Skip to content

Commit 6097f49

Browse files
authored
Merge pull request #224993 from MicrosoftDocs/main
Publish to Live Wednesday 4AM PST, 01/25
2 parents 2794c76 + 731bc4c commit 6097f49

File tree

114 files changed

+1498
-574
lines changed

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

114 files changed

+1498
-574
lines changed

.openpublishing.redirection.active-directory.json

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -11065,6 +11065,11 @@
1106511065
"source_path_from_root": "/articles/active-directory/privileged-identity-management/groups-features.md",
1106611066
"redirect_url": "azure/active-directory/privileged-identity-management/concept-pim-for-groups",
1106711067
"redirect_document_id": false
11068+
},
11069+
{
11070+
"source_path_from_root": "/articles/active-directory/cloud-infrastructure-entitlement-management/product-data-inventory.md",
11071+
"redirect_url": "/azure/active-directory/cloud-infrastructure-entitlement-management/product-data-billable-resources",
11072+
"redirect_document_id": false
1106811073
}
1106911074
]
1107011075
}

articles/active-directory/cloud-infrastructure-entitlement-management/TOC.yml

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -32,13 +32,13 @@
3232
href: ui-dashboard.md
3333
- name: View data about the activity in your authorization system
3434
href: product-dashboard.md
35-
- name: Configure settings for data collection
35+
- name: View current billable resources in your authorization system
36+
href: product-data-billable-resources.md
37+
- name: View information about your Authorization Systems
3638
expanded: false
3739
items:
3840
- name: View and configure settings for data collection
3941
href: product-data-sources.md
40-
- name: Display an inventory of created resources and licenses
41-
href: product-data-inventory.md
4242
- name: Manage organizational and personal information
4343
expanded: false
4444
items:
@@ -143,7 +143,7 @@
143143
href: report-view-system-report.md
144144
- name: Create, view, and share a custom report
145145
href: report-create-custom-report.md
146-
- name: Generate and download the Permissions analytics report
146+
- name: View and download the Permissions analytics report
147147
href: product-permissions-analytics-reports.md
148148
- name: Troubleshoot
149149
expanded: false

articles/active-directory/cloud-infrastructure-entitlement-management/faqs.md

Lines changed: 14 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -8,7 +8,7 @@ ms.service: active-directory
88
ms.subservice: ciem
99
ms.workload: identity
1010
ms.topic: faq
11-
ms.date: 04/20/2022
11+
ms.date: 01/25/2023
1212
ms.author: jfields
1313
---
1414

@@ -141,7 +141,19 @@ We also have the ability to remove, export or modify specific data should the Gl
141141
## Do I require a license to use Entra Permissions Management?
142142

143143
Yes, as of July 1st, 2022, new customers must acquire a free 45-day trial license or a paid license to use the service. You can enable a trial here: [https://aka.ms/TryPermissionsManagement](https://aka.ms/TryPermissionsManagement) or you can directly purchase resource-based licenses here: [https://aka.ms/BuyPermissionsManagement](https://aka.ms/BuyPermissionsManagement)
144-
144+
145+
## How is Permissions Management priced?
146+
147+
Permissions Management is $125 per resources/year ($10.40 per resource/month). Permissions Management requires licenses for workloads, which include any resource that uses compute or memory.
148+
149+
## Do I need to pay for all resources?
150+
151+
Although Permissions Management supports all resources, Microsoft only requires licenses for certain resources per cloud. To learn more about billable resources, visit [View billable resources listed in your authorization system](product-data-billable-resources.md)
152+
153+
## How do I figure out how many resources I have?
154+
155+
To find out how many resources you have across your multicloud infrastructure, view the Billable Resources tab in Permissions Management.
156+
145157
## What do I do if I’m using Public Preview version of Entra Permissions Management?
146158

147159
If you are using the Public Preview version of Entra Permissions Management, your current deployment(s) will continue to work through October 1st.
Loading

articles/active-directory/cloud-infrastructure-entitlement-management/product-dashboard.md

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -8,7 +8,7 @@ ms.service: active-directory
88
ms.subservice: ciem
99
ms.workload: identity
1010
ms.topic: how-to
11-
ms.date: 02/23/2022
11+
ms.date: 01/25/2023
1212
ms.author: jfields
1313
---
1414

@@ -25,6 +25,9 @@ The Permissions Management **Dashboard** provides an overview of the authorizati
2525

2626
The **Permission Creep Index (PCI)** chart updates to display information about the accounts and folders you selected. The number of days since the information was last updated displays in the upper right corner.
2727

28+
>[!NOTE]
29+
>Default and GCP-managed service accounts are not included in the PCI calculation.
30+
2831
1. In the Permission Creep Index (PCI) graph, select a bubble.
2932

