You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/active-directory/active-directory-conditional-access-controls.md
+7-3Lines changed: 7 additions & 3 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -14,7 +14,7 @@ ms.devlang: na
14
14
ms.topic: article
15
15
ms.tgt_pltfrm: na
16
16
ms.workload: identity
17
-
ms.date: 02/09/2018
17
+
ms.date: 03/28/2018
18
18
ms.author: markvi
19
19
ms.reviewer: calebb
20
20
@@ -73,11 +73,15 @@ Using multi-factor authentication helps protect resources from being accessed by
73
73
74
74
### Compliant device
75
75
76
-
You can configure conditional access policies that are device-based. The objective of a device-based conditional access policy is to grant access to the configured resources only from trusted devices. Requiring a compliant device is one option you have to define what a trusted device is. For more information, see [set up Azure Active Directory device-based conditional access policies](active-directory-conditional-access-policy-connected-applications.md).
76
+
You can configure conditional access policies that are device-based. The objective of a device-based conditional access policy is to grant access to the configured resources only from trusted devices. Requiring a compliant device is one option you have to define what a trusted device is. If this option is selected, your conditional access policy grants access to access attempts made with devices that are joined to your Azure Active Directory and are marked as compliant by your MDM solution.
77
+
78
+
For more information, see [set up Azure Active Directory device-based conditional access policies](active-directory-conditional-access-policy-connected-applications.md).
77
79
78
80
### Domain-joined device
79
81
80
-
Requiring a domain-joined device is another option you have to configure device-based conditional access policies. This requirement refers to Windows desktops, laptops, and enterprise tablets that are joined to an on-premises Active Directory. For more information, see [set up Azure Active Directory device-based conditional access policies](active-directory-conditional-access-policy-connected-applications.md).
82
+
Requiring a domain-joined device is another option you have to configure device-based conditional access policies. This requirement refers to Windows desktops, laptops, and enterprise tablets that are joined to an on-premises Active Directory. If this option is selected, your conditional access policy grants access to access attempts made with devices that are joined to your on-premises Active Directory and your Azure Active Directory.
83
+
84
+
For more information, see [set up Azure Active Directory device-based conditional access policies](active-directory-conditional-access-policy-connected-applications.md).
Copy file name to clipboardExpand all lines: articles/active-directory/active-directory-tou.md
+36-20Lines changed: 36 additions & 20 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -1,8 +1,7 @@
1
1
---
2
2
title: 'Azure Active Directory Terms of Use| Microsoft Docs'
3
-
description: Azure AD Terms of Use will allow you and your company the ability to provide terms of use to users of Azure AD servcies.
3
+
description: Azure AD Terms of Use will allow you and your company the ability to provide terms of use to users of Azure AD services.
4
4
services: active-directory
5
-
documentationcenter: ''
6
5
author: billmath
7
6
manager: mtillman
8
7
editor: ''
@@ -12,20 +11,20 @@ ms.workload: identity
12
11
ms.tgt_pltfrm: na
13
12
ms.devlang: na
14
13
ms.topic: get-started-article
15
-
ms.date: 03/06/2018
14
+
ms.date: 03/29/2018
16
15
ms.author: billmath
17
16
18
17
---
19
18
20
-
# Azure Active Directory Terms of Use feature (Preview)
21
-
Azure AD Terms of Use provides a simple method organizations can use to present information to end users. This ensures users see relevant disclaimers for legal or compliance requirements.
19
+
# Azure Active Directory Terms of Use feature
20
+
Azure AD Terms of Use provides a simple method organizations can use to present information to end users. This presentation, ensures users see relevant disclaimers for legal or compliance requirements.
22
21
23
-
Azure AD Terms of Use uses the pdf format to present content. This pdf can be any content, such as existing contract documents, allowing you to collect end user agreements during user sign-in. You can use the terms of use for applications, groups of users, or if you have multiple terms of use for different purposes.
22
+
Azure AD Terms of Use uses the pdf format to present content. The pdf can be any content, such as existing contract documents, allowing you to collect end user agreements during user sign-in. You can use the terms of use for applications, groups of users, or if you have multiple terms of use for different purposes.
24
23
25
24
The remainder of this document describes how to get going with Azure AD Terms of Use.
26
25
27
26
## Why use Azure AD Terms of Use
28
-
Finding it difficult to get employee’s or guests to agree to your terms of use before getting access? Need help figuring out who has or hasn’t agreed to your company terms of use? Azure AD Terms of Use provides a simple method organizations can use to present information to end users. This ensures that they see relevant disclaimers for legal or compliance requirements.
27
+
Finding it difficult to get employee’s or guests to agree to your terms of use before getting access? Need help figuring out who has or hasn’t agreed to your company terms of use? Azure AD Terms of Use provides a simple method organizations can use to present information to end users. This presentation, ensures that they see relevant disclaimers for legal or compliance requirements.
