Skip to content

Commit 5385335

Browse files
authored
Merge pull request #224601 from MicrosoftDocs/main
1/20 PM Publish
2 parents c0b0db4 + 8a7999c commit 5385335

File tree

337 files changed

+2102
-1368
lines changed

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

337 files changed

+2102
-1368
lines changed

.openpublishing.redirection.json

Lines changed: 6 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -29954,6 +29954,11 @@
2995429954
"source_path": "articles/dotnet-develop-multitenant-applications.md",
2995529955
"redirect_URL": "/azure/architecture/guide/multitenant/overview",
2995629956
"redirect_document_id": false
29957-
}
29957+
},
29958+
{
29959+
"source_path": "articles/load-balancer/protect-load-balancer-with-ddos-standard.md",
29960+
"redirect_URL": "/azure/load-balancer/tutorial-protect-load-balancer",
29961+
"redirect_document_id": false
29962+
}
2995829963
]
2995929964
}

articles/active-directory/app-proxy/application-proxy-configure-complex-application.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -59,7 +59,7 @@ Before you get started with Application Proxy Complex application scenario apps,
5959
To configure (and update) Application Segments for a complex app using the API, you first [create a wildcard application](application-proxy-wildcard.md#create-a-wildcard-application), and then update the application's onPremisesPublishing property to configure the application segments and respective CORS settings.
6060

6161
> [!NOTE]
62-
> One application segment is supported in preview. Support for multiple application segment to be announced soon.
62+
> 2 application segment per complex application are supported for [Microsoft Azure AD premium subscription](https://azure.microsoft.com/pricing/details/active-directory). Licence requirement for more than 2 application segments per complex application to be announced soon.
6363
6464
If successful, this method returns a `204 No Content` response code and does not return anything in the response body.
6565
## Example

articles/active-directory/cloud-infrastructure-entitlement-management/faqs.md

Lines changed: 7 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -18,7 +18,7 @@ This article answers frequently asked questions (FAQs) about Permissions Managem
1818

1919
## What's Permissions Management?
2020

21-
Permissions Management is a cloud infrastructure entitlement management (CIEM) solution that provides comprehensive visibility into permissions assigned to all identities. For example, over-privileged workload and user identities, actions, and resources across multi-cloud infrastructures in Microsoft Azure, Amazon Web Services (AWS), and Google Cloud Platform (GCP). Permissions Management detects, automatically right-sizes, and continuously monitors unused and excessive permissions. It deepens the Zero Trust security strategy by augmenting the least privilege access principle.
21+
Permissions Management is a cloud infrastructure entitlement management (CIEM) solution that provides comprehensive visibility into permissions assigned to all identities. For example, over-privileged workload and user identities, actions, and resources across multicloud infrastructures in Microsoft Azure, Amazon Web Services (AWS), and Google Cloud Platform (GCP). Permissions Management detects, automatically right-sizes, and continuously monitors unused and excessive permissions. It deepens the Zero Trust security strategy by augmenting the least privilege access principle.
2222

2323

2424
## What are the prerequisites to use Permissions Management?
@@ -39,15 +39,15 @@ No, Permissions Management is a hosted cloud offering.
3939

4040
## Can non-Azure customers use Permissions Management?
4141

42-
Yes, non-Azure customers can use our solution. Permissions Management is a multi-cloud solution so even customers who have no subscription to Azure can benefit from it.
42+
Yes, non-Azure customers can use our solution. Permissions Management is a multicloud solution so even customers who have no subscription to Azure can benefit from it.
4343

4444
## Is Permissions Management available for tenants hosted in the European Union (EU)?
4545

4646
Yes, Permissions Management is currently for tenants hosted in the European Union (EU).
4747

4848
## If I'm already using Azure AD Privileged Identity Management (PIM) for Azure, what value does Permissions Management provide?
4949

50-
Permissions Management complements Azure AD PIM. Azure AD PIM provides just-in-time access for admin roles in Azure (as well as Microsoft Online Services and apps that use groups), while Permissions Management allows multi-cloud discovery, remediation, and monitoring of privileged access across Azure, AWS, and GCP.
50+
Permissions Management complements Azure AD PIM. Azure AD PIM provides just-in-time access for admin roles in Azure (as well as Microsoft Online Services and apps that use groups), while Permissions Management allows multicloud discovery, remediation, and monitoring of privileged access across Azure, AWS, and GCP.
5151

5252
## What public cloud infrastructures are supported by Permissions Management?
5353

