|
1 | 1 | ---
|
2 |
| - |
3 | 2 | title: What is Azure Active Directory recommendations (preview)? | Microsoft Docs
|
4 | 3 | description: Provides a general overview of Azure Active Directory recommendations.
|
5 | 4 | services: active-directory
|
6 |
| -documentationcenter: '' |
7 |
| -author: MarkusVi |
| 5 | +author: shlipsey3 |
8 | 6 | manager: amycolannino
|
9 |
| -editor: '' |
10 |
| - |
11 |
| -ms.assetid: e2b3d8ce-708a-46e4-b474-123792f35526 |
12 | 7 | ms.service: active-directory
|
13 |
| -ms.devlang: na |
14 | 8 | ms.topic: overview
|
15 | 9 | ms.tgt_pltfrm: na
|
16 | 10 | ms.workload: identity
|
17 | 11 | ms.subservice: report-monitor
|
18 |
| -ms.date: 08/22/2022 |
19 |
| -ms.author: markvi |
| 12 | +ms.date: 10/13/2022 |
| 13 | +ms.author: sarahlipsey |
20 | 14 | ms.reviewer: hafowler
|
| 15 | +ms.collection: M365-identity-device-management |
21 | 16 |
|
22 | 17 | # Customer intent: As an Azure AD administrator, I want guidance to so that I can keep my Azure AD tenant in a healthy state.
|
23 |
| -ms.collection: M365-identity-device-management |
| 18 | + |
24 | 19 | ---
|
25 | 20 |
|
26 | 21 | # What is Azure Active Directory recommendations (preview)?
|
27 | 22 |
|
28 | 23 | This feature is supported as part of a public preview. For more information about previews, see [Supplemental Terms of Use for Microsoft Azure Previews](https://azure.microsoft.com/support/legal/preview-supplemental-terms/).
|
29 | 24 |
|
30 |
| -Ideally, you want your Azure Active Directory (Azure AD) tenant to be in a secure and healthy state. However, trying to keep your knowledge regarding the management of the various components in your tenant up to date can become overwhelming. |
31 |
| - |
32 |
| -This is where Azure AD recommendations can help you. |
| 25 | +Keeping track of all the settings and resources in your tenant can be overwhelming. The Azure AD recommendations (preview) feature helps monitor the status of your tenant so you don't have to. Azure AD recommendations helps ensure your tenant is in a secure and healthy state while also helping you maximize the value of the features available in Azure AD. |
33 | 26 |
|
34 | 27 | The Azure AD recommendations feature provides you personalized insights with actionable guidance to:
|
35 | 28 |
|
36 | 29 | - Help you identify opportunities to implement best practices for Azure AD-related features.
|
37 | 30 | - Improve the state of your Azure AD tenant.
|
| 31 | +- Optimize the configurations for your scenarios. |
38 | 32 |
|
39 |
| -This article gives you an overview of how you can use Azure AD recommendations. |
40 |
| - |
41 |
| - |
| 33 | +This article gives you an overview of how you can use Azure AD recommendations. As an administrator, you should review your tenant's recommendations, and their associated resources periodically. |
42 | 34 |
|
43 | 35 | ## What it is
|
44 | 36 |
|
45 |
| -The [Azure Advisor](../../advisor/advisor-overview.md) is a personalized cloud consultant that helps you follow best practices to optimize your Azure deployments. It analyzes your resource configuration and usage telemetry and then recommends solutions that can help you improve the cost effectiveness, performance, Reliability (formerly called High availability), and security of your Azure resources. |
| 37 | +Azure AD recommendations is the Azure AD specific implementation of [Azure Advisor](../../advisor/advisor-overview.md), which is a personalized cloud consultant that helps you follow best practices to optimize your Azure deployments. Azure Advisor analyzes your resource configuration and usage telemetry to recommend solutions that can help you improve the cost effectiveness, performance, reliability, and security of your Azure resources. |
46 | 38 |
|
47 |
| -Azure AD recommendations: |
48 |
| - |
49 |
| -- Is the Azure AD specific implementation of Azure Advisor. |
50 |
| -- Supports you with the roll-out and management of Microsoft's best practices for Azure AD tenants to keep your tenant in a secure and healthy state. |
| 39 | +*Azure AD recommendations* uses similar data to support you with the roll-out and management of Microsoft's best practices for Azure AD tenants to keep your tenant in a secure and healthy state. Azure AD recommendations provide a holistic view into your tenant's security, health, and usage. |
51 | 40 |
|
52 |
| -## Recommendation object |
53 |
| - |
54 |
