Skip to content

Commit 63d5cac

Browse files
committed
Merge branch 'main' into eur/stt-3-1
2 parents 3d724b7 + eb26bfb commit 63d5cac

File tree

1,087 files changed

+12463
-7832
lines changed

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

1,087 files changed

+12463
-7832
lines changed

.openpublishing.publish.config.json

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -674,6 +674,12 @@
674674
"branch": "main",
675675
"branch_mapping": {}
676676
},
677+
{
678+
"path_to_root": "cosmos-db-sql-api-javascript-samples",
679+
"url": "https://github.com/Azure-Samples/cosmos-db-sql-api-javascript-samples",
680+
"branch": "main",
681+
"branch_mapping": {}
682+
},
677683
{
678684
"path_to_root": "azure-cosmos-db-python-getting-started",
679685
"url": "https://github.com/Azure-Samples/azure-cosmos-db-python-getting-started",

.openpublishing.redirection.active-directory.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -10883,7 +10883,7 @@
1088310883
},
1088410884
{
1088510885
"source_path_from_root": "/articles/active-directory/cloud-infrastructure-entitlement-management/product-integrations.md",
10886-
"redirect_url": "/azure/active-directory/fundamentals/cloud-infrastructure-entitlement-management",
10886+
"redirect_url": "/azure/active-directory/cloud-infrastructure-entitlement-management",
1088710887
"redirect_document_id": false
1088810888
}
1088910889

.openpublishing.redirection.json

Lines changed: 45 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,20 @@
11
{
22
"redirections": [
3+
{
4+
"source_path": "articles/visual-studio/vs-storage-cloud-services-getting-started-blobs.md",
5+
"redirect_url": "/previous-versions/azure/visual-studio/vs-storage-cloud-services-getting-started-blobs",
6+
"redirect_document_id": false
7+
},
8+
{
9+
"source_path": "articles/visual-studio/vs-storage-cloud-services-getting-started-queues.md",
10+
"redirect_url": "/previous-versions/azure/visual-studio/vs-storage-cloud-services-getting-started-queues",
11+
"redirect_document_id": false
12+
},
13+
{
14+
"source_path": "articles/visual-studio/vs-storage-cloud-services-getting-started-tables.md",
15+
"redirect_url": "/previous-versions/azure/visual-studio/vs-storage-cloud-services-getting-started-tables",
16+
"redirect_document_id": false
17+
},
318
{
419
"source_path": "articles/automanage/automanage-virtual-machines.md",
520
"redirect_url": "/azure/automanage/index",
@@ -29124,6 +29139,11 @@
2912429139
"redirect_url": "/azure/iot-dps/quick-enroll-device-tpm",
2912529140
"redirect_document_id": false
2912629141
},
29142+
{
29143+
"source_path_from_root": "/articles/iot-dps/how-to-use-custom-allocation-policies.md",
29144+
"redirect_url": "/azure/iot-dps/tutorial-custom-allocation-policies",
29145+
"redirect_document_id": false
29146+
},
2912729147
{
2912829148
"source_path_from_root": "/articles/app-service/environment/app-service-app-service-environment-web-application-firewall.md",
2912929149
"redirect_url": "/azure/app-service/environment/integrate-with-application-gateway",
@@ -29363,6 +29383,31 @@
2936329383
"source_path": "articles/aks/howto-deploy-java-liberty-app-with-postgresql.md",
2936429384
"redirect_url": "/azure/developer/java/ee/howto-deploy-java-liberty-app-manual",
2936529385
"redirect_document_id": false
29386+
},
29387+
{
29388+
"source_path": "articles/virtual-machines/workloads/redhat/jboss-eap-on-rhel.md",
29389+
"redirect_url": "/azure/developer/java/ee/jboss-on-azure",
29390+
"redirect_document_id": false
29391+
},
29392+
{
29393+
"source_path": "articles/virtual-machines/workloads/redhat/jboss-eap-marketplace-image.md",
29394+
"redirect_url": "/azure/developer/java/ee/jboss-on-azure",
29395+
"redirect_document_id": false
29396+
},
29397+
{
29398+
"source_path": "articles/virtual-machines/workloads/redhat/jboss-eap-on-azure-best-practices.md",
29399+
"redirect_url": "/azure/developer/java/ee/jboss-on-azure",
29400+
"redirect_document_id": false
29401+
},
29402+
{
29403+
"source_path": "articles/virtual-machines/workloads/redhat/jboss-eap-on-azure-migration.md",
29404+
"redirect_url": "/azure/developer/java/ee/jboss-on-azure",
29405+
"redirect_document_id": false
29406+
},
29407+
{
29408+
"source_path": "articles/virtual-machines/workloads/redhat/wildfly-on-centos.md",
29409+
"redirect_url": "/azure/developer/java/ee/jboss-on-azure",
29410+
"redirect_document_id": false
2936629411
}
2936729412
]
2936829413
}