@@ -132,21 +132,21 @@ You can read our blog and visit our web page. You can also get in touch with you
132132

133133
## What is the data destruction/decommission process?
134134

135-
If a customer initiates a free Permissions Management 90-day trial, but does not follow up and convert to a paid license within 90 days of the free trial expiration, we will delete all collected data on or just before 90 days.
135+
If a customer initiates a free Permissions Management 45-day trial, but does not follow up and convert to a paid license within 45 days of the free trial expiration, we will delete all collected data on or just before 45 days.
136136

137-
If a customer decides to discontinue licensing the service, we will also delete all previously collected data within 90 days of license termination.
137+
If a customer decides to discontinue licensing the service, we will also delete all previously collected data within 45 days of license termination.
138138

139139
We also have the ability to remove, export or modify specific data should the Global Admin using the Entra Permissions Management service file an official Data Subject Request. This can be initiated by opening a ticket in the Azure portal [New support request - Microsoft Entra admin center](https://entra.microsoft.com/#blade/Microsoft_Azure_Support/NewSupportRequestV3Blade/callerName/ActiveDirectory/issueType/technical), or alternately contacting your local Microsoft representative.
140140

141141
## Do I require a license to use Entra Permissions Management?
142142

143-
Yes, as of July 1st, 2022, new customers must acquire a free 90-trial license or a paid license to use the service. You can enable a trial here: [https://aka.ms/TryPermissionsManagement](https://aka.ms/TryPermissionsManagement) or you can directly purchase resource-based licenses here: [https://aka.ms/BuyPermissionsManagement](https://aka.ms/BuyPermissionsManagement)
143+
Yes, as of July 1st, 2022, new customers must acquire a free 45-day trial license or a paid license to use the service. You can enable a trial here: [https://aka.ms/TryPermissionsManagement](https://aka.ms/TryPermissionsManagement) or you can directly purchase resource-based licenses here: [https://aka.ms/BuyPermissionsManagement](https://aka.ms/BuyPermissionsManagement)
144144

145145
## What do I do if I’m using Public Preview version of Entra Permissions Management?
146146

147147
If you are using the Public Preview version of Entra Permissions Management, your current deployment(s) will continue to work through October 1st.
148148

149-
After October 1st you will need to move over to use the newly released version of the service and enable a 90-day trial or purchase licenses to continue using the service.
149+
After October 1st you will need to move over to use the newly released version of the service and enable a 45-day trial or purchase licenses to continue using the service.
150150

151151
## What do I do if I’m using the legacy version of the CloudKnox service?
152152

articles/active-directory/cloud-infrastructure-entitlement-management/product-permissions-analytics-reports.md

Lines changed: 3 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -8,23 +8,21 @@ ms.service: active-directory
88
ms.subservice: ciem
99
ms.workload: identity
1010
ms.topic: how-to
11-
ms.date: 02/23/2022
11+
ms.date: 01/20/2023
1212
ms.author: jfields
1313
---
1414

1515
# Generate and download the Permissions analytics report
1616

17-
This article describes how to generate and download the **Permissions analytics report** in Permissions Management.
17+
This article describes how to generate and download the **Permissions analytics report** in Permissions Management for AWS, Azure, and GCP. You can generate the report in Excel format, and also as a PDF.
1818

19-
> [!NOTE]
20-
> This topic applies only to Amazon Web Services (AWS) users.
2119

2220
## Generate the Permissions analytics report
2321

2422
1. In the Permissions Management home page, select the **Reports** tab, and then select the **Systems Reports** subtab.
2523

2624
The **Systems Reports** subtab displays a list of reports the **Reports** table.
27-
1. Find **Permissions Analytics Report** in the list, and to download the report, select the down arrow to the right of the report name, or from the ellipses **(...)** menu, select **Download**.
25+
1. Select **Permissions Analytics Report** from the list. o download the report, select the down arrow to the right of the report name, or from the ellipses **(...)** menu, select **Download**.
2826

2927
The following message displays: **Successfully Started To Generate On Demand Report.**
3028

articles/active-directory/cloud-sync/how-to-attribute-mapping.md

Lines changed: 42 additions & 41 deletions
Original file line numberDiff line numberDiff line change
@@ -7,15 +7,17 @@ manager: amycolannino
77
ms.service: active-directory
88
ms.workload: identity
99
ms.topic: how-to
10-
ms.date: 01/11/2023
10+
ms.date: 01/20/2023
1111
ms.subservice: hybrid
1212
ms.author: billmath
1313
ms.collection: M365-identity-device-management
1414
---
1515

