|
| 1 | +--- |
| 2 | +title: Azure AD feature availability in Azure Government |
| 3 | +description: Learn which Azure AD features are available in Azure Government. |
| 4 | + |
| 5 | +services: multi-factor-authentication |
| 6 | +ms.service: active-directory |
| 7 | +ms.subservice: authentication |
| 8 | +ms.topic: conceptual |
| 9 | +ms.date: 02/28/2022 |
| 10 | + |
| 11 | +ms.author: justinha |
| 12 | +author: justinha |
| 13 | +manager: daveba |
| 14 | +ms.reviewer: michmcla |
| 15 | +ms.collection: M365-identity-device-management |
| 16 | +--- |
| 17 | + |
| 18 | +# Cloud feature availability |
| 19 | + |
| 20 | +<!---Jeremy said there are additional features that don't fit nicely in this list that we need to add later---> |
| 21 | + |
| 22 | +This following table lists Azure AD feature availability in Azure Government. |
| 23 | + |
| 24 | + |
| 25 | +|Service | Feature | Availability | |
| 26 | +|:------|---------|:------------:| |
| 27 | +|**Authentication, single sign-on, and MFA**||| |
| 28 | +||Cloud authentication (Pass-through authentication, password hash synchronization) | ✅ | |
| 29 | +|| Federated authentication (Active Directory Federation Services or federation with other identity providers) | ✅ | |
| 30 | +|| Single sign-on (SSO) unlimited | ✅ | |
| 31 | +|| Multifactor authentication (MFA) | Hardware OATH tokens are not available. Instead, use Conditional Access policies with named locations to establish when multifactor authentication should and should not be required based off the user's current IP address. Microsoft Authenticator only shows GUID and not UPN for compliance reasons. | |
| 32 | +|| Passwordless (Windows Hello for Business, Microsoft Authenticator, FIDO2 security key integrations) | ✅ | |
| 33 | +|| Service-level agreement | ✅ | |
| 34 | +|**Applications access**||| |
| 35 | +|| SaaS apps with modern authentication (Azure AD application gallery apps, SAML, and OAUTH 2.0) | ✅ | |
| 36 | +|| Group assignment to applications | ✅ | |
| 37 | +|| Cloud app discovery (Microsoft Cloud App Security) | ✅ | |
| 38 | +|| Application Proxy for on-premises, header-based, and Integrated Windows Authentication | ✅ | |
| 39 | +|| Secure hybrid access partnerships (Kerberos, NTLM, LDAP, RDP, and SSH authentication) | ✅ | |
| 40 | +|**Authorization and Conditional Access**||| |
| 41 | +|| Role-based access control (RBAC) | ✅ | |
| 42 | +|| Conditional Access | ✅ | |
| 43 | +|| SharePoint limited access | ✅ | |
| 44 | +|| Session lifetime management | ✅ | |
| 45 | +|| Identity Protection (vulnerabilities and risky accounts) | See [Identity protection](#identity-protection) below. | |
| 46 | +|| Identity Protection (risk events investigation, SIEM connectivity) | See [Identity protection](#identity-protection) below. | |
| 47 | +|**Administration and hybrid identity**||| |
| 48 | +|| User and group management | ✅ | |
| 49 | +|| Advanced group management (Dynamic groups, naming policies, expiration, default classification) | ✅ | |
| 50 | +|| Directory synchronization—Azure AD Connect (sync and cloud sync) | ✅ | |
| 51 | +|| Azure AD Connect Health reporting | ✅ | |
| 52 | +|| Delegated administration—built-in roles | ✅ | |
| 53 | +|| Global password protection and management – cloud-only users | ✅ | |
| 54 | +|| Global password protection and management – custom banned passwords, users synchronized from on-premises Active Directory | ✅ | |