.openpublishing.redirection.virtual-desktop.json

Lines changed: 6 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -29,6 +29,11 @@
2929
"source_path_from_root": "/articles/virtual-desktop/shortpath-public.md",
3030
"redirect_url": "/azure/virtual-desktop/rdp-shortpath",
3131
"redirect_document_id": false
32-
}
32+
},
33+
{
34+
"source_path_from_root": "/articles/virtual-machines/windows/using-visual-studio-vm.md",
35+
"redirect_url": "/visualstudio/install/using-visual-studio-vm",
36+
"redirect_document_id": false
37+
}
3338
]
3439
}

articles/active-directory-domain-services/troubleshoot-alerts.md

Lines changed: 4 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -10,7 +10,7 @@ ms.service: active-directory
1010
ms.subservice: domain-services
1111
ms.workload: identity
1212
ms.topic: troubleshooting
13-
ms.date: 08/17/2022
13+
ms.date: 09/20/2022
1414
ms.author: justinha
1515

1616
---
@@ -193,7 +193,9 @@ The managed domain's health automatically updates itself within two hours and re
193193

194194
### Resolution
195195

196-
This error is unrecoverable. To resolve the alert, [delete your existing managed domain](delete-aadds.md) and recreate it. If you have trouble deleting the managed domain, [open an Azure support request][azure-support] for additional troubleshooting assistance.
196+
Azure AD DS creates additional resources to function properly, such as public IP addresses, virtual network interfaces, and a load balancer. If any of these resources are modified, the managed domain is in an unsupported state and can't be managed. For more information about these resources, see [Network resources used by Azure AD DS](network-considerations.md#network-resources-used-by-azure-ad-ds).
197+
198+
This alert is generated when one of these required resources is modified and can't automatically be recovered by Azure AD DS. To resolve the alert, [open an Azure support request][azure-support] to fix the instance.
197199

198200
## AADDS114: Subnet invalid
199201

articles/active-directory/authentication/concept-fido2-hardware-vendor.md

Lines changed: 37 additions & 23 deletions
Original file line numberDiff line numberDiff line change
@@ -15,47 +15,61 @@ ms.collection: M365-identity-device-management
1515

1616
Most hacking related breaches use either stolen or weak passwords. Often, IT will enforce stronger password complexity or frequent password changes to reduce the risk of a security incident. However, this increases help desk costs and leads to poor user experiences as users are required to memorize or store new, complex passwords.
1717

18-
FIDO2 security keys offer an alternative. FIDO2 security keys can replace weak credentials with strong hardware-backed public/private-key credentials which cannot be reused, replayed, or shared across services. Security keys support shared device scenarios, allowing you to carry your credential with you and safely authenticate to an Azure Active Directory joined Windows 10 device that’s part of your organization.
18+
FIDO2 security keys offer an alternative. FIDO2 security keys can replace weak credentials with strong hardware-backed public/private-key credentials which can't be reused, replayed, or shared across services. Security keys support shared device scenarios, allowing you to carry your credential with you and safely authenticate to an Azure Active Directory joined Windows 10 device that’s part of your organization.
1919

2020
Microsoft partners with FIDO2 security key vendors to ensure that security devices work on Windows, the Microsoft Edge browser, and online Microsoft accounts, to enable strong password-less authentication.
2121

2222
You can become a Microsoft-compatible FIDO2 security key vendor through the following process. Microsoft doesn't commit to do go-to-market activities with the partner and will evaluate partner priority based on customer demand.
2323