3033
The bubble displays the number of identities that are considered high-risk.
Lines changed: 42 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,42 @@
1+
---
2+
title: View current billable resources in your authorization systems
3+
description: How to view current billable resources in your authorization system in Permissions Management.
4+
services: active-directory
5+
author: jenniferf-skc
6+
manager: amycolannino
7+
ms.service: active-directory
8+
ms.subservice: ciem
9+
ms.workload: identity
10+
ms.topic: how-to
11+
ms.date: 01/25/2023
12+
ms.author: jfields
13+
---
14+
15+
# View billable resources listed in your authorization system
16+
17+
Gain insight into current billable resources listed in your authorization system. In Microsoft Entra Permissions Management, a billable resource is defined as a cloud service that uses compute or memory and requires a license. The Permissions Management Billable Resources tab shows you which resources are in your authorization system, and how many of them you're being billed for.
18+
19+
Here is the current list of resources per cloud provider. This list is subject to change as cloud providers add more services in the future.
20+
21+
:::image type="content" source="media/onboard-enable-tenant/billable-resources.png" alt-text="A table of current Microsoft billable resources." lightbox="media/onboard-enable-tenant/billable-resources.png":::
22+
23+
## View resources in your authorization system
24+
25+
1. To access your billable resource information, from the Permissions Management home page, select Settings (gear icon).
26+
1. Select the Billable Resources tab.
27+
1. Select your Authorization System:
28+
29+
- **AWS** for Amazon Web Services.
30+
- **Azure** for Microsoft Azure.
31+
- **GCP** for Google Cloud Platform.
32+
33+
The interface displays information showing which resource you have in your Authorization System per category.
34+
35+
1. To change the columns displayed in the table, select **Columns**, and then select the information you want to display.
36+
37+
- To discard your changes, select **Reset to default**.
38+
39+
40+
## Next steps
41+
42+
- For information about viewing and configuring settings for collecting data from your authorization system and its associated accounts, see [View and configure settings for data collection](product-data-sources.md).

articles/active-directory/cloud-infrastructure-entitlement-management/product-data-inventory.md

Lines changed: 0 additions & 52 deletions
This file was deleted.

articles/active-directory/cloud-infrastructure-entitlement-management/product-data-sources.md

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,14 +1,14 @@
11
---
2-
title: View and configure settings for data collection from your authorization system in Permissions Management
3-
description: How to view and configure settings for collecting data from your authorization system in Permissions Management.
2+
title: View and configure settings for data collection
3+
description: How to view and configure settings for collecting data from your authorization system.
44
services: active-directory
55
author: jenniferf-skc
66
manager: amycolannino
77
ms.service: active-directory
88
ms.subservice: ciem
99
ms.workload: identity
1010
ms.topic: how-to
11-
ms.date: 02/23/2022
11+
ms.date: 01/25/2023
1212
ms.author: jfields
1313
---
1414

articles/active-directory/cloud-infrastructure-entitlement-management/product-permissions-analytics-reports.md

Lines changed: 56 additions & 84 deletions
Original file line numberDiff line numberDiff line change
@@ -1,99 +1,71 @@
11
---
2-
title: Generate and download the Permissions analytics report in Permissions Management
3-
description: How to generate and download the Permissions analytics report in Permissions Management.
2+
title: View and download the Permissions Analytics Report in Permissions Management
3+
description: How to view and download the Permissions Analytics Report in Permissions Management.
44
services: active-directory
55
author: jenniferf-skc
66
manager: amycolannino
77
ms.service: active-directory
88
ms.subservice: ciem
99
ms.workload: identity
1010
ms.topic: how-to
11-
ms.date: 01/20/2023
11+
ms.date: 01/25/2023
1212
ms.author: jfields
1313
---
1414

