Skip to content

Commit 2f3147a

Browse files
committed
Merge branch 'tamram22-0719' of https://github.com/tamram/azure-docs-pr; branch 'main' of https://github.com/MicrosoftDocs/azure-docs-pr into tamram22-0719
2 parents 277d639 + 553d533 commit 2f3147a

File tree

117 files changed

+1072
-662
lines changed

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

117 files changed

+1072
-662
lines changed

articles/active-directory-b2c/configure-authentication-sample-react-spa-app.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -171,7 +171,7 @@ In the sample folder, open the *config.json* file. This file contains informatio
171171

172172
|Section |Key |Value |
173173
|---------|---------|---------|
174-
|credentials|tenantName| The first part of your Azure AD B2C [tenant name](tenant-management.md#get-your-tenant-name). For example: `contoso`.|
174+
|credentials|tenantName| Your Azure AD B2C [domain/tenant name](tenant-management.md#get-your-tenant-name). For example: `contoso.ommicrosoft.com`.|
175175
|credentials|clientID| The web API application ID from step [2.1](#21-register-the-web-api-application). In the [earlier diagram](#app-registration), it's the application with **App ID: 2**.|
176176
|credentials| issuer| (Optional) The token issuer `iss` claim value. Azure AD B2C by default returns the token in the following format: `https://<your-tenant-name>.b2clogin.com/<your-tenant-ID>/v2.0/`. Replace `<your-tenant-name>` with the first part of your Azure AD B2C [tenant name](tenant-management.md#get-your-tenant-name). Replace `<your-tenant-ID>` with your [Azure AD B2C tenant ID](tenant-management.md#get-your-tenant-id). |
177177
|policies|policyName|The user flow or custom policy that you created in [step 1](#step-1-configure-your-user-flow). If your application uses multiple user flows or custom policies, specify only one. For example, use the sign-up or sign-in user flow.|

articles/active-directory/develop/scenario-web-api-call-api-app-configuration.md

Lines changed: 24 additions & 48 deletions
Original file line numberDiff line numberDiff line change
@@ -81,27 +81,19 @@ Instead of a client secret, you can provide a client certificate. The following
8181

8282
Microsoft.Identity.Web provides several ways to describe certificates, both by configuration or by code. For details, see [Microsoft.Identity.Web wiki - Using certificates](https://github.com/AzureAD/microsoft-identity-web/wiki/Using-certificates) on GitHub.
8383

84-
## Startup.cs
84+
## Program.cs
8585

86-
Your web API will need to acquire a token for the downstream API. You specify it by adding the `.EnableTokenAcquisitionToCallDownstreamApi()` line after `.AddMicrosoftIdentityWebApi(Configuration)`. This line exposes the `ITokenAcquisition` service, that you can use in your controller/pages actions. However, as you'll see in the next two bullet points, you can do even simpler. You'll also need to choose a token cache implementation, for example `.AddInMemoryTokenCaches()`, in *Startup.cs*:
86+
Your web API will need to acquire a token for the downstream API. You specify it by adding the `.EnableTokenAcquisitionToCallDownstreamApi()` line after `.AddMicrosoftIdentityWebApi(Configuration)`. This line exposes the `ITokenAcquisition` service, that you can use in your controller/pages actions. However, as you'll see in the next two bullet points, you can do even simpler. You'll also need to choose a token cache implementation, for example `.AddInMemoryTokenCaches()`, in *Program.cs*. If you use ASP.NET Core 3.1 or 5.0 the code will be similar but in the *Startup.cs* file.
8787

8888
```csharp
8989
using Microsoft.Identity.Web;
9090

91-
public class Startup
92-
{
93-
// ...
94-
public void ConfigureServices(IServiceCollection services)
95-
{
96-
// ...
97-
services.AddAuthentication(JwtBearerDefaults.AuthenticationScheme)
98-
.AddMicrosoftIdentityWebApi(Configuration, Configuration.GetSection("AzureAd"))
99-
.EnableTokenAcquisitionToCallDownstreamApi()
100-
.AddInMemoryTokenCaches();
101-
// ...
102-
}
103-
// ...
104-
}
91+
// ...
92+
builder.Services.AddAuthentication(JwtBearerDefaults.AuthenticationScheme)
93+
.AddMicrosoftIdentityWebApi(Configuration, Configuration.GetSection("AzureAd"))
94+
.EnableTokenAcquisitionToCallDownstreamApi()
95+
.AddInMemoryTokenCaches();
96+
// ...
10597
```
10698

10799
If you don't want to acquire the token yourself, *Microsoft.Identity.Web* provides two mechanisms for calling a downstream web API from another API. The option you choose depends on whether you want to call Microsoft Graph or another API.
@@ -111,26 +103,18 @@ If you don't want to acquire the token yourself, *Microsoft.Identity.Web* provid
111103
If you want to call Microsoft Graph, Microsoft.Identity.Web enables you to directly use the `GraphServiceClient` (exposed by the Microsoft Graph SDK) in your API actions. To expose Microsoft Graph:
112104