| -Azure AD tracks the status of a recommendation in a related object. This object includes attributes that are used to characterize the recommendation and a body to store the actionable guidance. |
55 |
| - |
56 |
| - |
57 |
| -Each object is characterized by: |
58 |
| - |
59 |
| -- **Title** - A short summary of what the recommendation is about. |
60 |
| - |
61 |
| -- **Priority** - Possible values are: low, medium, high |
62 |
| - |
63 |
| -- **Status** - Possible values are: Active, Dismissed, Postponed, CompletedByUser, CompletedBySystem. |
64 |
| - |
65 |
| - - A recommendation is marked as CompletedByUser if you mark the recommendation as complete. |
66 |
| - |
67 |
| - - A recommendation is marked as CompletedBySystem if a recommendation that did once apply is no longer applicable to you because you have taken the necessary steps. |
68 |
| - |
69 |
| - |
70 |
| -- **Impacted Resources** - A definition of the scope of a recommendation. Possible values are either a list of the impacted resources or **Tenant level**. |
71 |
| - |
72 |
| -- **Updated at** - The timestamp of the last status update. |
73 |
| - |
74 |
| - |
75 |
| - |
76 |
| - |
77 |
| - |
78 |
| - |
79 |
| -The body of a recommendation object contains the actionable guidance: |
80 |
| - |
81 |
| -- **Description** - An explanation of what it is that Azure AD has detected and related background information. |
82 |
| - |
83 |
| -- **Value** - An explanation of why completing the recommendation will benefit you, and the value of the associated feature. |
84 |
| - |
85 |
| -- **Action Plan** - Detailed instructions to step-by-step implement a recommendation. |
86 |
| - |
87 |
| - |
88 |
| - |
89 | 41 | ## How it works
|
90 | 42 |
|
91 |
| -On a daily basis, Azure AD analyzes the configuration of your tenant. During an analysis, Azure AD compares the data of the known recommendations with the actual configuration. If a recommendation is flagged as applicable to your tenant, the recommendation status and its corresponding resources are marked as active. |
92 |
| - |
93 |
| - |
94 |
| -In the recommendations or resource list, you can use the **Status** information to determine your action item. |
95 |
| - |
96 |
| -As an administrator, you should review your tenant's recommendations, and their associated resources periodically. |
97 |
| - |
98 |
| -- **Dismiss** |
99 |
| - |
100 |
| -- **Mark complete** |
101 |
| - |
102 |
| -- **Postpone** |
103 |
| - |
104 |
| -- **Reactivate** |
105 |
| - |
106 |
| - |
107 |
| -### Dismiss |
108 |
| - |
109 |
| -If you don't like a recommendation, or if you have another reason for not applying it, you can dismiss it. In this case, Azure AD asks you for a reason for dismissing a recommendation. |
110 |
| - |
111 |
| - |
112 |
| - |
| 43 | +On a daily basis, Azure AD analyzes the configuration of your tenant. During this analysis, Azure AD compares the data of a recommendation with the actual configuration of your tenant. If a recommendation is flagged as applicable to your tenant, the recommendation appears in the **Recommendations** section of the Azure AD Overview area. Recommendations are listed in order of priority so you can quickly determine where to focus first. |
113 | 44 |
|
114 |
| -### Mark as complete |
| 45 | +Recommendations contain a description, a summary of the value of addressing the recommendation, and a step-by-step action plan. If applicable, impacted resources that are associated with the recommendation are listed, so you can resolve each affected area. If a recommendation doesn't have any associated resources, the impacted resource type is *Tenant level*. so your step-by-step action plan impacts the entire tenant and not just a specific resource. |
115 | 46 |
|
116 |
| -Use this state to indicate that you have: |
| 47 | + |
117 | 48 |
|
118 |
| -- Completed the recommendation. |
119 |
| -- Taken action for an individual resource. |
| 49 | +## Recommendation details |
120 | 50 |
|
121 |
| -A recommendation or resource that has been marked as complete is again evaluated when Azure AD compares the available recommendations with your current configuration. |
| 51 | +Each recommendation provides the same set of details that explain what the recommendation is, why it's important, and how to fix it. |
122 | 52 |
|
| 53 | +The **Status** of a recommendation can be updated manually or automatically. If all resources are addressed according to the action plan, the status will automatically change to *Completed* the next time the recommendations service runs. The recommendation service runs every 24-48 hours, depending on the recommendation. |
