Skip to content

Commit 10f51f7

Browse files
authored
Merge pull request #95824 from MicrosoftGuyJFlo/Cleanup
[Azure AD] Post-ignite cleanup
2 parents b04f51c + aa713d8 commit 10f51f7

File tree

5 files changed

+13
-15
lines changed

5 files changed

+13
-15
lines changed

articles/active-directory/authentication/TOC.yml

Lines changed: 0 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -139,8 +139,6 @@
139139
href: howto-authentication-passwordless-security-key.md
140140
- name: Passwordless Windows 10
141141
href: howto-authentication-passwordless-security-key-windows.md
142-
- name: Passwordless on-premises
143-
href: howto-authentication-passwordless-security-key-on-premises.md
144142
- name: Passwordless phone sign-in
145143
href: howto-authentication-passwordless-phone.md
146144
- name: Windows Hello for Business

articles/active-directory/authentication/howto-mfa-mfasettings.md

Lines changed: 10 additions & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -19,7 +19,7 @@ ms.collection: M365-identity-device-management
1919

2020
This article helps you to manage Multi-Factor Authentication settings in the Azure portal. It covers various topics that help you to get the most out of Azure Multi-Factor Authentication. Not all of the features are available in every version of Azure Multi-Factor Authentication.
2121

22-
You can access settings related to Azure Multi-Factor Authentication from the Azure portal by browsing to **Azure Active Directory** > **MFA**.
22+
You can access settings related to Azure Multi-Factor Authentication from the Azure portal by browsing to **Azure Active Directory** > **Security** > **MFA**.
2323

2424
![Azure portal - Azure AD Multi-Factor Authentication settings](./media/howto-mfa-mfasettings/multi-factor-authentication-settings-portal.png)
2525

@@ -59,15 +59,15 @@ Use the _block and unblock users_ feature to prevent users from receiving authen
5959
### Block a user
6060

6161
1. Sign in to the [Azure portal](https://portal.azure.com) as an administrator.
62-
2. Browse to **Azure Active Directory** > **MFA** > **Block/unblock users**.
62+
2. Browse to **Azure Active Directory** > **Security** > **MFA** > **Block/unblock users**.
6363
3. Select **Add** to block a user.
6464
4. Select the **Replication Group**. Enter the username for the blocked user as **username\@domain.com**. Enter a comment in the **Reason** field.
6565
5. Select **Add** to finish blocking the user.
6666

6767
### Unblock a user
6868

6969
1. Sign in to the [Azure portal](https://portal.azure.com) as an administrator.
70-
2. Browse to **Azure Active Directory** > **MFA** > **Block/unblock users**.
70+
2. Browse to **Azure Active Directory** > **Security** > **MFA** > **Block/unblock users**.
7171
3. Select **Unblock** in the **Action** column next to the user to unblock.
7272
4. Enter a comment in the **Reason for unblocking** field.
7373
5. Select **Unblock** to finish unblocking the user.
@@ -79,7 +79,7 @@ Configure the _fraud alert_ feature so that your users can report fraudulent att
7979
### Turn on fraud alerts
8080

8181
1. Sign in to the [Azure portal](https://portal.azure.com) as an administrator.
82-
2. Browse to **Azure Active Directory** > **MFA** > **Fraud alert**.
82+
2. Browse to **Azure Active Directory** > **Security** > **MFA** > **Fraud alert**.
8383
3. Set the **Allow users to submit fraud alerts** setting to **On**.
8484
4. Select **Save**.
8585

@@ -121,7 +121,7 @@ You can use your own recordings or greetings for two-step verification with the
121121
Before you begin, be aware of the following restrictions:
122122

123123
* The supported file formats are .wav and .mp3.
124-
* The file size limit is 5 MB.
124+
* The file size limit is 1 MB.
125125
* Authentication messages should be shorter than 20 seconds. Messages that are longer than 20 seconds can cause the verification to fail. The user might not respond before the message finishes and the verification times out.
126126

127127
### Custom message language behavior
@@ -142,7 +142,7 @@ For example, if there is only one custom message, with a language of German:
142142
### Set up a custom message
143143

144144
1. Sign in to the [Azure portal](https://portal.azure.com) as an administrator.
145-
1. Browse to **Azure Active Directory** > **MFA** > **Phone call settings**.
145+
1. Browse to **Azure Active Directory** > **Security** > **MFA** > **Phone call settings**.
146146
1. Select **Add greeting**.
147147
1. Choose the type of greeting.
148148
1. Choose the language.
@@ -181,7 +181,7 @@ The _one-time bypass_ feature allows a user to authenticate a single time withou
181181
### Create a one-time bypass
182182

183183
1. Sign in to the [Azure portal](https://portal.azure.com) as an administrator.
184-
2. Browse to **Azure Active Directory** > **MFA** > **One-time bypass**.
184+
2. Browse to **Azure Active Directory** > **Security** > **MFA** > **One-time bypass**.
185185
3. Select **Add**.
186186
4. If necessary, select the replication group for the bypass.
187187
5. Enter the username as **username\@domain.com**. Enter the number of seconds that the bypass should last. Enter the reason for the bypass.
@@ -190,7 +190,7 @@ The _one-time bypass_ feature allows a user to authenticate a single time withou
190190
### View the one-time bypass report
191191

