Skip to content

Commit 03ec1d4

Browse files
committed
Merging changes synced from https://github.com/MicrosoftDocs/azure-docs-pr (branch live)
2 parents b01d4ba + acfc931 commit 03ec1d4

File tree

107 files changed

+5119
-1438
lines changed

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

107 files changed

+5119
-1438
lines changed

articles/active-directory/cloud-infrastructure-entitlement-management/cloudknox-faqs.md

Lines changed: 11 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -8,7 +8,7 @@ ms.service: active-directory
88
ms.subservice: ciem
99
ms.workload: identity
1010
ms.topic: faq
11-
ms.date: 02/23/2022
11+
ms.date: 04/20/2022
1212
ms.author: v-ydequadros
1313
---
1414

@@ -18,6 +18,9 @@ ms.author: v-ydequadros
1818
> CloudKnox Permissions Management (CloudKnox) is currently in PREVIEW.
1919
> Some information relates to a prerelease product that may be substantially modified before it's released. Microsoft makes no warranties, express or implied, with respect to the information provided here.
2020
21+
> [!NOTE]
22+
> The CloudKnox Permissions Management (CloudKnox) PREVIEW is currently not available for tenants hosted in the European Union (EU).
23+
2124

2225
This article answers frequently asked questions (FAQs) about CloudKnox Permissions Management (CloudKnox).
2326

@@ -46,6 +49,10 @@ No, CloudKnox is a hosted cloud offering.
4649

4750
Yes, non-Azure customers can use our solution. CloudKnox is a multi-cloud solution so even customers who have no subscription to Azure can benefit from it.
4851

52+
## Is CloudKnox available for tenants hosted in the European Union (EU)?
53+
54+
No, the CloudKnox Permissions Management (CloudKnox) PREVIEW is currently not available for tenants hosted in the European Union (EU).
55+
4956
## If I’m already using Azure AD Privileged Identity Management (PIM) for Azure, what value does CloudKnox provide?
5057

5158
CloudKnox complements Azure AD PIM. Azure AD PIM provides just-in-time access for admin roles in Azure (as well as Microsoft Online Services and apps that use groups), while CloudKnox allows multi-cloud discovery, remediation, and monitoring of privileged access across Azure, AWS, and GCP.
@@ -109,9 +116,9 @@ Customers only need to track the evolution of their Permission Creep Index to mo
109116
## Can customers generate permissions usage reports?
110117

111118
Yes, CloudKnox has various types of system report available that capture specific data sets. These reports allow customers to:
112-
- Make timely decisions
113-
- Analyze usage trends and system/user performance
114-
- Identify high-risk areas
119+
- Make timely decisions.
120+
- Analyze usage trends and system/user performance.
121+
- Identify high-risk areas.
115122

116123
For information about permissions usage reports, see [Generate and download the Permissions analytics report](cloudknox-product-permissions-analytics-reports.md).
117124

articles/active-directory/cloud-infrastructure-entitlement-management/cloudknox-onboard-aws.md

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -8,7 +8,7 @@ ms.service: active-directory
88
ms.subservice: ciem
99
ms.workload: identity
1010
ms.topic: how-to
11-
ms.date: 03/10/2022
11+
ms.date: 04/20/2022
1212
ms.author: v-ydequadros
1313
---
1414

@@ -18,6 +18,9 @@ ms.author: v-ydequadros
1818
> CloudKnox Permissions Management (CloudKnox) is currently in PREVIEW.
1919
> Some information relates to a prerelease product that may be substantially modified before it's released. Microsoft makes no warranties, express or implied, with respect to the information provided here.
2020
21+
> [!NOTE]
22+
> The CloudKnox Permissions Management (CloudKnox) PREVIEW is currently not available for tenants hosted in the European Union (EU).
23+
2124

2225
This article describes how to onboard an Amazon Web Services (AWS) account on CloudKnox Permissions Management (CloudKnox).
2326

articles/active-directory/cloud-infrastructure-entitlement-management/cloudknox-onboard-azure.md