29
28
30
29
Azure AD Terms of Use can be used in the following scenarios:
31
30
- General terms of use for all users in your organization.
@@ -51,11 +50,11 @@ Once you have finalized your Terms of Use, use the following procedure to add it
51
50
2. Click Add.</br>
52
51

53
52
3. Enter the **Name** for the Terms of Use
54
-
4. Enter **Display Name**. This header is what users see when they sign in.
53
+
4. Enter **Display Name**. The header is what users see when they sign in.
55
54
5.**Browse** to your finalized terms of use pdf and select it. The recommended font size is 24.
56
55
6.**Select** a language for the terms of use. The language option allows you to upload multiple terms of use, each with a different language. The version of the terms of use that an end user will see will be based on their browser preferences.
57
56
7. Select either on or off for **Require users to expand the terms of use**. If this is set to on, end users will be required to view the terms of use prior to accepting them.
58
-
8. Under the **Conditional Access** section you can **Enforce** the uploaded terms of use by using a template or a custom conditional access policy. Custom conditional access policies enables granular terms of use, down to a specific cloud application or group of users. For more information, see [configuring conditional access policies](active-directory-conditional-access-best-practices.md)
57
+
8. Under the **Conditional Access**, you can **Enforce** the uploaded terms of use by selecting a template from the drop-down or a custom conditional access policy. Custom conditional access policies enables granular terms of use, down to a specific cloud application or group of users. For more information, see [configuring conditional access policies](active-directory-conditional-access-best-practices.md)
59
58
9. Click **Create**.
60
59
10. If you selected a custom conditional access template, then a new screen appears which allows you to customize the CA policy.
61
60
11. You should now see your new Terms of Use.</br>
@@ -72,17 +71,33 @@ You can remove or delete old terms of use using the following procedure:
72
71
4. You should no longer see your new terms of use.
73
72
74
73
74
+
## Viewing current user status
75
+
You will notice that your terms of use shows a count for users who have accepted and declined.
Azure AD Terms of Use provides easy to use auditing so that you can see who has accepted and when they accepted your terms of use. To get started with auditing use the following procedure:
84
+
If you want to view historical acceptances and declines and not just the current status, Azure AD Terms of Use provides easy to use auditing. This auditing allows you to see who has accepted and when they accepted your terms of use.
85
+
86
+
There are two ways in which you can use auditing depending on what you are currently trying to do.
87
+
88
+
89
+
To get started with auditing use the following procedure:
77
90
78
91
### To audit Terms of Use
79
92
1. Navigate to the dashboard at [https://aka.ms/catou](https://aka.ms/catou)
4. From there you can review the terms of use you have accepted.
118
+
4. From there, you can review the terms of use you have accepted.
104
119
105
120
106
121
## Additional information
107
122
The following information is something to be aware of and can assist with using terms of use.
108
123
109
-
Users in scope will need to sign-out and sign-in in order to satisfy a new policy if:
110
-
- a conditional access policy is enabled on a terms of use
111
-
- or a second terms of use is created
112
-
113
-
This is because conditional access policies take effect immediately. When this happens the admin will start to see “sad clouds” or "Azure AD token issues". The admin must sign-out and sign-in again in order to satisfy the new policy.
124
+
>[!IMPORTANT]
125
+
> Users in scope will need to sign-out and sign-in in order to satisfy a new policy if:
126
+
> - a conditional access policy is enabled on a terms of use
127
+
> - or a second terms of use is created
128
+
>
129
+
>Conditional access policies take effect immediately. When this happens the admin will start to see “sad clouds” or "Azure AD token issues". The admin must sign-out and sign-in again in order to satisfy the new policy.
114
130
115
131
116
132
@@ -119,10 +135,10 @@ This is because conditional access policies take effect immediately. When this h
119
135
## Frequently asked questions
120
136
121
137
**Q: How do I see when/if a user has accepted a terms of use?**</br>
122
-
A: A user accepting the terms of use is written to the audit log. You can search the Azure AD audit log to see the results.
138
+
A: You can simply click on the number under accepted next to your terms of use. For more information, see [Viewing current user status](#viewing-current-user-status). Also, a user accepting the terms of use is written to the audit log. You can search the Azure AD audit log to see the results.
123
139
124
140
**Q: If you change the terms of use terms does it require users to accept again?**</br>
125
-
A: Yes, an administrator can change the terms of use terms and it requires re-accepting the new terms.
141
+
A: Yes, an administrator can change the terms of use terms and it requires reaccepting the new terms.
126
142
127
143
**Q: Can a terms of use support multiple languages?**</br>
128
144
A: Yes. Currently there are 18 different languages an administrator can configure for a single terms of use.
0 commit comments