# Phase 0 — Claim the Caldova tenant and request the Azure subscription

> Everything else in this skill assumes you already have a Caldova tenant. This file covers how to
> get one.
>
> ⚠️ **These two steps are strictly sequential, not parallel.** The tenant must exist **first** —
> the MCAPS BYOT request needs a target tenant to attach the subscription to. You cannot request
> the Azure subscription while the tenant is still provisioning. Claim → wait → *then* request.

**Portal:** <https://cdx.transform.microsoft.com/caldova>
Verified against the live CDX page, 2026-08-26.

---

## The critical path

```
Claim experience  ──►  Tenant provisions   ──►  Request Azure sub   ──►  Sub reaches
(Start demo)           several min; the       (MCAPS BYOT — needs        Completed
                       launcher may spin      the tenant to exist)      ──► add-ons unlock
                       15–30 min AFTER                                   procurement lead time
                       the tenant is ready
                       — check My Dashboard
```

Two waits, back to back, and **neither can be started early**. That is why Phase 0 is the longest
pole in the whole build — not because the work is hard, but because it is serial.

⚠️ **The first wait is shorter than it looks.** The launcher is an unreliable progress indicator —
verify completion in **My Dashboard**, not in the launcher window. See Step 2.

The one thing you *can* usefully do while waiting is
`reference/00-operator-profile.md` (the operator interview). It needs no tenant.

---

## What you are claiming

Caldova is Microsoft's fictional **pharmaceutical / healthcare and life-sciences** enterprise. CDX
describes the experience as spanning **AI Business Solutions, Security and Azure**, built on New
Commerce and bringing together E7, Azure, GitHub and the FY27 MCAPS START keynote scenarios.

| Attribute | Value |
|---|---|
| Experience type | Live Experience → **Individual Experience** |
| Tenant duration | **1 Year** |
| Level | Level 400 |
| MCEM stage | Inspire & Design |
| Conversation | AI in the Flow of Human Ambition |
| Solution areas | AI Business Solutions, Cloud and AI Platforms |
| Audience | BDM, IT Pro |

**Licensing you get** (from the experience card): Microsoft 365 E7 · **Dynamics 365 & Power
Platform Multi App** · D365 Finance · D365 Supply Chain Management · D365 Human Resources · Power
Apps per user · Power Automate with RPA · Power Virtual Agent · Intune Suite · Teams Premium ·
Teams Phone / Calling Plans · Priva · Planner and Project Plan 3 · Sustainability Manager.

> ⚠️ **Licensed ≠ installed.** The content pack is literally named **`Caldova-BlankTenant-V1`**.
> You get the licences and an empty tenant — **no Dynamics 365 apps are deployed**. That is the
> entire reason phases 1–2 of this skill exist. Do not expect to open a Sales Hub on day one.

---

## Step 1 — Check you have a free tenant slot *before* you start

**Go to `My Dashboard` → `Roles & Limits`**
(<https://cdx.transform.microsoft.com/dashboard?tab=roleslimits>)

You will see something like:

```
Microsoft Demos eXperiences Assigned Role(s):  Microsoft Internal
Tenant Limits:
  90 day Tenants:  0 of 3
  1 year Tenants:  3 of 3     ← FULL
```

**The Caldova experience consumes a 1-year tenant slot.** If that counter reads `3 of 3` you cannot
claim another one, and the failure will not necessarily be obvious at claim time.

To free a slot: `My Dashboard` → `Overview` (`?tab=mytenants`) → find an expired or dead tenant →
**Delete**. Expired tenants keep occupying a slot until you actually delete them. Statuses seen in
the wild include `Completed` (healthy), `Expired`, and `Addon-Failed`.

Check this first. It is thirty seconds and it is the difference between a smooth claim and a
confusing one.

---

## Step 2 — Claim the experience

1. Go to <https://cdx.transform.microsoft.com/caldova>.
2. Scroll to the **Caldova Live Demo Environment** card (it is headed *Live Experience* with a
   "Last updated" date).
3. Click **Start demo**.

That is the actual entry point. It is a JavaScript button with no direct URL, so you cannot deep-link
it — you must go to the Caldova page and scroll to the card.

### ⏱️ Expect several minutes — and **the launcher does not tell you when it is done**

**Claiming is not instant.** Provisioning typically takes **several minutes**, and the launcher can
sit there spinning for **15 to 30 minutes**.

> 🚨 **The launcher keeps running long after the tenant has actually been created.** A spinning
> launcher is *not* evidence that the tenant is still provisioning. In many cases the tenant is
> already sitting there, finished, in My Dashboard while the launcher continues to churn.

**So do not wait on the launcher. Check My Dashboard.**

`My Dashboard` → `Overview` (<https://cdx.transform.microsoft.com/dashboard?tab=mytenants>)

If your tenant appears there with **Tenant status = `Completed`**, it is ready — regardless of what
the launcher window is doing. You can close the launcher and move on.