1616
# Attribute mapping in Azure AD Connect cloud sync
1717

18-
You can use the cloud sync feature of Azure Active Directory (Azure AD) Connect to map attributes between your on-premises user or group objects and the objects in Azure AD. This capability has been added to the cloud sync configuration.
18+
You can use the cloud sync attribute mapping feature to map attributes between your on-premises user or group objects and the objects in Azure AD.
19+
20+
:::image type="content" source="media/how-to-attribute-mapping/new-ux-mapping-1.png" alt-text="Screenshot of new UX screen attribute mapping." lightbox="media/how-to-attribute-mapping/new-ux-mapping-1.png":::
1921

2022
You can customize (change, delete, or create) the default attribute mappings according to your business needs. For a list of attributes that are synchronized, see [Attributes synchronized to Azure Active Directory](../hybrid/reference-connect-sync-attributes-synchronized.md?context=azure%2factive-directory%2fcloud-provisioning%2fcontext%2fcp-context/hybrid/reference-connect-sync-attributes-synchronized.md).
2123

@@ -54,7 +56,10 @@ For more information on how to map UserType, see [Map UserType with cloud sync](
5456

5557
## Understand properties of attribute mappings
5658

57-
Along with the type property, attribute mappings support certain attributes. These attributes will depend on the type of mapping you have selected. The following sections describe the supported attribute mappings for each of the individual types
59+
Along with the type property, attribute mappings support certain attributes. These attributes will depend on the type of mapping you have selected. The following sections describe the supported attribute mappings for each of the individual types. The following type of attribute mapping is available.
60+
- Direct
61+
- Constant
62+
- Expression
5863

5964
### Direct mapping attributes
6065
The following are the attributes supported by a direct mapping:
@@ -66,7 +71,7 @@ The following are the attributes supported by a direct mapping:
6671
- **Always**: Apply this mapping on both user-creation and update actions.
6772
- **Only during creation**: Apply this mapping only on user-creation actions.
6873

69-
![Screenshot for direct](media/how-to-attribute-mapping/mapping-7.png)
74+
:::image type="content" source="media/how-to-attribute-mapping/new-ux-mapping-2.png" alt-text="Screenshot of editing attribute mapping." lightbox="media/how-to-attribute-mapping/new-ux-mapping-2.png":::
7075

7176
### Constant mapping attributes
7277
The following are the attributes supported by a constant mapping:
@@ -77,8 +82,6 @@ The following are the attributes supported by a constant mapping:
7782
- **Always**: Apply this mapping on both user-creation and update actions.
7883
- **Only during creation**: Apply this mapping only on user-creation actions.
7984

80-
![Screenshot for constant](media/how-to-attribute-mapping/mapping-9.png)
81-
8285
### Expression mapping attributes
8386
The following are the attributes supported by an expression mapping:
8487

@@ -90,61 +93,59 @@ The following are the attributes supported by an expression mapping:
9093
- **Always**: Apply this mapping on both user-creation and update actions.
9194
- **Only during creation**: Apply this mapping only on user-creation actions.
9295

93-
![Screenshot for expression](media/how-to-attribute-mapping/mapping-10.png)
94-
9596
## Add an attribute mapping
9697

97-
To use the new capability, follow these steps:
98-
99-
1. In the Azure portal, select **Azure Active Directory**.
100-
2. Select **Azure AD Connect**.
101-
3. Select **Manage cloud sync**.
102-
103-
![Screenshot that shows the link for managing cloud sync.](media/how-to-install/install-6.png)
104-
105-
4. Under **Configuration**, select your configuration.
106-
5. Select **Click to edit mappings**. This link opens the **Attribute mappings** screen.
98+
To use attribute mapping, follow these steps:
10799

108-
![Screenshot that shows the link for adding attributes.](media/how-to-attribute-mapping/mapping-6.png)
100+
1. In the Azure portal, select **Azure Active Directory**.
101+
2. On the left, select **Azure AD Connect**.
102+
3. On the left, select **Cloud sync**.
103+
104+
:::image type="content" source="media/how-to-on-demand-provision/new-ux-1.png" alt-text="Screenshot of new UX screen." lightbox="media/how-to-on-demand-provision/new-ux-1.png":::
109105

110-
6. Select **Add attribute**.
106+
4. Under **Configuration**, select your configuration.
107+
5. On the left, select **Attribute mapping**.
108+
6. At the top, ensure that you have the correct object type selected. That is, user, group, or contact.
109+
7. Click **Add attribute mapping**.
111110

