Skip to content

Commit 5f8e033

Browse files
committed
Bringing even with master.
2 parents 9128606 + 950a471 commit 5f8e033

21 files changed

+108
-91
lines changed

articles/active-directory/fundamentals/identity-secure-score.md

Lines changed: 12 additions & 28 deletions
Original file line numberDiff line numberDiff line change
@@ -23,7 +23,7 @@ ms.reviewer: nigu
2323

2424
How secure is your Azure AD tenant? If you don't know how to answer this question, read this article to learn how the identity secure score helps you to monitor and improve your identity security posture.
2525

26-
## What is a secure score?
26+
## What is an identity secure score?
2727

2828
The identity secure score is number between 1 and 248 that functions as indicator for how aligned you are with Microsoft's best practices recommendations for security.
2929

@@ -66,17 +66,6 @@ By following the improvement actions, you can:
6666

6767
- Take advantage of Microsoft’s Identity features.
6868

69-
The improvement actions take into consideration:
70-
71-
- Privileged accounts
72-
73-
- App management
74-
75-
- Conditional access policies
76-
77-
- Authentication methods
78-
79-
- Auditing and reporting.
8069

8170

8271
## How do I get my secure score?
@@ -104,19 +93,25 @@ Additionally, you also have the option to set recommendations to be ignored if t
10493

10594
## How does it help me?
10695

107-
Using the secure score helps increase your organization's security by encouraging you to use the built-in security features such as:
96+
The secure score helps you to:
97+
98+
- Objectively measure your identity security posture
10899

100+
- Plan identity security improvements
109101

110-
Learning more about these features as you use the tool will help give you piece of mind that you're taking the right steps to protect your organization from threats.
102+
- Review the success of your improvements
111103

112-
Customers who are using Secure Score have seen their score increase five times more than customers who aren't using it. (The increase in score corresponds with the security features being used in their organizations.)
113104

114105

115106
## What you should know
116107

117-
### Who can use Secure Score?
108+
### Who can use the identity secure score?
109+
110+
The identity secure score can be used by the following roles:
118111

119-
Anyone who has admin permissions (global admin or a custom admin role) for your Azure AD tenant. Users who aren't assigned an admin role can't access the score. However, admins can use the tool to share their results with other people in their organization.
112+
- Global admin
113+
- Security admin
114+
- Security readers
120115

121116
### What does [Not Scored] mean?
122117

@@ -126,9 +121,6 @@ Actions labeled as [Not Scored] are ones you can perform in your organization bu
126121

127122
The score is calculated once per day (around 1:00 AM PST). If you make a change to a measured action, the score will automatically update the next day. It takes up to 48 hours for a change to be reflected in your score.
128123

129-
### Who can see my results?
130-
131-
Results are filtered to show scores only to people in your organization who are assigned an admin role (global admin or a custom admin role).
132124

133125
### My score changed. How do I figure out why?
134126

@@ -162,14 +154,6 @@ The [Office 365 secure score](https://docs.microsoft.com/office365/securitycompl
162154
The identity secure score represents the identity part of of the Office 365 secure score. This means that your recommendations for the identity secure score and the identity score in Office 365 are the same.
163155

164156

165-
### I have an idea for another control. How do I let you know what it is?
166-
We'd love to hear from you. Post your ideas on the Office Security, Privacy & Compliance community. We're listening and want the Secure Score to include all options that are important to you.
167-
168-
Something isn't working right. Who should I contact?
169-
If you have any issues, let us know by posting on the Office Security, Privacy & Compliance community. We're monitoring the community and will provide help.
170-
171-
### My organization only has certain security features. Does this affect my score?
172-
The Secure Score calculates your score based on the services you purchased. For example, if you only purchased an Exchange Online plan, you won't be scored for SharePoint Online security features. The denominator of the score is the sum of all the baselines for the controls that apply to the products you purchased. The numerator is the sum of all the controls for which you completed, or partially completed, the actions to fulfill that control.
173157
## Next steps
174158

175159
If you would like to see a video about the Office 365 secure score, click [here](https://www.youtube.com/watch?v=jzfpDJ9Kg-A).

