You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
*Data Use Management* (DUM) is an option within the data source registration in Microsoft Purview. This option lets Microsoft Purview manage data access for your resources. The high level concept is that the data owner allows its data resource to be available for access policies by enabling *DUM*.
17
+
*Data use management* (DUM) is an option within the data source registration in Microsoft Purview. This option lets Microsoft Purview manage data access for your resources. The high level concept is that the data owner allows its data resource to be available for access policies by enabling *DUM*.
18
18
19
19
Currently, a data owner can enable DUM on a data resource for these types of access policies:
20
20
@@ -24,68 +24,68 @@ Currently, a data owner can enable DUM on a data resource for these types of acc
24
24
To be able to create any data policy on a resource, DUM must first be enabled on that resource. This article will explain how to enable DUM on your resources in Microsoft Purview.
25
25
26
26
>[!IMPORTANT]
27
-
>Because Data Use Management directly affects access to your data, it directly affects your data security. Review [**additional considerations**](#additional-considerations-related-to-data-use-management) and [**best practices**](#data-use-management-best-practices) below before enabling DUM in your environment.
27
+
>Because Data use management directly affects access to your data, it directly affects your data security. Review [**additional considerations**](#additional-considerations-related-to-data-use-management) and [**best practices**](#data-use-management-best-practices) below before enabling DUM in your environment.
To enable *Data Use Management* for a resource, the resource will first need to be registered in Microsoft Purview.
34
+
To enable *Data use management* for a resource, the resource will first need to be registered in Microsoft Purview.
35
35
To register a resource, follow the **Prerequisites** and **Register** sections of the [source pages](azure-purview-connector-overview.md) for your resources.
36
36
37
-
Once you have your resource registered, follow the rest of the steps to enable an individual resource for *Data Use Management*.
37
+
Once you have your resource registered, follow the rest of the steps to enable an individual resource for *Data use management*.
38
38
39
39
1. Go to the [Microsoft Purview governance portal](https://web.purview.azure.com/resource/).
40
40
41
41
1. Select the **Data map** tab in the left menu.
42
42
43
43
1. Select the **Sources** tab in the left menu.
44
44
45
-
1. Select the source where you want to enable *Data Use Management*.
45
+
1. Select the source where you want to enable *Data use management*.
46
46
47
47
1. At the top of the source page, select **Edit source**.
48
48
49
-
1. Set the *Data Use Management* toggle to **Enabled**, as shown in the image below.
49
+
1. Set the *Data use management* toggle to **Enabled**, as shown in the image below.
50
50
51
-
:::image type="content" source="./media/tutorial-data-owner-policies-storage/register-data-source-for-policy-storage.png" alt-text="Set Data Use Management toggle to **Enabled** at the bottom of the menu.":::
51
+
:::image type="content" source="./media/tutorial-data-owner-policies-storage/register-data-source-for-policy-storage.png" alt-text="Set Data use management toggle to **Enabled** at the bottom of the menu.":::
52
52
53
-
## Disable Data Use Management
53
+
## Disable Data use management
54
54
55
-
To disable Data Use Management for a source, resource group, or subscription, a user needs to either be a resource IAM **Owner** or a Microsoft Purview **Data source admin**. Once you have those permissions follow these steps:
55
+
To disable Data use management for a source, resource group, or subscription, a user needs to either be a resource IAM **Owner** or a Microsoft Purview **Data source admin**. Once you have those permissions follow these steps:
56
56
57
57
1. Go to the [Microsoft Purview governance portal](https://web.purview.azure.com/resource/).
58
58
59
59
1. Select the **Data map** tab in the left menu.
60
60
61
61
1. Select the **Sources** tab in the left menu.
62
62
63
-
1. Select the source you want to disable Data Use Management for.
63
+
1. Select the source you want to disable Data use management for.
64
64
65
65
1. At the top of the source page, select **Edit source**.
66
66
67
-
1. Set the **Data Use Management** toggle to **Disabled**.
67
+
1. Set the **Data use management** toggle to **Disabled**.
68
68
69
-
## Additional considerations related to Data Use Management
69
+
## Additional considerations related to Data use management
70
70
- Make sure you write down the **Name** you use when registering in Microsoft Purview. You will need it when you publish a policy. The recommended practice is to make the registered name exactly the same as the endpoint name.