| 55 | +|| Microsoft Identity Manager user client access license (CAL) | ✅ | |
| 56 | +|**End-user self-service**||| |
| 57 | +|| Application launch portal (My Apps) | ✅ | |
| 58 | +|| User application collections in My Apps | ✅ | |
| 59 | +|| Self-service account management portal (My Account) | ✅ | |
| 60 | +|| Self-service password change for cloud users | ✅ | |
| 61 | +|| Self-service password reset/change/unlock with on-premises write-back | ✅ | |
| 62 | +|| Self-service sign-in activity search and reporting | ✅ | |
| 63 | +|| Self-service group management (My Groups) | ✅ | |
| 64 | +|| Self-service entitlement management (My Access) | ✅ | |
| 65 | +|**Identity governance**||| |
| 66 | +|| Automated user provisioning to apps | ✅ | |
| 67 | +|| Automated group provisioning to apps | ✅ | |
| 68 | +|| HR-driven provisioning | Partial. See [HR-provisioning apps](#hr-provisioning-apps). | |
| 69 | +|| Terms of use attestation | ✅ | |
| 70 | +|| Access certifications and reviews | ✅ | |
| 71 | +|| Entitlement management | ✅ | |
| 72 | +|| Privileged Identity Management (PIM), just-in-time access | ✅ | |
| 73 | +|**Event logging and reporting**||| |
| 74 | +|| Basic security and usage reports | ✅ | |
| 75 | +|| Advanced security and usage reports | ✅ | |
| 76 | +|| Identity Protection: vulnerabilities and risky accounts | ✅ | |
| 77 | +|| Identity Protection: risk events investigation, SIEM connectivity | ✅ | |
| 78 | +|**Frontline workers**||| |
| 79 | +|| SMS sign-in | Feature not available. | |
| 80 | +|| Shared device sign-out | Enterprise state roaming for Windows 10 devices is not available. | |
| 81 | +|| Delegated user management portal (My Staff) | Feature not available. | |
| 82 | + |
| 83 | + |
| 84 | +## Identity protection |
| 85 | + |
| 86 | +| Risk Detection | Availability | |
| 87 | +|----------------|:--------------------:| |
| 88 | +|Leaked credentials (MACE) | ✅ | |
| 89 | +|Azure AD threat intelligence | Feature not available. | |
| 90 | +|Anonymous IP address | ✅ | |
| 91 | +|Atypical travel | ✅ | |
| 92 | +|Anomalous Token | Feature not available. | |
| 93 | +|Token Issuer Anomaly| Feature not available. | |
| 94 | +|Malware linked IP address | ✅ | |
| 95 | +|Suspicious browser | ✅ | |
| 96 | +|Unfamiliar sign-in properties | ✅ | |
| 97 | +|Admin confirmed user compromised | ✅ | |
| 98 | +|Malicious IP address | ✅ | |
| 99 | +|Suspicious inbox manipulation rules | ✅ | |
| 100 | +|Password spray | ✅ | |
| 101 | +|Impossible travel | ✅ | |
| 102 | +|New country | ✅ | |
| 103 | +|Activity from anonymous IP address | ✅ | |
| 104 | +|Suspicious inbox forwarding | ✅ | |
| 105 | +|Azure AD threat intelligence | Feature not available. | |
| 106 | +|Additional risk detected | ✅ | |
| 107 | + |
| 108 | + |
| 109 | +## HR-provisioning apps |
| 110 | + |
| 111 | +| HR-provisioning app | Availability | |
| 112 | +|----------------|:--------------------:| |
| 113 | +|Workday to Azure AD User Provisioning | ✅ | |
| 114 | +|Workday Writeback | ✅ | |
| 115 | +|SuccessFactors to Azure AD User Provisioning | ✅ | |
| 116 | +|SuccessFactors to Writeback | ✅ | |
| 117 | +|Provisioning agent configuration and registration with Gov cloud tenant| Works with special undocumented command-line invocation:<br> AADConnectProvisioningAgent.Installer.exe ENVIRONMENTNAME=AzureUSGovernment | |
| 118 | + |
| 119 | + |
| 120 | + |
| 121 | + |
| 122 | + |
0 commit comments