articles/active-directory/user-help/microsoft-authenticator-app-faq.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -40,7 +40,7 @@ The Microsoft Authenticator app replaced the Azure Authenticator app, and is the
4040
|Why does the Microsoft Authenticator app allow you to approve a request without unlocking the device?|You don't have to unlock your device to approve verification requests because all you need to prove is that you have your phone with you. Two-step verification requires proving two things – a thing you know, and a thing you have. The thing you know is your password. The thing you have is your phone (set up with the Microsoft Authenticator app and registered as an MFA proof.) Therefore, having the phone and approving the request meets the criteria for the second factor of authentication.|
4141
|Why aren’t all my accounts showing up when I open the Microsoft Authenticator app on my Apple Watch?|The Microsoft Authenticator app only supports using Microsoft personal or school or work accounts with push notifications on the Apple Watch companion app. For your other accounts, like Google or Facebook, you’ll have to open the authenticator app on your phone to view your verification codes.|
4242
|Why can’t I approve or deny notifications on my Apple Watch?|First, make sure you’ve upgraded to the Microsoft Authenticator app, version 6.0.0 or higher on your iPhone. After that, open the Microsoft Authenticator companion app on your Apple Watch and look for any accounts with a **Set Up** button beneath them. You must complete that set up process to approve notifications for those accounts.|
43-
|Why am I getting the error, **Unable to communicate with the phone while using the Microsoft Authenticator companion app on the Apple Watch**?|If your phone and watch aren’t communicating, you can try the following:<ol><li>Force quit the Microsoft Authenticator phone app and open it again on your iPhone.</li><li>Force quit the companion app on your Apple Watch.<ol><li> Open the Microsoft Authenticator companion app on your Watch</li><li>Hold down the side button until the **Shutdown** screen appears.</li><li>Release the side button and hold down the Digital Crown to force quit the active app.</li></ol></li><li>Turn off both Bluetooth and Wi-Fi for both your phone and your Watch, and then turn them back on.</li><li>Restart your iPhone and your Watch.</li></ol>|
43+
|I’m getting a communication error between the Apple Watch and my phone. What can I do to troubleshoot?|This error happens when your Watch screen goes to sleep before it finishes communicating with your phone.<br><br><b>If this happens during setup:</b><br>Try to run setup again, making sure to keep your Watch awake until the process is done. At the same time, open the app on your phone and respond to any prompts that appear.<br><br>If your phone and Watch still aren’t communicating, you can try the following:<ol><li>Force quit the Microsoft Authenticator phone app and open it again on your iPhone.</li><li>Force quit the companion app on your Apple Watch.<ol><li> Open the Microsoft Authenticator companion app on your Watch</li><li>Hold down the side button until the **Shutdown** screen appears.</li><li>Release the side button and hold down the Digital Crown to force quit the active app.</li></ol></li><li>Turn off both Bluetooth and Wi-Fi for both your phone and your Watch, and then turn them back on.</li><li>Restart your iPhone and your Watch.</li></ol><b>If this happens when you’re trying to approve a notification:</b><br>The next time you try to approve a notification on your Apple Watch, keep the screen awake until the request is complete and you hear the sound that indicates it was successful.|
4444
|Why isn’t the Microsoft Authenticator companion app for Apple Watch syncing or showing up on my watch?|If the app isn’t showing up on your Watch, try the following: <ol><li>Make sure your Watch is running watchOS 4.0 or higher.</li><li>Sync your Watch again.</li></ol>|
4545
|My Apple Watch companion app crashed. Can I send you my crash logs so you can investigate? |You first have to make sure you’ve chosen to share your analytics with us. If you’re a TestFlight user, you’re already signed up. Otherwise, you can go to **Settings > Privacy > Analytics** and select both the **Share iPhone & Watch analytics** and the **Share with App Developers** options.<br><br>After you sign up, you can try to reproduce your crash so your crash logs are automatically sent to us for investigation. However, if you can’t reproduce your crash, you can manually copy your log files and send them to us.<ol><li>Open the Watch app on your phone, go to **Settings > General**, and then click **Copy Watch Analytics**.</li><li>Find the corresponding crash under **Settings > Privacy > Analytics > Analytics Data**, and then manually copy the entire text.</li><li>Open the Microsoft Authenticator app on your phone and paste that copied text into the **Share with App Developers** text box on the **Send logs** page.</li></ol>|
4646

articles/application-insights/app-insights-diagnostic-search.md

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -12,7 +12,7 @@ ms.workload: tbd
1212
ms.tgt_pltfrm: ibiza
1313
ms.devlang: na
1414
ms.topic: conceptual
15-
ms.date: 07/18/2018
15+
ms.date: 09/20/2018
1616
ms.author: mbullwin
1717

1818
---
@@ -119,8 +119,8 @@ Here are the search expressions you can use:
119119
| Sample query | Effect |
120120
| --- | --- |
121121
| `apple` |Find all events in the time range whose fields include the word "apple" |
122-
| `apple AND banana` |Find events that contain both words. Use capital "AND", not "and". |
123-
| `apple OR banana`<br/>`apple banana` |Find events that contain either word. Use "OR", not "or".<br/>Short form. |
122+
| `apple AND banana` <br/>`apple banana` |Find events that contain both words. Use capital "AND", not "and". |
123+
| `apple OR banana` |Find events that contain either word. Use "OR", not "or".<br/>Short form. |
124124
| `apple NOT banana` |Find events that contain one word but not the other. |
125125