71
-
- To disable a source for *Data Use Management*, remove it first from being bound (i.e. published) in any policy.
72
-
- While user needs to have both data source *Owner* and Microsoft Purview *Data source admin* to enable a source for *Data Use Management*, either of those roles can independently disable it.
73
-
- Disabling *Data Use Management* for a subscription will disable it also for all assets registered in that subscription.
71
+
- To disable a source for *Data use management*, remove it first from being bound (i.e. published) in any policy.
72
+
- While user needs to have both data source *Owner* and Microsoft Purview *Data source admin* to enable a source for *Data use management*, either of those roles can independently disable it.
73
+
- Disabling *Data use management* for a subscription will disable it also for all assets registered in that subscription.
74
74
75
75
> [!WARNING]
76
76
> **Known issues** related to source registration
77
77
> - Moving data sources to a different resource group or subscription is not supported. If want to do that, de-register the data source in Microsoft Purview before moving it and then register it again after that happens. Note that policies are bound to the data source ARM path. Changing the data source subscription or resource group makes policies ineffective.
78
-
> - Once a subscription gets disabled for *Data Use Management* any underlying assets that are enabled for *Data Use Management* will be disabled, which is the right behavior. However, policy statements based on those assets will still be allowed after that.
78
+
> - Once a subscription gets disabled for *Data use management* any underlying assets that are enabled for *Data use management* will be disabled, which is the right behavior. However, policy statements based on those assets will still be allowed after that.
79
79
80
-
## Data Use Management best practices
81
-
- We highly encourage registering data sources for *Data Use Management* and managing all associated access policies in a single Microsoft Purview account.
82
-
- Should you have multiple Microsoft Purview accounts, be aware that **all** data sources belonging to a subscription must be registered for *Data Use Management* in a single Microsoft Purview account. That Microsoft Purview account can be in any subscription in the tenant. The *Data Use Management* toggle will become greyed out when there are invalid configurations. Some examples of valid and invalid configurations follow in the diagram below:
80
+
## Data use management best practices
81
+
- We highly encourage registering data sources for *Data use management* and managing all associated access policies in a single Microsoft Purview account.
82
+
- Should you have multiple Microsoft Purview accounts, be aware that **all** data sources belonging to a subscription must be registered for *Data use management* in a single Microsoft Purview account. That Microsoft Purview account can be in any subscription in the tenant. The *Data use management* toggle will become greyed out when there are invalid configurations. Some examples of valid and invalid configurations follow in the diagram below:
83
83
-**Case 1** shows a valid configuration where a Storage account is registered in a Microsoft Purview account in the same subscription.
84
84
-**Case 2** shows a valid configuration where a Storage account is registered in a Microsoft Purview account in a different subscription.
85
-
-**Case 3** shows an invalid configuration arising because Storage accounts S3SA1 and S3SA2 both belong to Subscription 3, but are registered to different Microsoft Purview accounts. In that case, the *Data Use Management* toggle will only enable in the Microsoft Purview account that wins and registers a data source in that subscription first. The toggle will then be greyed out for the other data source.
86
-
- If the *Data Use Management* toggle is greyed out and cannot be enabled, hover over it to know the name of the Microsoft Purview account that has registered the data resource first.
85
+
-**Case 3** shows an invalid configuration arising because Storage accounts S3SA1 and S3SA2 both belong to Subscription 3, but are registered to different Microsoft Purview accounts. In that case, the *Data use management* toggle will only enable in the Microsoft Purview account that wins and registers a data source in that subscription first. The toggle will then be greyed out for the other data source.
86
+
- If the *Data use management* toggle is greyed out and cannot be enabled, hover over it to know the name of the Microsoft Purview account that has registered the data resource first.