112-
![Screenshot that shows the button for adding an attribute, along with lists of attributes and mapping types.](media/how-to-attribute-mapping/mapping-1.png)
111+
:::image type="content" source="media/how-to-attribute-mapping/new-ux-mapping-3.png" alt-text="Screenshot of adding an attribute mapping." lightbox="media/how-to-attribute-mapping/new-ux-mapping-3.png":::
113112

114-
7. Select the mapping type. This can be one of the following:
113+
8. Select the mapping type. This can be one of the following:
115114
- **Direct**: The target attribute is populated with the value of an attribute of the linked object in Active Directory.
116115
- **Constant**: The target attribute is populated with a specific string that you specify.
117116
- **Expression**: The target attribute is populated based on the result of a script-like expression.
118117
- **None**: The target attribute is left unmodified.
119-
120-
For more information see See [Understanding attribute types](#understand-types-of-attribute-mapping) above.
121-
8. Depending on what you have selected in the previous step, different options will be available for filling in. See the [Understand properties of attribute mappings](#understand-properties-of-attribute-mappings)sections above for information on these attributes.
122-
9. Select when to apply this mapping, and then select **Apply**.
123-
11. Back on the **Attribute mappings** screen, you should see your new attribute mapping.
124-
12. Select **Save schema**.
118+
119+
9. Depending on what you have selected in the previous step, different options will be available for filling in.
120+
10. Select when to apply this mapping, and then select **Apply**.
121+
:::image type="content" source="media/how-to-attribute-mapping/new-ux-mapping-4.png" alt-text="Screenshot of saving an attribute mapping." lightbox="media/how-to-attribute-mapping/new-ux-mapping-4.png":::
122+
123+
11. Back on the **Attribute mappings** screen, you should see your new attribute mapping.
124+
12. Select **Save schema**. You will be notified that once you save the schema, a synchronization will occur. Click **OK**.
125+
:::image type="content" source="media/how-to-attribute-mapping/new-ux-mapping-5.png" alt-text="Screenshot of saving schema." lightbox="media/how-to-attribute-mapping/new-ux-mapping-5.png":::
125126

126-
![Screenshot that shows the Save schema button.](media/how-to-attribute-mapping/mapping-3.png)
127+
13. Once the save is successful you will see a notification on the right.
128+
129+
:::image type="content" source="media/how-to-attribute-mapping/new-ux-mapping-6.png" alt-text="Screenshot of successful schema save." lightbox="media/how-to-attribute-mapping/new-ux-mapping-6.png":::
127130

128131
## Test your attribute mapping
129132

130133
To test your attribute mapping, you can use [on-demand provisioning](how-to-on-demand-provision.md):
131134

132-
1. In the Azure portal, select **Azure Active Directory**.
133-
2. Select **Azure AD Connect**.
134-
3. Select **Manage provisioning**.
135-
4. Under **Configuration**, select your configuration.
136-
5. Under **Validate**, select the **Provision a user** button.
137-
6. On the **Provision on demand** screen, enter the distinguished name of a user or group and select the **Provision** button.
138-
139-
The screen shows that the provisioning is in progress.
135+
1. In the Azure portal, select **Azure Active Directory**.
136+
2. On the left, select **Azure AD Connect**.
137+
3. On the left, select **Cloud sync**.
138+
4. Under **Configuration**, select your configuration.
139+
5. On the left, select **Provision on demand**.
140+
6. Enter the distinguished name of a user and select the **Provision** button.
141+
142+
:::image type="content" source="media/how-to-on-demand-provision/new-ux-2.png" alt-text="Screenshot of user distinguished name." lightbox="media/how-to-on-demand-provision/new-ux-2.png":::
140143

141-
![Screenshot that shows provisioning in progress.](media/how-to-attribute-mapping/mapping-4.png)
144+
7. After provisioning finishes, a success screen appears with four green check marks. Any errors appear to the left.
142145

143-
8. After provisioning finishes, a success screen appears with four green check marks.
146+
:::image type="content" source="media/how-to-on-demand-provision/new-ux-3.png" alt-text="Screenshot of on-demand success." lightbox="media/how-to-on-demand-provision/new-ux-3.png":::
144147

145-
Under **Perform action**, select **View details**. On the right, you should see the new attribute synchronized and the expression applied.
146148

147-
![Screenshot that shows success and export details.](media/how-to-attribute-mapping/mapping-5.png)
148149

149150

150151

0 commit comments

Comments
 (0)