This is the single most time-wasting trap in Phase 0, and it is the same lesson the rest of this
skill teaches about `pac` CLI and the CI provisioning portal: **the progress indicator is not the
source of truth; the management surface is.**

### What NOT to do

- ❌ **Do not re-click Start demo** because nothing seems to be happening. You risk burning a
  second tenant slot against a cap of three (see Step 1).
- ❌ **Do not close the browser and assume it failed.** Provisioning continues server-side.
- ❌ **Do not sit and watch the launcher.** It is not a reliable progress indicator.
- ✅ **Do open My Dashboard in a second tab** and refresh it every few minutes.

### Reading My Dashboard

`My Dashboard` → `Overview` has two tables:

**Tenants** — `Tenant name · Creation date · Expiry date · Period · Content pack · Tenant status ·
Renewal status · Actions · Credentials`

**Experience Details** — `Type · Experience name · Experience SubType · Environment Link · Status ·
Claim Date · Action`

You are waiting for **Tenant status = `Completed`** and **Experience Status = `Active`**, at which
point the row's **Action** column offers **Launch**.

> The page itself says: *"To get the current status of your experience refresh the My Dashboard
> screen."* There is no auto-refresh. Refresh manually every few minutes.

**Do not proceed to Step 3 until the tenant shows `Completed`.** The Azure subscription request
needs a real, finished tenant to target.

### Tenant and experience are separate objects

Worth understanding, because the dashboard shows them separately and the dates differ. On the
reference build the **tenant** `Caldova<NNNNNNNN>` was created **08/14/26** while the **experience**
was claimed **08/24/26** — ten days apart. The `Environment Link` column is what ties an experience
row to its tenant.

### Get your credentials — and switch identity

The **Credentials** button on the tenant row gives the admin account and the user personas. Your
admin will look like `admin@caldova<NNNNNNNN>.onmicrosoft.com`, where `<NNNNNNNN>` is the tenant
number shown in the Tenant name column.

> 🔑 **Ask the operator for this and sign in as the Caldova admin before doing anything else.**
> Every subsequent phase — `pac`, the browser, `az`, the CI portal — must run as the **Caldova
> tenant admin**, not the operator's corporate account. See "Identity" below; it is the single
> most common source of confusing failures in this playbook.

Sign in at the **Microsoft 365 Admin Portal** with the admin account, or with any of the user
profiles listed in your tenant details, to confirm the tenant is alive.

> 🔒 **DO NOT CHANGE ANY TENANT PASSWORDS.** The CDX page states this in capitals. Passwords must
> remain exactly as issued or **the add-on experiences will not work**. This is very easy to trip
> over if you habitually harden a new tenant. There is no warning at the point of failure — the
> add-ons simply misbehave later.

---

## Step 2.5 — Identity: work as the Caldova admin, not yourself

**This is not optional and it is not obvious.** From here on there are at least two identities in
play, and the tooling will happily let you use the wrong one:

| Identity | Example | Use it for |
|---|---|---|
| Your corporate account | `{{USER_EMAIL}}` | CDX portal only |
| **Caldova tenant admin** | `admin@<your-tenant>.onmicrosoft.com` | **Everything else** |

### What to ask the operator

Ask for the **admin UPN** — the `admin@caldova<NNNNNNNN>.onmicrosoft.com` address from the
Credentials panel — and the **tenant ID** (GUID) if they have it.

> 🔒 **Do not ask anyone to paste a password into a chat window, a file, a script, or a commit.**
> Ask only for the UPN. Every sign-in below is an interactive browser prompt; the operator types
> the password into the Microsoft sign-in page themselves. Nothing about this playbook requires a
> password to be written down or shared with an assistant.

### Sign in everywhere, up front

Do all of these before starting Phase 1. Each is a separate identity context and each will silently
use the wrong account if you skip it.

```powershell
# Power Platform CLI — creates a named auth profile for the Caldova tenant
pac auth create --name caldova
# verify the RIGHT profile is active (the * marks it)
pac auth list
```

```powershell
# Azure CLI — only needed once the BYOT subscription lands (Step 3)
az login --tenant <caldova-tenant-id>
```

**Browser:** sign in to the M365 admin portal, Power Platform admin center, and later the Customer
Insights portal as the Caldova admin. If you also use your corporate account in the same browser,
expect an account picker on every new portal — **read it every time**. Picking your own account is
the easy mistake, and it fails in unhelpful ways.

### How wrong-identity failures actually present

They rarely say "wrong account". Symptoms observed:

- `pac` commands run against a **different tenant's environments**, or return an empty list, making
  it look like nothing was created.
- Power Query connection sign-in silently authenticates as the wrong user, and the CSV upload lands
  in the **wrong OneDrive**.
- Portal pages load but show no environments, no apps, or a 404-flavoured error.

**If something is inexplicably empty or missing, check your identity before you debug anything
else.** `pac auth list` and the account chip in the top-right of any portal will tell you in
seconds.

### A note on multiple auth profiles

`pac auth list` may accumulate several profiles over time. Only one is active — the `*` column.
Confirm the active profile points at the Caldova org URL (`https://org<...>.crm.dynamics.com/`)
before running anything that writes.