87
87
88
-

88
+

Copy file name to clipboardExpand all lines: articles/purview/how-to-policies-data-owner-authoring-generic.md
+13-13Lines changed: 13 additions & 13 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -7,7 +7,7 @@ ms.service: purview
7
7
ms.subservice: purview-data-policies
8
8
ms.custom: event-tier1-build-2022
9
9
ms.topic: how-to
10
-
ms.date: 05/27/2022
10
+
ms.date: 08/22/2022
11
11
---
12
12
13
13
# Authoring and publishing data owner access policies (Preview)
@@ -28,26 +28,26 @@ Before authoring data policies in the Microsoft Purview governance portal, you'l
28
28
29
29
1. Follow any policy-specific prerequisites for your source. Check the [Microsoft Purview supported data sources table](microsoft-purview-connector-overview.md) and select the link in the **Access Policy** column for sources where access policies are available. Follow any steps listed in the Access policy or Prerequisites sections.
30
30
1. Register the data source in Microsoft Purview. Follow the **Prerequisites** and **Register** sections of the [source pages](microsoft-purview-connector-overview.md) for your resources.
31
-
1.[Enable the Data Use Management toggle on the data source](how-to-enable-data-use-management.md#enable-data-use-management). Additional permissions for this step are described in the linked document.
31
+
1.[Enable the Data use management toggle on the data source](how-to-enable-data-use-management.md#enable-data-use-management). Additional permissions for this step are described in the linked document.
32
32
33
33
## Create a new policy
34
34
35
35
This section describes the steps to create a new policy in Microsoft Purview.
36
-
Ensure you have the *Policy Author* permission as described [here](#permissions-for-policy-authoring-and-publishing)
36
+
Ensure you have the *Policy Author* permission as described [here](#permissions-for-policy-authoring-and-publishing).
37
37
38
38
1. Sign in to the [Microsoft Purview governance portal](https://web.purview.azure.com/resource/).
39
39
40
40
1. Navigate to the **Data policy** feature using the left side panel. Then select **Data policies**.
41
41
42
42
1. Select the **New Policy** button in the policy page.
43
43
44
-
:::image type="content" source="./media/access-policies-common/policy-onboard-guide-1.png" alt-text="Data owner can access the Policy functionality in Microsoft Purview when it wants to create policies.":::
44
+
:::image type="content" source="./media/how-to-policies-data-owner-authoring-generic/policy-onboard-guide-1.png" alt-text="Screenshot showing data owner can access the Policy functionality in Microsoft Purview when it wants to create policies.":::
45
45
46
46
1. The new policy page will appear. Enter the policy **Name** and **Description**.
47
47
48
48
1. To add policy statements to the new policy, select the **New policy statement** button. This will bring up the policy statement builder.
49
49
50
-
:::image type="content" source="./media/access-policies-common/create-new-policy.png" alt-text="Data owner can create a new policy statement.":::
50
+
:::image type="content" source="./media/how-to-policies-data-owner-authoring-generic/create-new-policy.png" alt-text="Screenshot showing data owner can create a new policy statement.":::
51
51
52
52
1. Select the **Effect** button and choose *Allow* from the drop-down list.
53
53
@@ -59,15 +59,15 @@ Ensure you have the *Policy Author* permission as described [here](#permissions-
59
59
- To create a broad policy statement that covers an entire data source, resource group, or subscription that was previously registered, use the **Data sources** box and select its **Type**.
60
60
- To create a fine-grained policy, use the **Assets** box instead. Enter the **Data Source Type** and the **Name** of a previously registered and scanned data source. See example in the image.
61
61
62
-
:::image type="content" source="./media/access-policies-common/select-data-source-type.png" alt-text="Data owner can select a Data Resource when editing a policy statement.":::
62
+
:::image type="content" source="./media/how-to-policies-data-owner-authoring-generic/select-data-source-type.png" alt-text="Screenshot showing data owner can select a Data Resource when editing a policy statement.":::
63
63
64
64
1. Select the **Continue** button and transverse the hierarchy to select and underlying data-object (for example: folder, file, etc.). Select **Recursive** to apply the policy from that point in the hierarchy down to any child data-objects. Then select the **Add** button. This will take you back to the policy editor.