113105
1. Add the [Microsoft.Identity.Web.MicrosoftGraph](https://www.nuget.org/packages/Microsoft.Identity.Web.MicrosoftGraph) NuGet package to your project.
114-
1. Add `.AddMicrosoftGraph()` after `.EnableTokenAcquisitionToCallDownstreamApi()` in the *Startup.cs* file. `.AddMicrosoftGraph()` has several overrides. Using the override that takes a configuration section as a parameter, the code becomes:
106+
1. Add `.AddMicrosoftGraph()` after `.EnableTokenAcquisitionToCallDownstreamApi()` in the *Program.cs* file. `.AddMicrosoftGraph()` has several overrides. Using the override that takes a configuration section as a parameter, the code becomes:
115107

116108
```csharp
117109
using Microsoft.Identity.Web;
118110

119-
public class Startup
120-
{
121-
// ...
122-
public void ConfigureServices(IServiceCollection services)
123-
{
124-
// ...
125-
services.AddAuthentication(JwtBearerDefaults.AuthenticationScheme)
126-
.AddMicrosoftIdentityWebApi(Configuration, Configuration.GetSection("AzureAd"))
127-
.EnableTokenAcquisitionToCallDownstreamApi()
128-
.AddMicrosoftGraph(Configuration.GetSection("GraphBeta"))
129-
.AddInMemoryTokenCaches();
130-
// ...
131-
}
132-
// ...
133-
}
111+
// ...
112+
builder.Services.AddAuthentication(JwtBearerDefaults.AuthenticationScheme)
113+
.AddMicrosoftIdentityWebApi(Configuration, Configuration.GetSection("AzureAd"))
114+
.EnableTokenAcquisitionToCallDownstreamApi()
115+
.AddMicrosoftGraph(Configuration.GetSection("GraphBeta"))
116+
.AddInMemoryTokenCaches();
117+
// ...
134118
```
135119

136120
### Option 2: Call a downstream web API other than Microsoft Graph
@@ -140,26 +124,18 @@ To call a downstream API other than Microsoft Graph, *Microsoft.Identity.Web* pr
140124
```csharp
141125
using Microsoft.Identity.Web;
142126

143-
public class Startup
144-
{
145-
// ...
146-
public void ConfigureServices(IServiceCollection services)
147-
{
148-
// ...
149-
services.AddAuthentication(JwtBearerDefaults.AuthenticationScheme)
150-
.AddMicrosoftIdentityWebApi(Configuration, "AzureAd")
151-
.EnableTokenAcquisitionToCallDownstreamApi()
152-
.AddDownstreamWebApi("MyApi", Configuration.GetSection("GraphBeta"))
153-
.AddInMemoryTokenCaches();
154-
// ...
155-
}
156-
// ...
157-
}
127+
// ...
128+
builder.Services.AddAuthentication(JwtBearerDefaults.AuthenticationScheme)
129+
.AddMicrosoftIdentityWebApi(Configuration, "AzureAd")
130+
.EnableTokenAcquisitionToCallDownstreamApi()
131+
.AddDownstreamWebApi("MyApi", Configuration.GetSection("GraphBeta"))
132+
.AddInMemoryTokenCaches();
133+
// ...
158134
```
159135

160136
As with web apps, you can choose various token cache implementations. For details, see [Microsoft identity web - Token cache serialization](https://aka.ms/ms-id-web/token-cache-serialization) on GitHub.
161137

162-
The following image shows the various possibilities of *Microsoft.Identity.Web* and their impact on the *Startup.cs* file:
138+
The following image shows the various possibilities of *Microsoft.Identity.Web* and their impact on the *Program.cs* file:
163139

164140
:::image type="content" source="media/scenarios/microsoft-identity-web-startup-cs.svg" alt-text="Block diagram showing service configuration options in startup dot C S for calling a web API and specifying a token cache implementation":::
165141

articles/active-directory/privileged-identity-management/groups-activate-roles.md

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -4,22 +4,22 @@ description: Learn how to activate your privileged access group roles in Azure A
44
services: active-directory
55
documentationcenter: ''
66
author: amsliu
7-
manager: karenhoran
7+
manager: amycolannino
88
ms.service: active-directory
99
ms.topic: how-to
1010
ms.tgt_pltfrm: na
1111
ms.workload: identity
1212
ms.subservice: pim
13-
ms.date: 02/24/2022
13+
ms.date: 08/24/2022
1414
ms.author: amsliu
15-
ms.reviewer: shaunliu
15+
ms.reviewer: ilyal
1616
ms.custom: pim
1717
ms.collection: M365-identity-device-management
1818
---
1919

2020
# Activate my privileged access group roles in Privileged Identity Management
2121

22-
Use Privileged Identity Management (PIM) in Azure Active Directory (Azure AD), part of Microsoft Entra,to allow eligible role members for privileged access groups to schedule role activation for a specified date and time. They can also select a activation duration up to the maximum duration configured by administrators.
22+
Use Privileged Identity Management (PIM) in Azure Active Directory (Azure AD), part of Microsoft Entra, to allow eligible role members for privileged access groups to schedule role activation for a specified date and time. They can also select an activation duration up to the maximum duration configured by administrators.
2323

2424
This article is for eligible members who want to activate their privileged access group role in Privileged Identity Management.
2525

169 KB
Loading
Loading
Loading
Loading
Loading
Loading

0 commit comments

Comments
 (0)