---

## Step 3 — Request a NET NEW Azure subscription

> 🛑 **Prerequisite: the tenant from Step 2 must already show `Completed`.** The BYOT request needs
> an existing tenant to attach the subscription to. Requesting before the tenant finishes
> provisioning means there is nothing to target.

The CDX page is explicit:

> *"A NET NEW Azure subscription is required to enable multiple product capabilities in the tenant,
> so please obtain one via the MCAPS BYOT Process."*

**Request it here: <https://aka.ms/MCAPSBYOT>**

Submit it the moment the tenant lands. This is the second of the two waits and the longer one —
everything after it is blocked until the subscription clears.

### The rules that actually matter

1. **It must be NET NEW.** An existing subscription already attached to another tenant will not
   work.
2. **It lands in the Caldova tenant, not your corporate tenant.** Any `az` CLI work against it
   needs `az login --tenant <caldova-tenant-id>` as the Caldova admin, not your `@microsoft.com`
   identity.
3. **You do not attach it by hand.** Once provisioned it appears automatically under
   **Subscriptions** on the CDX tenant detail page.
4. **Wait for the right state.** You want status **`Completed`**, step **`AzTsPreReqsCompleted`**.
   Anything earlier means the add-ons will still refuse to deploy.

### Why you want it even if you think you don't

Both **Add-On experiences** on the Caldova page are hard-gated behind it, each fronted by
`* * * PRE-REQ: MUST ADD NEW AZURE SUB VIA MCAPS BYOT * * *`:

| Add-on | Solution area | What it deploys |
|---|---|---|
| **Chapter 2: Build, Observe, and Tune** | Cloud and AI Platforms | Caldova's invoice-assurance solution, proof of concept → scaled and governed |
| **Chapter 3: Security + Agent 365 Scenarios** | AI Business Solutions, Security | XDR base infra, Entra Connect, MDE, Agent 365 |

Their **Get Add-On** buttons do not work until the subscription reaches `Completed`.

**This is a procurement step, not a permanent block** — but it has lead time you cannot compress,
and it cannot be started until the tenant exists. Submit it the moment the tenant lands. On the
reference build, subscription `ME-Caldova<NNNNNNNN>-{{USER_ALIAS}}-1` eventually appeared on the CDX tenant
page with `AzTsPreReqsCompleted / Completed`, releasing both add-ons.

Once it is live, deploy add-ons by opening each experience card and following its scenario
instructions.

---

## Step 4 — Read the supporting documentation

Three documents sit in the **Supporting documentation** section of the Caldova page. They are
download buttons, not links.

| Document | Why you care |
|---|---|
| **Seller FAQ - Caldova Tenant** | General Q&A |
| **STEP 1 - Caldova Demo Experience One-Time Setup Guide** | **The users and licences per persona, plus technical setup.** The most useful of the three. |
| **STEP 2 - Caldova Demo Experience Chapter Narrative** | The packaged demo story across Chapters 1–3 |

Read STEP 1 before you start phase 1 of this skill. It tells you which persona holds which licence,
which is exactly what you need when a feature is missing and you are trying to work out whether it
is a licensing problem or an install problem.

---

## Where you are now

At this point you have an empty, licensed, 1-year Caldova tenant and an Azure subscription request
in flight. Nothing is installed.

**Next:** `reference/00-operator-profile.md` — profile yourself before reskinning anything, then
`reference/01-environment-provisioning.md` to create the Dataverse environment and install the apps.

The operator interview is the one thing that needs no tenant, so it is the right way to spend
either of the two Phase 0 waits.

---

## Claim-time checklist

Strictly in order — steps 2 and 6 are gated on what precedes them.

- [ ] `Roles & Limits` shows a free 1-year tenant slot (delete an expired tenant if not)
- [ ] **Start demo** clicked on the Caldova Live Demo Environment card — **once**
- [ ] ⏱️ Waited several minutes (allow 15+); refreshed My Dashboard manually rather than re-clicking
- [ ] Tenant status `Completed` **and** experience status `Active` on My Dashboard
- [ ] **Admin UPN obtained from the Credentials panel** (`admin@caldova<NNNNNNNN>.onmicrosoft.com`)
- [ ] **`pac auth create --name caldova` run, and `pac auth list` confirms it is the active profile**
- [ ] Browser signed in to the M365 admin portal **as the Caldova admin**, tenant confirmed alive
- [ ] **Passwords left exactly as issued** — and never written into a file, script or chat
- [ ] ⬆️ *Tenant confirmed complete before the next line* — the request needs a target tenant
- [ ] NET NEW Azure subscription requested via <https://aka.ms/MCAPSBYOT>
- [ ] STEP 1 setup guide downloaded and skimmed for the persona/licence table
- [ ] (Later) Subscription shows `AzTsPreReqsCompleted / Completed` under Subscriptions
- [ ] (Later, once the sub lands) `az login --tenant <caldova-tenant-id>` as the Caldova admin
