You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
# Customer Lockbox for Microsoft Azure alternate email notifications (public preview)
12
12
13
13
> [!NOTE]
14
14
> To use this feature, your organization must have an [Azure support plan](https://azure.microsoft.com/support/plans/) with a minimal level of **Developer**.
15
15
16
-
Customer Lockbox for Microsoft Azure is launching a new feature that enables customers to use alternate email IDs for getting lockbox notifications. This enables Customer Lockbox customers to receive notifications in scenarios where their Azure account is not email enabled or if they have a service principal defined as the tenant admin or subscription owner.
16
+
Customer Lockbox for Microsoft Azure is launching a new feature that enables customers to use alternate email IDs for getting Customer Lockbox notifications. This enables Customer Lockbox for Microsoft Azure customers to receive notifications in scenarios where their Azure account is not email enabled or if they have a service principal defined as the tenant admin or subscription owner.
17
17
18
18
> [!IMPORTANT]
19
-
> This feature only enables Lockbox notifications to be sent to alternate email IDs. It does not enable alternate users to act as approvers for Lockbox requests.
19
+
> This feature only enables Customer Lockbox notifications to be sent to alternate email IDs. It does not enable alternate users to act as approvers for Customer Lockbox requests.
20
20
>
21
-
> For example, Alice has the subscription owner role for subscription X and she adds Bob's email address as alternate email/other email in her user profile who has a reader role. When a lockbox request is created for a resource scoped to subscription 'X', Bob will receive the email notification, but he'll not be able to approve/reject the Lockbox request as he does not have the required privileges for it (subscription owner role).
21
+
> For example, Alice has the subscription owner role for subscription X and she adds Bob's email address as alternate email/other email in her user profile who has a reader role. When a Customer Lockbox request is created for a resource scoped to subscription 'X', Bob will receive the email notification, but he'll not be able to approve/reject the Customer Lockbox request as he does not have the required privileges for it (subscription owner role).
22
22
23
23
## Prerequisites
24
24
25
-
To take advantage of the Azure Lockbox alternate email feature, you must have:
25
+
To take advantage of the Customer Lockbox for Microsoft Azure alternate email feature, you must have:
26
26
27
-
- A Microsoft Entra ID tenant that has Lockbox enabled on it.
27
+
- A Microsoft Entra ID tenant that has Customer Lockbox for Microsoft Azure enabled on it.
28
28
- A Developer or above Azure support plan.
29
29
- Role Assignments:
30
30
- A user account with Tenant admin/privileged authentication administrator/User administrator role to update user settings.
31
-
-[Optional] Subscription owner or the new Azure Customer Lockbox Approver for Subscription role if you’d like to approve/reject Lockbox requests.
31
+
-[Optional] Subscription owner or the new Azure Customer Lockbox Approver for Subscription role if you’d like to approve/reject Customer Lockbox requests.
32
32
33
33
## Set up
34
34
35
-
Here are the steps to set up the Azure Lockbox alternate email feature.
35
+
Here are the steps to set up the Customer Lockbox for Microsoft Azure alternate email feature.
36
36
37
37
1. Access the [Azure portal](https://portal.azure.com/).
38
38
1. Sign in with the user account with tenant/privileged authentication administrator/User administrator role privileges.
1. Search for the user for whom you want to add alternate email address.
42
42
43
43
> [!NOTE]
44
44
> Please note that this user must have tenant admin/subscription owner/ Azure Customer Lockbox Approver for Subscription role privileges to act on Lockbox requests.
1. Anytime a lockbox request is triggered and if the above user is identified as a Lockbox approver, the Lockbox email notification will be sent to both primary and other email addresses, notifying that the Microsoft Support is trying to access a resource within their tenant, and they should take an action by logging into Azure portal to approve/reject the request. Here is an example screenshot:
1. Anytime a lockbox request is triggered and if the above user is identified as a Lockbox approver, the Lockbox email notification is sent to both primary and other email addresses, notifying that the Microsoft Support is trying to access a resource within their tenant, and they should take an action by logging into Azure portal to approve/reject the request. Here is an example screenshot:
summary: This article answers frequently asked questions about Customer Lockbox.
11
+
title: Customer Lockbox for Microsoft Azure frequently asked questions
12
+
summary: This article answers frequently asked questions about Customer Lockbox for Microsoft Azure.
13
13
14
14
sections:
15
15
- name: General
16
16
questions:
17
17
- question: |
18
-
Can I enable lockbox at management group or subscription level?
18
+
Can I enable Customer Lockbox for Microsoft Azure at management group or subscription level?
19
19
answer: |
20
-
No, Lockbox can only be enabled at tenant-level, and is applicable to all the subscriptions and resources under that tenant.
20
+
No, Customer Lockbox for Microsoft Azure can only be enabled at tenant-level, and is applicable to all the subscriptions and resources under that tenant.
21
21
- question: |
22
22
What does Microsoft do when a customer rejects a Customer Lockbox request?
23
23
answer: |
24
24
If a customer rejects a Customer Lockbox request, no access to customer content occurs. If a user in your organization continues to experience a service issue requiring Microsoft to access customer content to resolve the issue, then the service issue might persist and Microsoft will inform the user about this.
25
25
- question: |
26
-
Can I assign the lockbox approver role at the management group level?
26
+
Can I assign the Customer Lockbox approver role at the management group level?
27
27
answer: |
28
-
No, role assignments scoped to management groups are not supported in lockbox at this time.
28
+
No, role assignments scoped to management groups are not supported in Customer Lockbox for Microsoft Azure at this time.
29
29
- question: |
30
-
Can I use PIM to activate the lockbox approver role after a lockbox request is initiated?