24-
1. First, your authenticator needs to have a FIDO2 certification. We will not be able to work with providers who do not have a FIDO2 certification. To learn more about the certification, please visit this website: [https://fidoalliance.org/certification/](https://fidoalliance.org/certification/)
24+
1. First, your authenticator needs to have a FIDO2 certification. We won't be able to work with providers who don't have a FIDO2 certification. To learn more about the certification, please visit this website: [https://fidoalliance.org/certification/](https://fidoalliance.org/certification/)
2525
2. After you have a FIDO2 certification, please fill in your request to our form here: [https://forms.office.com/r/NfmQpuS9hF](https://forms.office.com/r/NfmQpuS9hF). Our engineering team will only test compatibility of your FIDO2 devices. We won't test security of your solutions.
2626
3. Once we confirm a move forward to the testing phase, the process usually take about 3-6 months. The steps usually involve:
2727
- Initial discussion between Microsoft and your team.
2828
- Verify FIDO Alliance Certification or the path to certification if not complete
2929
- Receive an overview of the device from the vendor
3030
- Microsoft will share our test scripts with you. Our engineering team will be able to answer questions if you have any specific needs.
31-
- You will complete and send all passed results to Microsoft Engineering team
31+
- You'll complete and send all passed results to Microsoft Engineering team
3232
4. Upon successful passing of all tests by Microsoft Engineering team, Microsoft will confirm vendor's device is listed in [the FIDO MDS](https://fidoalliance.org/metadata/).
3333
5. Microsoft will add your FIDO2 Security Key on Azure AD backend and to our list of approved FIDO2 vendors.
3434

3535
## Current partners
3636

3737
The following table lists partners who are Microsoft-compatible FIDO2 security key vendors.
3838

39-
| **Provider** | **Link** |
40-
| --- | --- |
41-
| AuthenTrend | [https://authentrend.com/about-us/#pg-35-3](https://authentrend.com/about-us/#pg-35-3) |
42-
| Ensurity | [https://www.ensurity.com/contact](https://www.ensurity.com/contact) |
43-
| Excelsecu | [https://www.excelsecu.com/productdetail/esecufido2secu.html](https://www.excelsecu.com/productdetail/esecufido2secu.html) |
44-
| Feitian | [https://ftsafe.us/pages/microsoft](https://ftsafe.us/pages/microsoft) |
45-
| Go-Trust ID | [https://www.gotrustid.com/](https://www.gotrustid.com/idem-key) |
46-
| HID | [https://www.hidglobal.com/contact-us](https://www.hidglobal.com/contact-us) |
47-
| Hypersecu | [https://www.hypersecu.com/hyperfido](https://www.hypersecu.com/hyperfido) |
48-
| IDmelon Technologies Inc. | [https://www.idmelon.com/#idmelon](https://www.idmelon.com/#idmelon) |
49-
| Kensington | [https://www.kensington.com/solutions/product-category/why-biometrics/](https://www.kensington.com/solutions/product-category/why-biometrics/) |
50-
| KONA I | [https://konai.com/business/security/fido](https://konai.com/business/security/fido) |
51-
| Nymi | [https://www.nymi.com/product](https://www.nymi.com/product) |
52-
| OneSpan Inc. | [https://www.onespan.com/products/fido](https://www.onespan.com/products/fido) |
53-
| Thales | [https://cpl.thalesgroup.com/access-management/authenticators/fido-devices](https://cpl.thalesgroup.com/access-management/authenticators/fido-devices) |
54-
| Thetis | [https://thetis.io/collections/fido2](https://thetis.io/collections/fido2) |
55-
| Token2 Switzerland | [https://www.token2.swiss/shop/product/token2-t2f2-alu-fido2-u2f-and-totp-security-key](https://www.token2.swiss/shop/product/token2-t2f2-alu-fido2-u2f-and-totp-security-key) |
56-
| TrustKey Solutions | [https://www.trustkeysolutions.com/security-keys/](https://www.trustkeysolutions.com/security-keys/) |
57-
| VinCSS | [https://passwordless.vincss.net](https://passwordless.vincss.net/) |
58-
| Yubico | [https://www.yubico.com/solutions/passwordless/](https://www.yubico.com/solutions/passwordless/) |
39+
| Provider | Biometric | USB | NFC | BLE | FIPS Certified | Contact |
40+
|---------------------------|:-----------------:|:---:|:---:|:---:|:--------------:|-----------------------------------------------------------------------------------------------------|
41+
| AuthenTrend | ![y] | ![y]| ![y]| ![y]| ![n] | https://authentrend.com/about-us/#pg-35-3 |
42+
| Ciright | ![n] | ![n]| ![y]| ![n]| ![n] | https://www.cyberonecard.com/ |
43+
| Crayonic | ![y] | ![n]| ![y]| ![y]| ![n] | https://www.crayonic.com/keyvault |
44+
| Ensurity | ![y] | ![y]| ![n]| ![n]| ![n] | https://www.ensurity.com/contact |
45+
| Excelsecu | ![y] | ![y]| ![y]| ![y]| ![n] | https://www.excelsecu.com/productdetail/esecufido2secu.html |
46+
| Feitian | ![y] | ![y]| ![y]| ![y]| ![y] | https://shop.ftsafe.us/pages/microsoft |
47+
| Fortinet | ![n] | ![y]| ![n]| ![n]| ![n] | https://www.fortinet.com/ |
48+
| Giesecke + Devrient (G+D) | ![y] | ![y]| ![y]| ![y]| ![n] | https://www.gi-de.com/en/identities/enterprise-security/hardware-based-authentication |
49+
| GoTrustID Inc. | ![n] | ![y]| ![y]| ![y]| ![n] | https://www.gotrustid.com/idem-key |
50+
| HID | ![n] | ![y]| ![y]| ![n]| ![n] | https://www.hidglobal.com/contact-us |
51+
| Hypersecu | ![n] | ![y]| ![n]| ![n]| ![n] | https://www.hypersecu.com/hyperfido |
52+
| IDmelon Technologies Inc. | ![y] | ![y]| ![y]| ![y]| ![n] | https://www.idmelon.com/#idmelon |
53+
| Kensington | ![y] | ![y]| ![n]| ![n]| ![n] | https://www.kensington.com/solutions/product-category/why-biometrics/ |
54+
| KONA I | ![y] | ![n]| ![y]| ![y]| ![n] | https://konai.com/business/security/fido |
55+
| NeoWave | ![n] | ![y]| ![y]| ![n]| ![n] | https://neowave.fr/en/products/fido-range/ |
56+
| Nymi | ![y] | ![n]| ![y]| ![n]| ![n] | https://www.nymi.com/nymi-band |
57+
| Octatco | ![y] | ![y]| ![n]| ![n]| ![n] | https://octatco.com/ |
58+
| OneSpan Inc. | ![n] | ![y]| ![n]| ![y]| ![n] | https://www.onespan.com/products/fido |
59+
| Swissbit | ![n] | ![y]| ![y]| ![n]| ![n] | https://www.swissbit.com/en/products/ishield-fido2/ |
60+
| Thales Group | ![n] | ![y]| ![y]| ![n]| ![y] | https://cpl.thalesgroup.com/access-management/authenticators/fido-devices |
61+
| Thetis | ![y] | ![y]| ![y]| ![y]| ![n] | https://thetis.io/collections/fido2 |
62+
| Token2 Switzerland | ![y] | ![y]| ![y]| ![n]| ![n] | https://www.token2.swiss/shop/product/token2-t2f2-alu-fido2-u2f-and-totp-security-key |
63+
| TrustKey Solutions | ![y] | ![y]| ![n]| ![n]| ![n] | https://www.trustkeysolutions.com/security-keys/ |
64+
| VinCSS | ![n] | ![y]| ![n]| ![n]| ![n] | https://passwordless.vincss.net |
65+
| Yubico | ![y] | ![y]| ![y]| ![n]| ![y] | https://www.yubico.com/solutions/passwordless/ |
66+
67+
68+
69+
<!--Image references-->
70+
[y]: ./media/fido2-compatibility/yes.png
71+
[n]: ./media/fido2-compatibility/no.png
72+
5973