65
65
66
-
:::image type="content" source="./media/access-policies-common/select-asset.png" alt-text="Data owner can select the asset when creating or editing a policy statement.":::
66
+
:::image type="content" source="./media/how-to-policies-data-owner-authoring-generic/select-asset.png" alt-text="Screenshot showing data owner can select the asset when creating or editing a policy statement.":::
67
67
68
68
1. Select the **Subjects** button and enter the subject identity as a principal, group, or MSI. Then select the **OK** button. This will take you back to the policy editor
69
69
70
-
:::image type="content" source="./media/access-policies-common/select-subject.png" alt-text="Data owner can select the subject when creating or editing a policy statement.":::
70
+
:::image type="content" source="./media/how-to-policies-data-owner-authoring-generic/select-subject.png" alt-text="Screenshot showing data owner can select the subject when creating or editing a policy statement.":::
71
71
72
72
1. Repeat the steps #5 to #11 to enter any more policy statements.
73
73
@@ -86,15 +86,15 @@ The steps to publish a policy are as follows:
86
86
87
87
1. Navigate to the **Data policy** feature using the left side panel. Then select **Data policies**.
88
88
89
-
:::image type="content" source="./media/access-policies-common/policy-onboard-guide-2.png" alt-text="Data owner can access the Policy functionality in Microsoft Purview when it wants to update a policy by selecting 'Data policies'.":::
89
+
:::image type="content" source="./media/how-to-policies-data-owner-authoring-generic/policy-onboard-guide-2.png" alt-text="Screenshot showing data owner can access the Policy functionality in Microsoft Purview when it wants to update a policy by selecting Data policies.":::
90
90
91
91
1. The Policy portal will present the list of existing policies in Microsoft Purview. Locate the policy that needs to be published. Select the **Publish** button on the right top corner of the page.
92
92
93
-
:::image type="content" source="./media/access-policies-common/publish-policy.png" alt-text="Data owner can publish a policy.":::
93
+
:::image type="content" source="./media/how-to-policies-data-owner-authoring-generic/publish-policy.png" alt-text="Screenshot showing data owner can publish a policy.":::
94
94
95
95
1. A list of data sources is displayed. You can enter a name to filter the list. Then, select each data source where this policy is to be published and then select the **Publish** button.
96
96
97
-
:::image type="content" source="./media/access-policies-common/select-data-sources-publish-policy.png" alt-text="Data owner can select the data source where the policy will be published.":::
97
+
:::image type="content" source="./media/how-to-policies-data-owner-authoring-generic/select-data-sources-publish-policy.png" alt-text="Screenshot showing data owner can select the data source where the policy will be published.":::
98
98
99
99
>[!Note]
100
100
> After making changes to a policy, there is no need to publish it again for it to take effect if the data source(s) continues to be the same.
@@ -108,13 +108,13 @@ Ensure you have the *Policy Author* permission as described [here](#permissions-
108
108
109
109
1. Navigate to the **Data policy** feature using the left side panel. Then select **Data policies**.
110
110
111
-
:::image type="content" source="./media/access-policies-common/policy-onboard-guide-2.png" alt-text="Data owner can access the Policy functionality in Microsoft Purview when it wants to update a policy.":::
111
+
:::image type="content" source="./media/how-to-policies-data-owner-authoring-generic/policy-onboard-guide-2.png" alt-text="Screenshot showing data owner can access the Policy functionality in Microsoft Purview when it wants to update a policy.":::
112
112
113
113
1. The Policy portal will present the list of existing policies in Microsoft Purview. Select the policy that needs to be updated.
114
114
115
115
1. The policy details page will appear, including Edit and Delete options. Select the **Edit** button, which brings up the policy statement builder. Now, any parts of the statements in this policy can be updated. To delete the policy, use the **Delete** button.
116
116
117
-
:::image type="content" source="./media/access-policies-common/edit-policy.png" alt-text="Data owner can edit or delete a policy statement.":::
117
+
:::image type="content" source="./media/how-to-policies-data-owner-authoring-generic/edit-policy.png" alt-text="Screenshot showing data owner can edit or delete a policy statement.":::
0 commit comments