← Open mockup
Phase 9 · Architecture & Data Model

IntelliBroadcast Architecture

A separate ASP.NET Core application using shared Azure SQL platform data and Microsoft Entra ID SSO.

1. Components

Component Responsibility
Microsoft Entra ID Authenticates users for IntelliCampus, Intelli Backoffice, and IntelliBroadcast.
ASP.NET Core MVC Announcement feed, administration pages, tenant filtering, and API.
Azure VM Hosts IntelliBroadcast independently over HTTPS.
Azure SQL Shared Tenant/UserExtended records and the new Announcement table.
IntelliCampus Consumes the latest-announcements API and links to IntelliBroadcast.

2. Simple data model

Existing shared tables

New table: Announcement

Column Type Rule
Id bigint Primary key
TenantId bigint Required FK to Tenant
Title nvarchar(150) Required
Message nvarchar(max) Required
Category nvarchar(30) Academic, Campus, Events, Emergency, General
Audience nvarchar(20) Everyone, Students, Employees
IsImportant bit Default false
Status nvarchar(20) Draft, Scheduled, Published, Archived
PublishOn datetime2 Required to publish
ExpireOn datetime2 Optional, after PublishOn
CreatedByUserId nvarchar(100) FK/reference to UserExtended

No read-receipt or subscription table is needed in the teaching version.

3. SSO flow

  1. User signs into IntelliCampus through Microsoft Entra ID.
  2. User selects “View all announcements.”
  3. Browser opens IntelliBroadcast, which redirects to Entra ID.
  4. Entra reuses the existing session and returns a token to IntelliBroadcast.
  5. IntelliBroadcast validates the token, uses tid and oid claims to find Tenant/UserExtended, then applies TenantId filtering server-side.

The applications share identity through Entra ID; they do not share passwords, cookies, or application sessions.

4. API

GET /api/announcements/latest?limit=3 returns published, active announcements for the authenticated user's tenant and audience. TenantId is derived from the validated identity, never trusted from a query parameter.

5. Deployment

Codex scaffolds and tests the application. The release is published to an Azure VM, run as a managed service, placed behind Nginx or IIS, configured with HTTPS, and supplied database/Entra settings through environment configuration.