123 | 54 |
|
124 |
| -### Postpone |
| 55 | + |
125 | 56 |
|
126 |
| -Postpone a recommendation or resource to address it in the future. The recommendation or resource will be marked as Active again when the date that the recommendation or resource is postponed to occurs. |
| 57 | +The **Priority** of a recommendation could be low, medium, or high. These values are determined by several factors, such as security implications, health concerns, or potential breaking changes. |
127 | 58 |
|
128 |
| -### Reactivate |
129 |
| -Accidentally dismissed, completed, or postponed a recommendation or resource. Mark it as active again to keep it top of mind. |
| 59 | + |
130 | 60 |
|
| 61 | +- **High**: Must do. Not acting will result in severe security implications or potential downtime. |
| 62 | +- **Medium**: Should do. No severe risk if action isn't taken. |
| 63 | +- **Low**: Might do. No security risks or health concerns if action isn't taken. |
131 | 64 |
|
132 |
| -## Common tasks |
| 65 | +The **Impacted resources** for a recommendation could be things like applications or users. This detail gives you an idea of what type of resources you'll need to address. The impacted resource could also be at the tenant level, so you may need to make a global change. |
133 | 66 |
|
134 |
| -### Enable recommendations |
| 67 | +The **Status description** tells you the date the recommendation status changed and if it was changed by the system or a user. |
135 | 68 |
|
136 |
| -To enable your Azure AD recommendations: |
| 69 | +The recommendation's **Value** is an explanation of why completing the recommendation will benefit you, and the value of the associated feature. |
137 | 70 |
|
138 |
| -1. Navigate to the **[Preview features](https://portal.azure.com/#blade/Microsoft_AAD_IAM/ActiveDirectoryMenuBlade/PreviewHub)** page. |
139 |
| -2. Set the **State** to **On**. |
| 71 | +The **Action plan** provides step-by-step instructions to implement a recommendation. May include links to relevant documentation or direct you to other pages in the Azure AD portal. |
140 | 72 |
|
141 |
| -  |
142 |
| - |
143 |
| - |
144 |
| - |
145 |
| -### Manage recommendations |
146 |
| - |
147 |
| -To manage your Azure AD recommendations: |
148 |
| - |
149 |
| -1. Navigate to the [Azure AD overview](https://portal.azure.com/#blade/Microsoft_AAD_IAM/ActiveDirectoryMenuBlade/Overview) page. |
150 |
| - |
151 |
| -2. On the Azure AD overview page, in the toolbar, click **Recommendations (Preview)**. |
152 |
| - |
153 |
| -  |
154 |
| - |
155 |
| - |
156 |
| - |
157 |
| -### Update the status of a resource |
158 |
| - |
159 |
| -To update the status of a resource, you have to right click a resource to bring up the edit menu. |
160 |
| - |
161 |
| - |
162 |
| -## Who can access it? |
| 73 | +## What you should know |
163 | 74 |
|
164 |
| -The Azure AD recommendations feature supports all editions of Azure AD. In other words, there is no specific subscription or license required to use this feature. |
| 75 | +The following roles provide *read-only* access to recommendations: |
165 | 76 |
|
166 |
| -To (re-) view your recommendations, you need to be: |
| 77 | +- Reports Reader |
| 78 | +- Security Reader |
| 79 | +- Global Reader |
167 | 80 |
|
168 |
| -- Global reader |
| 81 | +The following roles provide *update and read-only* access to recommendations: |
169 | 82 |
|
170 |
| -- Security reader |
| 83 | +- Global Administrator |
| 84 | +- Security Administrator |
| 85 | +- Security Operator |
| 86 | +- Cloud apps Administrator |
| 87 | +- Apps Administrator |
171 | 88 |
|
172 |
| -- Reports reader |
| 89 | +Any role can enable the Azure AD recommendations preview, but you'll need one of the roles listed above to view or update recommendations. Azure AD only displays the recommendations that apply to your tenant, so you may not see all supported recommendations listed. |
173 | 90 |
|
| 91 | +Some recommendations have a list of impacted resources associated. This list of resources gives you more context on how the recommendation applies to you and/or which resources you need to address. The only action recorded in the audit log is completing recommendations. Actions taken on a recommendation are collected in the audit log. To view these logs, go to **Azure AD** > **Audit logs** and filter the service to "Azure AD recommendations." |