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -8,7 +8,7 @@ ms.service: active-directory
88
ms.subservice: ciem
99
ms.workload: identity
1010
ms.topic: how-to
11-
ms.date: 03/10/2022
11+
ms.date: 04/20/2022
1212
ms.author: v-ydequadros
1313
---
1414

@@ -18,6 +18,9 @@ ms.author: v-ydequadros
1818
> CloudKnox Permissions Management (CloudKnox) is currently in PREVIEW.
1919
> Some information relates to a prerelease product that may be substantially modified before it's released. Microsoft makes no warranties, express or implied, with respect to the information provided here.
2020
21+
> [!NOTE]
22+
> The CloudKnox Permissions Management (CloudKnox) PREVIEW is currently not available for tenants hosted in the European Union (EU).
23+
2124
This article describes how to onboard a Microsoft Azure subscription or subscriptions on CloudKnox Permissions Management (CloudKnox). Onboarding a subscription creates a new authorization system to represent the Azure subscription in CloudKnox.
2225

2326
> [!NOTE]

articles/active-directory/cloud-infrastructure-entitlement-management/cloudknox-onboard-enable-tenant.md

Lines changed: 7 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -8,7 +8,7 @@ ms.service: active-directory
88
ms.subservice: ciem
99
ms.workload: identity
1010
ms.topic: how-to
11-
ms.date: 03/14/2022
11+
ms.date: 04/20/2022
1212
ms.author: v-ydequadros
1313
---
1414

@@ -18,6 +18,12 @@ ms.author: v-ydequadros
1818
> CloudKnox Permissions Management (CloudKnox) is currently in PREVIEW.
1919
> Some information relates to a prerelease product that may be substantially modified before it's released. Microsoft makes no warranties, express or implied, with respect to the information provided here.
2020
21+
22+
> [!NOTE]
23+
> The CloudKnox Permissions Management (CloudKnox) PREVIEW is currently not available for tenants hosted in the European Union (EU).
24+
25+
26+
2127
This article describes how to enable CloudKnox Permissions Management (CloudKnox) in your organization. Once you've enabled CloudKnox, you can connect it to your Amazon Web Services (AWS), Microsoft Azure, or Google Cloud Platform (GCP) platforms.
2228

2329
> [!NOTE]

articles/active-directory/cloud-infrastructure-entitlement-management/cloudknox-onboard-gcp.md

Lines changed: 6 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -8,7 +8,7 @@ ms.service: active-directory
88
ms.subservice: ciem
99
ms.workload: identity
1010
ms.topic: how-to
11-
ms.date: 03/14/2022
11+
ms.date: 04/20/2022
1212
ms.author: v-ydequadros
1313
---
1414

@@ -18,6 +18,11 @@ ms.author: v-ydequadros
1818
> CloudKnox Permissions Management (CloudKnox) is currently in PREVIEW.
1919
> Some information relates to a prerelease product that may be substantially modified before it's released. Microsoft makes no warranties, express or implied, with respect to the information provided here.
2020
21+
22+
> [!NOTE]
23+
> The CloudKnox Permissions Management (CloudKnox) PREVIEW is currently not available for tenants hosted in the European Union (EU).
24+
25+
2126
This article describes how to onboard a Google Cloud Platform (GCP) project on CloudKnox Permissions Management (CloudKnox).
2227

2328
> [!NOTE]

articles/active-directory/cloud-infrastructure-entitlement-management/cloudknox-overview.md

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -8,7 +8,7 @@ ms.service: active-directory
88
ms.subservice: ciem
99
ms.workload: identity
1010
ms.topic: overview
11-
ms.date: 03/10/2022
11+
ms.date: 04/20/2022
1212
ms.author: v-ydequadros
1313
---
1414

@@ -19,6 +19,9 @@ ms.author: v-ydequadros
1919
> CloudKnox Permissions Management (CloudKnox) is currently in PREVIEW.
2020
> Some information relates to a prerelease product that may be substantially modified before it's released. Microsoft makes no warranties, express or implied, with respect to the information provided here.
2121
22+
> [!NOTE]
23+
> The CloudKnox Permissions Management (CloudKnox) PREVIEW is currently not available for tenants hosted in the European Union (EU).
24+
2225
## Overview
2326