126126
## Sampling

articles/application-insights/app-insights-profiler.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -18,7 +18,7 @@ ms.author: mbullwin
1818
---
1919
# Profile live Azure web apps with Application Insights
2020

21-
This feature of Azure Application Insights is generally available for the Web Apps feature of Azure App Service and is in preview for Azure compute resources. For information regarding [on premises use of profiler](https://docs.microsoft.com/azure/application-insights/enable-profiler-compute#enable-profiler-on-on-premises-servers).
21+
This feature of Azure Application Insights is generally available for the Web Apps feature of Azure App Service and Azure compute resources. For information regarding [on premises use of profiler](https://docs.microsoft.com/azure/application-insights/enable-profiler-compute#enable-profiler-on-on-premises-servers).
2222

2323
This article discusses the amount of time that's spent in each method of your live web application when you use [Application Insights](app-insights-overview.md). The Application Insights Profiler tool displays detailed profiles of live requests that were served by your app. Profiler highlights the *hot path* that uses the most time. Requests with various response times are profiled on a sampling basis. By using a variety of techniques, you can minimize the overhead that's associated with the application.
2424

articles/automation/automation-update-azure-modules.md

Lines changed: 4 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -6,7 +6,7 @@ ms.service: automation
66
ms.component: process-automation
77
author: georgewallace
88
ms.author: gwallace
9-
ms.date: 03/16/2018
9+
ms.date: 09/19/2018
1010
ms.topic: conceptual
1111
manager: carmonm
1212
---
@@ -39,8 +39,10 @@ Because modules are updated regularly by the product group, changes can occur wi
3939

4040
If the modules are already up-to-date, then the process completes in a few seconds. When the update process completes, you are notified.<br><br> ![Update Azure Modules update status](media/automation-update-azure-modules/automation-update-azure-modules-updatestatus.png)
4141

42+
The .NET core AzureRm modules (AzureRm.*.Core) are not supported in Azure Automation and can not be imported.
43+
4244
> [!NOTE]
43-
> Azure Automation uses the latest modules in your Automation account when a new scheduled job is run.
45+
> Azure Automation uses the latest modules in your Automation account when a new scheduled job is run.
4446
4547
If you use cmdlets from these Azure PowerShell modules in your runbooks, you want to run this update process every month or so to make sure that you have the latest modules. Azure Automation uses the AzureRunAsConnection connection to authenticate when updating the modules, if the service principal is expired or no longer exists on the subscription level, the module update will fail.
4648

articles/automation/automation-update-management.md

Lines changed: 19 additions & 13 deletions
Original file line numberDiff line numberDiff line change
@@ -29,7 +29,7 @@ The following diagram shows a conceptual view of the behavior and data flow with
2929

3030
![Update Management process flow](media/automation-update-management/update-mgmt-updateworkflow.png)
3131

32-
Update Management can be used to natively onboard machines in multiple subscriptions in the same tenant. To manage machines in a different tenant you must onboard them as [Non-Azure machines](automation-onboard-solutions-from-automation-account.md#onboard-a-non-azure-machine).
32+
Update Management can be used to natively onboard machines in multiple subscriptions in the same tenant. To manage machines in a different tenant you must onboard them as [Non-Azure machines](automation-onboard-solutions-from-automation-account.md#onboard-a-non-azure-machine).
3333

3434
After a computer performs a scan for update compliance, the agent forwards the information in bulk to Azure Log Analytics. On a Windows computer, the compliance scan is performed every 12 hours by default.
3535

@@ -50,6 +50,8 @@ Updates are installed by runbooks in Azure Automation. You can't view these runb
5050

5151
At the date and time specified in the update deployment, the target computers execute the deployment in parallel. Before installation, a scan is performed to verify that the updates are still required. For WSUS client computers, if the updates aren't approved in WSUS, the update deployment fails.
5252

53+
Having a machine registered for Update Management in multiple Log Analytics Workspaces (multi-homing) is not supported.
54+
5355
## Clients
5456

5557
### Supported client types
@@ -193,18 +195,6 @@ To avoid updates being applied outside of a maintenance window on Ubuntu, reconf
193195

194196
Virtual machines that were created from the on-demand Red Hat Enterprise Linux (RHEL) images that are available in the Azure Marketplace are registered to access the [Red Hat Update Infrastructure (RHUI)](../virtual-machines/virtual-machines-linux-update-infrastructure-redhat.md) that's deployed in Azure. Any other Linux distribution must be updated from the distribution's online file repository by following the distribution's supported methods.
195197