174 | 92 |
|
175 |
| -To manage your recommendations, you need to be: |
| 93 | +The table below provides the impacted resources and links available documentation. |
176 | 94 |
|
177 |
| -- Global admin |
| 95 | +| Recommendation | Impacted resources | |
| 96 | +|---- |---- | |
| 97 | +| [Convert per-user MFA to Conditional Access MFA](recommendation-turn-off-per-user-mfa.md) | Users | |
| 98 | +| [Integrate 3rd party applications](recommendation-integrate-third-party-apps.md) | Tenant level | |
| 99 | +| [Migrate applications from AD FS to Azure AD](recommendation-migrate-apps-from-adfs-to-azure-ad.md) | Users | |
| 100 | +| [Migrate to Microsoft Authenticator](recommendation-migrate-to-authenticator.md) | Users | |
| 101 | +| [Minimize MFA prompts from known devices](recommendation-migrate-apps-from-adfs-to-azure-ad.md) | Users | |
178 | 102 |
|
179 |
| -- Security admin |
| 103 | +## How to access Azure AD recommendations (preview) |
180 | 104 |
|
181 |
| -- Security operator |
| 105 | +To enable the Azure AD recommendations preview: |
182 | 106 |
|
183 |
| -- Cloud app admin |
| 107 | +1. Sign in to the [Azure portal](https://portal.azure.com/). |
184 | 108 |
|
185 |
| -- App admin |
| 109 | +1. Go to **Azure AD** > **Preview features** and enable **Azure AD recommendations.** |
| 110 | + - Recommendations may take a few minutes to sync. |
| 111 | + - While anyone can enable the preview feature, you'll need a [specific role](overview-recommendations.md#what-you-should-know) to view or update a recommendation. |
186 | 112 |
|
| 113 | +  |
187 | 114 |
|
| 115 | +After the preview is enabled, you can view the available recommendations from the Azure AD administration portal. The Azure AD recommendations feature appears on the **Overview** page of your tenant. |
188 | 116 |
|
| 117 | +## How to use Azure AD recommendations (preview) |
189 | 118 |
|
190 |
| -## What you should know |
| 119 | +1. Go to **Azure AD** > **Recommendations**. |
191 | 120 |
|
192 |
| -- On the recommendations page, you might not see all supported recommendations. This is because Azure AD only displays the recommendations that apply to your tenant. |
| 121 | +1. Select a recommendation from the list to view the details, status, and action plan. |
193 | 122 |
|
194 |
| -- Some recommendations have a list of impacted resources associated. This list of resources gives you more context on how the recommendation applies to you and/or which resources you need to address. |
| 123 | +  |
195 | 124 |
|
196 |
| -**Right now:** |
| 125 | +1. Follow the **Action plan**. |
197 | 126 |
|
198 |
| -- You can update the status of a recommendation with a read only roles (global reader, security reader, reports reader). This is a known issue that will be fixed. |
| 127 | +1. If applicable, right-click on a resource in a recommendation, select **Mark as**, then select a status. |
199 | 128 |
|
200 |
| -- The only action recorded in the audit log is completing recommendations. |
| 129 | +  |
201 | 130 |
|
202 |
| -- Audit logs do not capture actions taken by reader roles. |
| 131 | +1. If you need to manually change the status of a recommendation, select **Mark as** from the top of the page and select a status. |
203 | 132 |
|
| 133 | + - Mark a recommendation as **Completed** if all impacted resources have been addressed. |
| 134 | + - Active resources may still appear in the list of resources for manually completed recommendations. If the resource is completed, the service will update the status the next time the service runs. |
| 135 | + - If the service identifies an active resource for a manually completed recommendation the next time the service runs, the recommendation will automatically change back to **Active**. |
| 136 | + - Mark a recommendation as **Dismissed** if you think the recommendation is irrelevant or the data is wrong. |
| 137 | + - Azure AD will ask for a reason why you dismissed the recommendation so we can improve the service. |
| 138 | + - Mark a recommendation as **Postponed** if you want to address the recommendation at a later time. |
| 139 | + - The recommendation will become **Active** when the selected date occurs. |
| 140 | + - You can reactivate a completed or postponed recommendation to keep it top of mind and reassess the resources. |
204 | 141 |
|
| 142 | +Continue to monitor the recommendations in your tenant for changes. |
205 | 143 |
|
206 | 144 | ## Next steps
|
207 | 145 |
|
|
0 commit comments