2427
CloudKnox Permissions Management (CloudKnox) is a cloud infrastructure entitlement management (CIEM) solution that provides comprehensive visibility into permissions assigned to all identities. For example, over-privileged workload and user identities, actions, and resources across multi-cloud infrastructures in Microsoft Azure, Amazon Web Services (AWS), and Google Cloud Platform (GCP).

articles/active-directory/cloud-infrastructure-entitlement-management/cloudknox-training-videos.md

Lines changed: 1 addition & 27 deletions
Original file line numberDiff line numberDiff line change
@@ -8,7 +8,7 @@ ms.service: active-directory
88
ms.subservice: ciem
99
ms.workload: identity
1010
ms.topic: how-to
11-
ms.date: 03/14/2022
11+
ms.date: 04/20/2022
1212
ms.author: v-ydequadros
1313
---
1414

@@ -31,33 +31,7 @@ To view a video on how to configure and onboard Amazon Web Services (AWS) accoun
3131

3232
To view a video on how to configure and onboard Google Cloud Platform (GCP) accounts in CloudKnox, select [Configure and onboard GCP accounts](https://www.youtube.com/watch?app=desktop&v=W3epcOaec28).
3333

34-
<!---## Privilege on demand (POD) work flows
3534

36-
- View a step-by-step video on the [privilege on demand (POD) work flow from the Just Enough Permissions (JEP) Controller](https://vimeo.com/461508166/3d88107f41).
37-
38-
## Usage analytics
39-
40-
- View a step-by-step video on [usage analytics](https://vimeo.com/461509556/b7bb392b83).
41-
42-
## Just Enough Permissions (JEP) roles and policies
43-
44-
- View a step-by-step video on [how to use and interpret data on the Role/Policy tab under the JEP Controller](https://vimeo.com/461510754/3dd31d85b7).
45-
46-
## Attach or detach permissions for users, roles, and resources
47-
48-
- View a step-by-step video on [how to attach and detach permissions for users, roles, and resources](https://vimeo.com/461512552/6f6a06e6c1).
49-
50-
## Audit trails
51-
52-
- View a step-by-step video on [how to use the audit trail](https://vimeo.com/461513290/b431a38b6c).
53-
54-
## Alert triggers
55-
56-
- View a step-by-step video on [how to create an alert trigger](https://vimeo.com/461881849/019c843cc6).
57-
58-
## Group permissions
59-
60-
- View a step-by-step video on [how to create group-based permissions](https://vimeo.com/462797947/d041de9157).--->
6135

6236

6337
## Next steps
Loading
Loading

articles/active-directory/privileged-identity-management/pim-resource-roles-assign-roles.md

Lines changed: 9 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -10,7 +10,7 @@ ms.topic: how-to
1010
ms.tgt_pltfrm: na
1111
ms.workload: identity
1212
ms.subservice: pim
13-
ms.date: 02/02/2022
13+
ms.date: 04/18/2022
1414
ms.author: curtand
1515
ms.custom: pim
1616
ms.collection: M365-identity-device-management
@@ -86,6 +86,14 @@ Follow these steps to make a user eligible for an Azure resource role.
8686

8787
1. To specify a specific assignment duration, change the start and end dates and times.
8888

89+
1. If the role has been defined with actions that permit assignments to that role with conditions, then you can select **Add condition** to add a condition based on the principal user and resource attributes that are part of the assignment.
90+
91+
![New assignment - Conditions](./media/pim-resource-roles-assign-roles/new-assignment-conditions.png)
92+
93+
Conditions can be entered in the expression builder.
94+
95+
![New assignment - Condition built from an expression](./media/pim-resource-roles-assign-roles/new-assignment-condition-expression.png)
96+
8997
1. When finished, select **Assign**.
9098

9199
1. After the new role assignment is created, a status notification is displayed.

0 commit comments

Comments
 (0)