192192
1. Sign in to the [Azure portal](https://portal.azure.com).
193-
2. Browse to **Azure Active Directory** > **MFA** > **One-time bypass**.
193+
2. Browse to **Azure Active Directory** > **Security** > **MFA** > **One-time bypass**.
194194

195195
## Caching rules
196196

@@ -202,15 +202,15 @@ You can set a time period to allow authentication attempts after a user is authe
202202
### Set up caching
203203

204204
1. Sign in to the [Azure portal](https://portal.azure.com) as an administrator.
205-
2. Browse to **Azure Active Directory** > **MFA** > **Caching rules**.
205+
2. Browse to **Azure Active Directory** > **Security** > **MFA** > **Caching rules**.
206206
3. Select **Add**.
207207
4. Select the **cache type** from the drop-down list. Enter the maximum number of **cache seconds**.
208208
5. If necessary, select an authentication type and specify an application.
209209
6. Select **Add**.
210210

211211
## MFA service settings
212212

213-
Settings for app passwords, trusted IPs, verification options, and remember multi-factor authentication for Azure Multi-Factor Authentication can be found in service settings. Service settings can be accessed from the Azure portal by browsing to **Azure Active Directory** > **MFA** > **Getting started** > **Configure** > **Additional cloud-based MFA settings**.
213+
Settings for app passwords, trusted IPs, verification options, and remember multi-factor authentication for Azure Multi-Factor Authentication can be found in service settings. Service settings can be accessed from the Azure portal by browsing to **Azure Active Directory** > **Security** > **MFA** > **Getting started** > **Configure** > **Additional cloud-based MFA settings**.
214214

215215
![Azure Multi-Factor Authentication service settings](./media/howto-mfa-mfasettings/multi-factor-authentication-settings-service-settings.png)
216216

Loading

articles/active-directory/conditional-access/location-condition.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -48,7 +48,7 @@ A named location has the following components:
4848
- **IP ranges** - One or more IPv4 address ranges in CIDR format. Specifying an IPv6 address range is not supported.
4949

5050
> [!NOTE]
51-
> IPv6 address rangess cannot currently be included in a named location. This measn IPv6 ranges cannot be excluded from a Conditional Access policy.
51+
> IPv6 address ranges cannot currently be included in a named location. This means IPv6 ranges cannot be excluded from a Conditional Access policy.
5252
5353
- **Mark as trusted location** - A flag you can set for a named location to indicate a trusted location. Typically, trusted locations are network areas that are controlled by your IT department. In addition to Conditional Access, trusted named locations are also used by Azure Identity Protection and Azure AD security reports to reduce [false positives](../reports-monitoring/concept-risk-events.md#impossible-travel-to-atypical-locations-1).
5454
- **Countries/Regions** - This option enables you to select one or more country or region to define a named location.

articles/active-directory/devices/hybrid-azuread-join-control.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -30,7 +30,7 @@ To do a controlled validation of hybrid Azure AD join on Windows current devices
3030
1. Clear the Service Connection Point (SCP) entry from Active Directory (AD) if it exists
3131
1. Configure client-side registry setting for SCP on your domain-joined computers using a Group Policy Object (GPO)
3232
1. If you are using AD FS, you must also configure the client-side registry setting for SCP on your AD FS server using a GPO
33-
33+
1. You may also need to [customize synchronization options](../hybrid/how-to-connect-post-installation.md#additional-tasks-available-in-azure-ad-connect) in Azure AD Connect to enable device synchronization.
3434

3535

3636
### Clear the SCP from AD
@@ -79,7 +79,7 @@ Use the following example to create a Group Policy Object (GPO) to deploy a regi
7979
If you are using AD FS, you first need to configure client-side SCP using the instructions mentioned above but linking the GPO to your AD FS servers. The SCP object defines the source of authority for device objects. It can be on-premises or Azure AD. When this is configured for AD FS, the source for device objects is established as Azure AD.
8080

8181
> [!NOTE]
82-
> If you failed to configure client-side SCP on your AD FS servers, the source for device identities would be considered as on-premises, and if you have device writeback, AD FS would start deleting device objects from on-premises registered device container after a stipulated period.
82+
> If you failed to configure client-side SCP on your AD FS servers, the source for device identities would be considered as on-premises. ADFS will then start deleting device objects from on-premises directory after the stipulated period defined in the ADFS Device Registration's attribute "MaximumInactiveDays". ADFS Device Registration objects can be found using the [Get-AdfsDeviceRegistration cmdlet](https://docs.microsoft.com/powershell/module/adfs/get-adfsdeviceregistration?view=win10-ps).
8383
8484
## Controlled validation of hybrid Azure AD join on Windows down-level devices
8585

0 commit comments

Comments
 (0)