Skip to main content
This article documents all Azure resources that ContraForce provisions during the onboarding process. Use this reference to understand what’s deployed in your environment, verify deployments, and plan for offboarding if needed.
The resources deployed depend on your module selection (XDR vs XDR + SIEM) and whether you enable AI Agents. Not all resources apply to every deployment.

Deployment Overview

ContraForce deploys resources across several Azure components:

Enterprise Applications

Service principals in Microsoft Entra ID for API access and authentication

Azure Lighthouse

Cross-tenant delegation for MSSP management scenarios

Apollo Infrastructure

Real-time incident notification system for Sentinel

Agent Infrastructure

AI agent hosting environment (optional)

Resources by Module


Phase 1: Initial Onboarding

The first phase provisions core enterprise applications required for all ContraForce deployments.

Enterprise Applications

These applications are provisioned and consented during initial setup:
These two applications are required for all ContraForce deployments, regardless of module selection. They are consented when you first sign in at portal.contraforce.com, as separate ContraForce API and ContraForce Portal Microsoft consent prompts granted by a Global Administrator.

Permissions Granted

Consent model. ContraForce enterprise applications are consented with application (app-only) Microsoft Graph permissions. Admin consent for Microsoft Graph application permissions must be granted by a Global Administrator — Cloud Application Administrator and Application Administrator cannot grant it. Global Administrator is required for the one-time consent only and is not retained; activate it just-in-time with Privileged Identity Management (PIM) and deactivate afterward.Because actions run as the application (no signed-in user required), operator control is enforced through Gamebook approval gates — only Workspace Owners can approve high-impact actions — and a complete audit trail in the Gamebooks History page.

Phase 2: Module-Specific Applications

Additional enterprise applications are consented based on your module selection and enabled features.

Microsoft Defender for Endpoint Applications

Identity Applications

Microsoft Sentinel Applications

Email Applications


Phase 3: Microsoft Sentinel Core Components

For XDR + SIEM deployments, additional Azure resources establish the connection between your Sentinel environment and ContraForce.
This phase only applies to XDR + SIEM module deployments. XDR-only deployments skip this phase.

Azure Lighthouse Delegation

Azure Lighthouse enables cross-tenant management without credential sharing.

What Lighthouse Enables

  • Cross-tenant visibility into your Sentinel workspace
  • Incident management without logging into your tenant
  • Centralized management for MSSPs
Azure Lighthouse delegates Azure resource access only (Sentinel Contributor + Reader on the Sentinel resource group). It does not delegate identity, mailbox, or endpoint response. Those capabilities are provided by the consented ContraForce enterprise applications in each tenant — through per-tenant application consent, or GDAP for CSP relationships. Azure Lighthouse is distinct from Microsoft 365 Lighthouse and from GDAP.
Azure Lighthouse is the Microsoft-recommended approach for MSSP scenarios. It provides secure delegated access without sharing credentials or creating guest accounts.

Role Assignments

Resource Provider Registrations

The following resource providers are registered in your subscription:

Phase 4: Apollo Resource Group

Apollo enables real-time Sentinel incident notifications. A dedicated resource group is created with supporting infrastructure.

Resource Group Details

Resources Deployed

Apollo Architecture


Phase 5: Sentinel Resource Group Deployments

Resources are also deployed directly into your existing Sentinel resource group to enable incident streaming.

Resources in Sentinel Resource Group

How Incident Streaming Works

1

Incident Created

A new incident is created in Microsoft Sentinel
2

Automation Rule Triggers

The Run-Playbook-Publish-Incident-To-Apollo automation rule detects the new incident
3

Logic App Executes

The Publish-Incident-To-Apollo Logic App is triggered
4

Incident Sent

The Logic App sends incident data to the Apollo Function App
5

ContraForce Updated

The incident appears in the ContraForce Command Page in near real-time

Phase 6: Agent Center Resource Group (Optional)

If you deploy ContraForce AI Agents, a dedicated resource group hosts the core agent infrastructure.
AI Agents are an optional feature. Most deployments do not include agent infrastructure. Skip this section if you haven’t enabled AI Agents.

Resource Group Details

Resources Deployed


Phase 7: Per-Agent Resource Groups (Optional)

A dedicated resource group is created for each AI agent deployed per workspace.

Resource Group Naming

Resources Per Agent

Each workspace can have multiple agents, each with its own resource group. Monitor your Azure costs if you deploy many agents across many workspaces.

Complete Resource Summary

By Deployment Type

Enterprise Applications:
  • ContraForce API
  • ContraForce Portal
  • ContraForce for MDE
  • ContraForce Gamebooks for MDE
  • ContraForce Gamebooks for Identity
  • ContraForce Gamebooks for Email
Azure Resources: None

Enterprise Application Quick Reference


Verifying Deployed Resources

Check Enterprise Applications

1

Open Entra ID

2

Go to Enterprise Applications

Click Identity > Applications > Enterprise applications
3

Search for ContraForce

Search for “ContraForce” to see all provisioned applications
4

Verify Status

Each application should show “Enabled” status

Check Azure Resources

1

Open Azure Portal

Navigate to portal.azure.com
2

Search Resource Groups

Search for “contraforce” or “cf-agent” in resource groups
3

Verify Resources

Open each resource group and confirm expected resources exist

Check Role Assignments

1

Navigate to Sentinel Resource Group

Find your Sentinel resource group in Azure Portal
2

Open Access Control

Click Access control (IAM)
3

View Role Assignments

Click Role assignments tab
4

Find ContraForce

Search for “ContraForce” to verify assignments

Cost Considerations

Included Resources

Most ContraForce resources have minimal Azure cost impact:

Potentially Significant Costs

AI Agent deployments can incur significant Azure costs depending on usage:
  • AI Foundry / OpenAI: Pay-per-token pricing
  • Container Apps: Compute costs based on usage
  • CosmosDB: Storage and throughput costs Monitor your Azure spending if you enable AI Agents.

Troubleshooting

Common Issues

Viewing Deployment History

1

Open Subscription

Navigate to your Azure subscription
2

Go to Deployments

Click Deployments in the left navigation
3

Find ContraForce Deployments

Search for “ContraForce” or “Apollo”
4

Review Status

Check deployment status and error messages

Sentinel Onboarding

Complete SIEM module deployment guide

XDR Onboarding

Defender module deployment guide

Enterprise Applications

Service principal details and permissions

Questions about deployed resources? Contact us at support@contraforce.com.