-identity-supported tenant configuration that removes domain requirements for the organization when configuring the consumer-identity-supported tenant environment.

18 . The method of claim 16 , wherein the consumer-identity-supported tenant environment supports mapping of consumer identities to the consumer-identity-supported tenant environment and discovery of mappings of consumer identities to the consumer-identity-supported tenant environment.

19 . The method of claim 16 , wherein executing the first plurality of access orchestration operations further comprises:

generating a consumer-identity-supported tenant configuration that initializes the consumer-identity-supported tenant environment;

mapping a first consumer identity to the consumer-identity-supported tenant environment; and

assigning a license to the consumer identity in the consumer-identity-supported tenant environment.

20 . The method of claim 16 , wherein executing the second plurality of access orchestration operations further comprises:

provisioning the remote client with remote client access resources comprising a plurality of remote access services that support accessing the remote client using the consumer identity;

provisioning the remote client with the organization resources of the organization; and

priming the remote client with the consumer identity resources of the consumer identity.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 11, 2023
From: BODAPATI, PURNA VENKATA S.; DHAWAN, GAURAV RAGHU; GOEL, SOMESH; IVANOV, IVAYLO DETELINOV; LAMBERT, ALEXIS JADE; LIU, SUYIN; PADMANABHAN, PRASANNA CHROMEPET; PATNAIK, SANDEEP; WESTON, WILLIAM LEE WAYNE; WILLSON, ZACHARY COLE; WU, YIZHONG; XU, WENSHENG
To: MICROSOFT TECHNOLOGY LICENSING, LLC
Reel/Frame 064252/0155 →
Continuity (1)
Related Publication 20240388576A1 · Nov 21, 2024
References Cited (10)
US 10057273B1 · Chakraborty · 2018 [cited by examiner]
US 10616224B2 · Subramanian · 2020 [cited by examiner]
US 12238102B2 · Palanisamy · 2025 [cited by examiner]
US 20130254847A1 · Adams et al. · 2013 [cited by applicant]
US 20140090037A1 · Singh · 2014 [cited by applicant]
US 20160134619A1 · Mikheev · 2016 [cited by applicant]
US 20200244664A1 · Pate · 2020 [cited by examiner]
“Identity Platform multi-tenancy”, Retrieved from the URL: https://web.archive.org/web/20191217141430/https://cloud.google.com/identity-platform/docs/multi-tenancy, Dec. 17, 2019, 2 Pages. [cited by applicant]
International Search Report and Written Opinion received for PCT Application No. PCT/US2024/026710, Sep. 10, 2024, 15 pages. [cited by applicant]
International Preliminary Report on Patentability (Chapter I) received for PCT Application No. PCT/US2024/026710, Mailed on Nov. 27, 2025, 09 Pages. [cited by applicant]