15-
# Generate and download the Permissions analytics report
16-
17-
This article describes how to generate and download the **Permissions analytics report** in Permissions Management for AWS, Azure, and GCP. You can generate the report in Excel format, and also as a PDF.
18-
19-
20-
## Generate the Permissions analytics report
21-
22-
1. In the Permissions Management home page, select the **Reports** tab, and then select the **Systems Reports** subtab.
23-
24-
The **Systems Reports** subtab displays a list of reports the **Reports** table.
25-
1. Select **Permissions Analytics Report** from the list. o download the report, select the down arrow to the right of the report name, or from the ellipses **(...)** menu, select **Download**.
26-
27-
The following message displays: **Successfully Started To Generate On Demand Report.**
28-
29-
1. For detailed information in the report, select the right arrow next to one of the following categories. Or, select the required category under the **Findings** column.
30-
31-
- **AWS**
32-
- Inactive Identities
33-
- Users
34-
- Roles
35-
- Resources
36-
- Serverless Functions
37-
- Inactive Groups
38-
- Super Identities
39-
- Users
40-
- Roles
41-
- Resources
42-
- Serverless Functions
43-
- Over-Provisioned Active Identities
44-
- Users
45-
- Roles
46-
- Resources
47-
- Serverless Functions
48-
- PCI Distribution
49-
- Privilege Escalation
50-
- Users
51-
- Roles
52-
- Resources
53-
- S3 Bucket Encryption
54-
- Unencrypted Buckets
55-
- SSE-S3 Buckets
56-
- S3 Buckets Accessible Externally
57-
- EC2 S3 Buckets Accessibility
58-
- Open Security Groups
59-
- Identities That Can Administer Security Tools
60-
- Users
61-
- Roles
62-
- Resources
63-
- Serverless Functions
64-
- Identities That Can Access Secret Information
65-
- Users
66-
- Roles
67-
- Resources
68-
- Serverless Functions
69-
- Cross-Account Access
70-
- External Accounts
71-
- Roles That Allow All Identities
72-
- Hygiene: MFA Enforcement
73-
- Hygiene: IAM Access Key Age
74-
- Hygiene: Unused IAM Access Keys
75-
- Exclude From Reports
76-
- Users
77-
- Roles
78-
- Resources
79-
- Serverless Functions
80-
- Groups
81-
- Security Groups
82-
- S3 Buckets
83-
84-
85-
1. Select a category and view the following columns of information:
86-
87-
- **User**, **Role**, **Resource**, **Serverless Function Name**: Displays the name of the identity.
88-
- **Authorization System**: Displays the authorization system to which the identity belongs.
89-
- **Domain**: Displays the domain name to which the identity belongs.
90-
- **Permissions**: Displays the maximum number of permissions that the identity can be granted.
91-
- **Used**: Displays how many permissions that the identity has used.
92-
- **Granted**: Displays how many permissions that the identity has been granted.
93-
- **PCI**: Displays the permission creep index (PCI) score of the identity.
94-
- **Date Last Active On**: Displays the date that the identity was last active.
95-
- **Date Created On**: Displays the date when the identity was created.
15+
# View and download the Permissions analytics report
9616

17+
This article describes how to view and download the **Permissions analytics report** in Permissions Management for AWS, Azure, and GPC authorization systems.
18+
19+
>[!NOTE]
20+
>The Permissions analytics report can be downloaded in Excel and PDF formats.
21+
22+
## View the Permissions Analytics Report in the Permissions Management UI
23+
24+
You can view the Permissions Analytics Report information directly in the Permissions Management UI.
25+
26+
1. In Permissions Management, select **Reports** in the navigation menu.
27+
2. Locate the **Permissions Analytics Report** in the list, then select it.
28+
3. View detailed report information from the list of categories that are displayed.
29+
>[!NOTE]
30+
> Categories will vary depending on which Authorization System you are viewing.
31+
32+
4. To view more detailed information into each category, select the drop-down arrow next to the category name.
33+
34+
35+
## Download the Permissions Analytics Report in Excel format
36+
37+
1. From the Permissions Management home page, select the **Reports** tab, then select the **Systems Reports** subtab.
38+
39+
The **Systems Reports** subtab displays a list of report names in the **Reports** table.
40+
2. Locate the **Permissions Analytics Report** in the list.
41+
3. To download the report in Excel format, click on the ellipses **(...)**, the select **Generate & Download**.
42+
43+
The Permissions Analytics Report screen is displayed.
44+
4. Click on **Report Format** and make sure that **XLSX** is selected.
45+
5. Click on **Schedule** and, if you want to download this report regularly, select the frequency for which you want it downloaded. You can also leave this at the default setting of **None**.
46+
6. Click on **Authorization Systems** and select which system you want to download the report for (AWS, Azure, or GCP).
47+
>[!NOTE]
48+
> To download a report for all Authorization Systems, check the **Collate** box. This will combine all selected Authorization Systems into one report.
49+
7. Click **Save**
50+
51+
The following message displays: **Report has been created**.
52+
53+
Once the Excel file is generated, the report is automatically sent to your email.
54+
55+
## Download the Permissions Analytics Report in PDF format
56+
57+
1. From the Permissions Management home page, select the **Reports** tab, then select the **Systems Reports** subtab.
58+
59+
The **Systems Reports** subtab displays a list of reports names in the **Reports** table.
60+
2. Locate the **Permissions Analytics Report** in the list, then select it.
61+
3. Select which Authorization System you want to generate the PDF download for (AWS, Azure, or GCP).
62+
>[!NOTE]
63+
> The PDF can only be downloaded for one Authorization System at a time. If more than one Authorization System is selected, the **Export PDF** button will be disabled.
64+
4. To download the report in PDF format, click on **Export PDF**.
65+
66+
The following message displays: **Successfully started to generate PDF report**.
67+
68+
Once the PDF is generated, the report is automatically sent to your email.
9769

9870

9971
<!---## Add and remove tags in the Permissions analytics report

0 commit comments

Comments
 (0)