6074
## Next steps
6175

articles/active-directory/develop/reference-aadsts-error-codes.md

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -348,6 +348,7 @@ The `error` field has several possible values - review the protocol documentatio
348348
| AADSTS700022 | InvalidMultipleResourcesScope - The provided value for the input parameter scope isn't valid because it contains more than one resource. |
349349
| AADSTS700023 | InvalidResourcelessScope - The provided value for the input parameter scope isn't valid when request an access token. |
350350
| AADSTS7000215 | Invalid client secret is provided. Developer error - the app is attempting to sign in without the necessary or correct authentication parameters.|
351+
| AADSTS7000218 | The request body must contain the following parameter: 'client_assertion' or 'client_secret'. |
351352
| AADSTS7000222 | InvalidClientSecretExpiredKeysProvided - The provided client secret keys are expired. Visit the Azure portal to create new keys for your app, or consider using certificate credentials for added security: [https://aka.ms/certCreds](./active-directory-certificate-credentials.md) |
352353
| AADSTS700005 | InvalidGrantRedeemAgainstWrongTenant - Provided Authorization Code is intended to use against other tenant, thus rejected. OAuth2 Authorization Code must be redeemed against same tenant it was acquired for (/common or /{tenant-ID} as appropriate) |
353354
| AADSTS1000000 | UserNotBoundError - The Bind API requires the Azure AD user to also authenticate with an external IDP, which hasn't happened yet. |

0 commit comments

Comments
 (0)