196-
## View missing updates
197-
198-
Select **Missing updates** to view the list of updates that are missing from your machines. Each update is listed and can be selected. Information about the number of machines that require the update, the operating system, and a link for more information is shown. The **Log search** pane shows more details about the updates.
199-
200-
## View update deployments
201-
202-
Select the **Update Deployments** tab to view the list of existing update deployments. Select any of the update deployments in the table to open the **Update Deployment Run** pane for that update deployment.
203-
204-
![Overview of update deployment results](./media/automation-update-management/update-deployment-run.png)
205-
206-
## Create or edit an update deployment
207-
208198
To create a new update deployment, select **Schedule update deployment**. The **New Update Deployment** pane opens. Enter values for the properties described in the following table and then click **Create**:
209199

210200
| Property | Description |
@@ -220,6 +210,20 @@ To create a new update deployment, select **Schedule update deployment**. The **
220210
| Maintenance window |Number of minutes set for updates. The value can be not be less than 30 minutes and no more than 6 hours |
221211
| Reboot control| Determines how reboots should be handled. Available options are:</br>Reboot if required (Default)</br>Always reboot</br>Never reboot</br>Only reboot - will not install updates|
222212

213+
Update Deployments can also be created programmatically. To learn how to create an Update Deployment with the REST API, see [Software Update Configurations - Create](/rest/api/automation/softwareupdateconfigurations/create). There is also a sample runbook that can be used to create a weekly Update Deployment. To learn more about this runbook, see [Create a weekly update deployment for one or more VMs in a resource group](https://gallery.technet.microsoft.com/scriptcenter/Create-a-weekly-update-2ad359a1).
214+
215+
## View missing updates
216+
217+
Select **Missing updates** to view the list of updates that are missing from your machines. Each update is listed and can be selected. Information about the number of machines that require the update, the operating system, and a link for more information is shown. The **Log search** pane shows more details about the updates.
218+
219+
## View update deployments
220+
221+
Select the **Update Deployments** tab to view the list of existing update deployments. Select any of the update deployments in the table to open the **Update Deployment Run** pane for that update deployment.
222+
223+
![Overview of update deployment results](./media/automation-update-management/update-deployment-run.png)
224+
225+
To view an update deployment from the REST API, see [Software Update Configuration Runs](/rest/api/automation/softwareupdateconfigurationruns).
226+
223227
## Update classifications
224228

225229
The following tables list the update classifications in Update Management, with a definition for each classification.
@@ -544,3 +548,5 @@ Continue to the tutorial to learn how to manage updates for your Windows virtual
544548
545549
* Use log searches in [Log Analytics](../log-analytics/log-analytics-log-searches.md) to view detailed update data.
546550
* [Create alerts](../log-analytics/log-analytics-alerts.md) when critical updates are detected as missing from computers or if a computer has automatic updates disabled.
551+
552+
* To learn how to interact with Update Management through the REST API, see [Software Update Configurations](/rest/api/automation/softwareupdateconfigurations)

articles/azure-stack/azure-stack-csp-howto-register-tenants.md

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -12,7 +12,7 @@ ms.workload: na
1212
pms.tgt_pltfrm: na
1313
ms.devlang: na
1414
ms.topic: article
15-
ms.date: 07/12/2018
15+
ms.date: 09/19/2018
1616
ms.author: sethm
1717
ms.reviewer: alfredo
1818

@@ -66,9 +66,9 @@ Update your registration with the new customer’s subscription. Azure reports t
6666
### New-AzureRmResource PowerShell parameters
6767
| Parameter | Description |
6868
| --- | --- |
69-
|registrationSubscriptionID | The Azure subscription that was used for the initial registration of the Azure Stack. |
70-
| customerSubscriptionID | The Azure subscription (not Azure Stack) belonging to the customer to be registered. Must be created in the CSP offer; in practice, this means through Partner Center. If a customer has more than one Azure Active Directory tenant, this subscription must be created in the tenant that will be used to log into Azure Stack.
71-
| resourceGroup | The resource group in Azure in which your registration is stored.
69+
|registrationSubscriptionID | The Azure subscription that was used for the initial registration of the Azure Stack.|
70+
| customerSubscriptionID | The Azure subscription (not Azure Stack) belonging to the customer to be registered. Must be created in the CSP offer; in practice, this means through Partner Center. If a customer has more than one Azure Active Directory tenant, this subscription must be created in the tenant that will be used to log into Azure Stack. The customer subscription ID must use lowercase letters. |
71+
| resourceGroup | The resource group in Azure in which your registration is stored. |
7272
| registrationName | The name of the registration of your Azure Stack. It is an object stored in Azure. |
7373
| Properties | Specifies properties for the resource. Use this parameter to specify the values of properties that are specific to the resource type.
7474

0 commit comments

Comments
 (0)