30
+
Can I use PIM to activate the Customer Lockbox approver role after a Customer Lockbox request is initiated?
31
31
answer: |
32
-
Role assignments must be in place before Lockbox starts to process a request. Any role assignments made after Lockbox starts to process a given request will not be recognized by Lockbox. Because of this, to use PIM eligible assignments for the lockbox approver role, users are required to activate the role before the Customer Lockbox request is initiated.
32
+
Role assignments must be in place before Customer Lockbox for Microsoft Azure starts to process a request. Any role assignments made after Customer Lockbox for Microsoft Azure starts to process a given request will not be recognized. Because of this, to use PIM eligible assignments for the Customer Lockbox approver role, users are required to activate the role before the Customer Lockbox request is initiated.
33
33
34
34
- name: Customer Lockbox Approver Role for Subscriptions (public preview)
35
35
questions:
36
36
- question: |
37
-
Can I use the new lockbox approver role for tenant-scoped requests as well?
37
+
Can I use the new Customer Lockbox approver role for tenant-scoped requests as well?
38
38
answer: |
39
-
No, Azure Customer Lockbox Approver for Subscription role works only for subscription-scoped requests. The Lockbox team will be creating a lesser privilege role for tenant-scoped requests in subsequent releases.
39
+
No, Azure Customer Lockbox Approver for Subscription role works only for subscription-scoped requests. The Customer Lockbox for Microsoft Azure team will be creating a lesser privilege role for tenant-scoped requests in subsequent releases.
40
40
- question: |
41
-
Can I use the new lockbox approver role with Microsoft Purview Customer Lockbox or Customer Lockbox for Power Platform and Dynamics 365?
41
+
Can I use the new Customer Lockbox approver role with Microsoft Purview Customer Lockbox or Customer Lockbox for Power Platform and Dynamics 365?
42
42
answer: |
43
43
No, the Azure Customer Lockbox Approver for Subscription role works only for subscription-scoped requests created by Customer Lockbox for Microsoft Azure.
44
44
- question: |
45
-
Can I use PIM to activate the new lockbox approver role after a lockbox request is initiated?
45
+
Can I use PIM to activate the new Customer Lockbox approver role after a Customer Lockbox request is initiated?
46
46
answer: |
47
-
Role assignments must be in place before Lockbox starts to process a request. Any role assignments made after Lockbox starts to process a given request will not be recognized by Lockbox. Because of this, to use PIM eligible assignments for the lockbox approver role, users are required to activate the role before the Customer Lockbox request is initiated.
47
+
Role assignments must be in place before Customer Lockbox starts to process a request. Any role assignments made after Customer Lockbox for Microsoft Azure starts to process a given request will not be recognized. Because of this, to use PIM eligible assignments for the Customer Lockbox approver role, users are required to activate the role before the Customer Lockbox request is initiated.
48
48
49
49
- name: Alternative email feature (public preview)
50
50
questions:
51
51
- question: |
52
52
Can I add a different user email address as an alternate email to another user's account?
53
53
answer: |
54
-
Yes, you can add any email address in the other emails field to be used as alternate email for receiving lockbox notifications.
54
+
Yes, you can add any email address in the other emails field to be used as alternate email for receiving Customer Lockbox notifications.
55
55
- question: |
56
-
If I add a second user's email address as an alternate email to an existing lockbox approver user's account, will the second user be able to see and approve/reject lockbox requests?
56
+
If I add a second user's email address as an alternate email to an existing Customer Lockbox approver user's account, will the second user be able to see and approve/reject Customer Lockbox requests?
57
57
answer: |
58
-
No, this feature only allows customers to receive lockbox request notifications on alternate email addresses, but it does not provide the ability to configure other users as lockbox approvers. For example, Alice has the subscription owner role for subscription X and she adds Bob's email address as alternate email/other email in her user profile who has a reader role. When a lockbox request is created for a resource scoped to subscription ‘X', Bob will receive the email notification, but he'll not be able to approve/reject the Lockbox request as he does not have the required privileges for it (subscription owner role).
58
+
No, this feature only allows customers to receive Customer Lockbox request notifications on alternate email addresses, but it does not provide the ability to configure other users as Customer Lockbox approvers. For example, Alice has the subscription owner role for subscription X and she adds Bob's email address as alternate email/other email in her user profile who has a reader role. When a Customer Lockbox request is created for a resource scoped to subscription ‘X', Bob will receive the email notification, but he'll not be able to approve/reject the Customer Lockbox request as he does not have the required privileges for it (subscription owner role).
59
59
- question: |
60
60
Can I add more than one alternate email address to a user account?
61
61
answer: |
62
-
You can add multiple email addresses in the other field but currently lockbox supports sending notifications only to the first email address in ‘other emails' despite multiple email ids configured.
62
+
You can add multiple email addresses in the other field but currently Customer Lockbox for Microsoft Azure supports sending notifications only to the first email address in "other emails" despite multiple email ids configured.
63
63
- question: |
64
64
Can I use alternate email notification functionality with Microsoft Purview Customer Lockbox or Customer Lockbox for Power Platform and Dynamics 365?
65
65
answer: |
66
66
No, this feature is limited to Customer Lockbox for Microsoft Azure.
67
67
- question: |
68
-
Will the alternate email notification work for both tenant-scoped and subscription-scoped lockbox requests?
68
+
Will the alternate email notification work for both tenant-scoped and subscription-scoped Customer Lockbox requests?
69
69
answer: |
70
-
Yes, alternate email notifications will work for all lockbox requests.ents for the lockbox approver role, users are required to activate the role before the Customer Lockbox request is initiated.
70
+
Yes, alternate email notifications will work for all Customer Lockbox requests.
0 commit comments