Phase 9 · Architecture & Data Model
IntelliBroadcast Architecture
A separate ASP.NET Core application using shared Azure SQL platform data and Microsoft Entra ID SSO.
1. Components
| Component | Responsibility |
|---|---|
| Microsoft Entra ID | Authenticates users for IntelliCampus, Intelli Backoffice, and IntelliBroadcast. |
| ASP.NET Core MVC | Announcement feed, administration pages, tenant filtering, and API. |
| Azure VM | Hosts IntelliBroadcast independently over HTTPS. |
| Azure SQL | Shared Tenant/UserExtended records and the new Announcement table. |
| IntelliCampus | Consumes the latest-announcements API and links to IntelliBroadcast. |
2. Simple data model
Existing shared tables
-
Tenantidentifies the customer university and stores its Entra Tenant ID. -
UserExtendedidentifies the user, TenantId, audience/role, and Entra Object ID.
New table: Announcement
| Column | Type | Rule |
|---|---|---|
| Id | bigint | Primary key |
| TenantId | bigint | Required FK to Tenant |
| Title | nvarchar(150) | Required |
| Message | nvarchar(max) | Required |
| Category | nvarchar(30) | Academic, Campus, Events, Emergency, General |
| Audience | nvarchar(20) | Everyone, Students, Employees |
| IsImportant | bit | Default false |
| Status | nvarchar(20) | Draft, Scheduled, Published, Archived |
| PublishOn | datetime2 | Required to publish |
| ExpireOn | datetime2 | Optional, after PublishOn |
| CreatedByUserId | nvarchar(100) | FK/reference to UserExtended |
No read-receipt or subscription table is needed in the teaching version.
3. SSO flow
- User signs into IntelliCampus through Microsoft Entra ID.
- User selects “View all announcements.”
- Browser opens IntelliBroadcast, which redirects to Entra ID.
- Entra reuses the existing session and returns a token to IntelliBroadcast.
- IntelliBroadcast validates the token, uses
tidandoidclaims to find Tenant/UserExtended, then applies TenantId filtering server-side.
The applications share identity through Entra ID; they do not share passwords, cookies, or application sessions.
4. API
GET /api/announcements/latest?limit=3 returns published, active announcements for the authenticated user's tenant and audience. TenantId is derived from the validated identity, never trusted from a query parameter.
5. Deployment
Codex scaffolds and tests the application. The release is published to an Azure VM, run as a managed service, placed behind Nginx or IIS, configured with HTTPS, and supplied database/Entra settings through environment configuration.