Skip to content

Commit 6693205

Browse files
committed
update
1 parent 0e061d0 commit 6693205

File tree

4 files changed

+71
-71
lines changed

4 files changed

+71
-71
lines changed

articles/security/fundamentals/TOC.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -177,7 +177,7 @@
177177
href: database-security-checklist.md
178178
- name: Storage security guide
179179
href: ../../storage/blobs/security-recommendations.md?toc=/azure/security/fundamentals/toc.json&bc=/azure/security/breadcrumb/toc.json
180-
- name: Customer Lockbox
180+
- name: Customer Lockbox for Microsoft Azure
181181
items:
182182
- name: Overview
183183
href: customer-lockbox-overview.md
Lines changed: 22 additions & 22 deletions
Original file line numberDiff line numberDiff line change
@@ -1,67 +1,67 @@
11
---
2-
title: Azure Lockbox alternate email feature
3-
description: Azure Lockbox alternate email feature
2+
title: Customer Lockbox for Microsoft Azure alternate email feature
3+
description: Azre LockboxCustomer Lockbox for Microsoft Azure alternate email feature
44
author: msmbaldwin
55
ms.service: information-protection
66
ms.topic: article
77
ms.author: mbaldwin
88
ms.date: 03/15/2024
99
---
1010

11-
# Azure Lockbox alternate email notifications (public preview)
11+
# Customer Lockbox for Microsoft Azure alternate email notifications (public preview)
1212

1313
> [!NOTE]
1414
> To use this feature, your organization must have an [Azure support plan](https://azure.microsoft.com/support/plans/) with a minimal level of **Developer**.
1515
16-
Customer Lockbox for Microsoft Azure is launching a new feature that enables customers to use alternate email IDs for getting lockbox notifications. This enables Customer Lockbox customers to receive notifications in scenarios where their Azure account is not email enabled or if they have a service principal defined as the tenant admin or subscription owner.
16+
Customer Lockbox for Microsoft Azure is launching a new feature that enables customers to use alternate email IDs for getting Customer Lockbox notifications. This enables Customer Lockbox for Microsoft Azure customers to receive notifications in scenarios where their Azure account is not email enabled or if they have a service principal defined as the tenant admin or subscription owner.
1717

1818
> [!IMPORTANT]
19-
> This feature only enables Lockbox notifications to be sent to alternate email IDs. It does not enable alternate users to act as approvers for Lockbox requests.
19+
> This feature only enables Customer Lockbox notifications to be sent to alternate email IDs. It does not enable alternate users to act as approvers for Customer Lockbox requests.
2020
>
21-
> For example, Alice has the subscription owner role for subscription X and she adds Bob's email address as alternate email/other email in her user profile who has a reader role. When a lockbox request is created for a resource scoped to subscription 'X', Bob will receive the email notification, but he'll not be able to approve/reject the Lockbox request as he does not have the required privileges for it (subscription owner role).
21+
> For example, Alice has the subscription owner role for subscription X and she adds Bob's email address as alternate email/other email in her user profile who has a reader role. When a Customer Lockbox request is created for a resource scoped to subscription 'X', Bob will receive the email notification, but he'll not be able to approve/reject the Customer Lockbox request as he does not have the required privileges for it (subscription owner role).
2222
2323
## Prerequisites
2424

25-
To take advantage of the Azure Lockbox alternate email feature, you must have:
25+
To take advantage of the Customer Lockbox for Microsoft Azure alternate email feature, you must have:
2626

27-
- A Microsoft Entra ID tenant that has Lockbox enabled on it.
27+
- A Microsoft Entra ID tenant that has Customer Lockbox for Microsoft Azure enabled on it.
2828
- A Developer or above Azure support plan.
2929
- Role Assignments:
3030
- A user account with Tenant admin/privileged authentication administrator/User administrator role to update user settings.
31-
- [Optional] Subscription owner or the new Azure Customer Lockbox Approver for Subscription role if you’d like to approve/reject Lockbox requests.
31+
- [Optional] Subscription owner or the new Azure Customer Lockbox Approver for Subscription role if you’d like to approve/reject Customer Lockbox requests.
3232

3333
## Set up
3434

35-
Here are the steps to set up the Azure Lockbox alternate email feature.
35+
Here are the steps to set up the Customer Lockbox for Microsoft Azure alternate email feature.
3636

3737
1. Access the [Azure portal](https://portal.azure.com/).
3838
1. Sign in with the user account with tenant/privileged authentication administrator/User administrator role privileges.
3939
1. Search for Users at the home page:
40-
:::image type="content" source="./media/customer-lockbox-overview/alt-email-1.png" lightbox="./media/customer-lockbox-overview/alt-email-1.png" alt-text="Alt Email 1":::
40+
:::image type="content" source="./media/customer-lockbox-overview/customer-lockbox-alternative-email-home.png" lightbox="./media/customer-lockbox-overview/customer-lockbox-alternative-email-home.png" alt-text="Alt Email 1":::
4141
1. Search for the user for whom you want to add alternate email address.
4242

4343
> [!NOTE]
4444
> Please note that this user must have tenant admin/subscription owner/ Azure Customer Lockbox Approver for Subscription role privileges to act on Lockbox requests.
4545
46-
:::image type="content" source="./media/customer-lockbox-overview/alt-email-2.png" lightbox="./media/customer-lockbox-overview/alt-email-2.png" alt-text="Alt Email 2":::
46+
:::image type="content" source="./media/customer-lockbox-overview/customer-lockbox-alternative-email-user-search.png" lightbox="./media/customer-lockbox-overview/customer-lockbox-alternative-email-user-search.png" alt-text="Alt Email 2":::
4747
1. Select the user and select on edit properties.
48-
:::image type="content" source="./media/customer-lockbox-overview/alt-email-3.png" lightbox="./media/customer-lockbox-overview/alt-email-3.png" alt-text="Alt Email 3":::
48+
:::image type="content" source="./media/customer-lockbox-overview/customer-lockbox-alternative-email-edit-properties.png" lightbox="./media/customer-lockbox-overview/customer-lockbox-alternative-email-edit-properties.png" alt-text="Alt Email 3":::
4949
1. Navigate to Contact Information Tab
50-
:::image type="content" source="./media/customer-lockbox-overview/alt-email-4.png" lightbox="./media/customer-lockbox-overview/alt-email-4.png" alt-text="Alt Email 4":::
50+
:::image type="content" source="./media/customer-lockbox-overview/customer-lockbox-alternative-email-contact-information.png" lightbox="./media/customer-lockbox-overview/customer-lockbox-alternative-email-contact-information.pngg" alt-text="Alt Email 4":::
5151
1. Select Add email under 'Other emails' category and then select Add.
52-
:::image type="content" source="./media/customer-lockbox-overview/alt-email-5.png" lightbox="./media/customer-lockbox-overview/alt-email-5.png" alt-text="Alt Email 5":::
52+
:::image type="content" source="./media/customer-lockbox-overview/customer-lockbox-alternative-email-add-email.png" lightbox="./media/customer-lockbox-overview/customer-lockbox-alternative-email-add-email.png" alt-text="Alt Email 5":::
5353
1. Add alternate email address in the text field and select save.
54-
:::image type="content" source="./media/customer-lockbox-overview/alt-email-6.png" lightbox="./media/customer-lockbox-overview/alt-email-6.png" alt-text="Alt Email 6":::
54+
:::image type="content" source="./media/customer-lockbox-overview/customer-lockbox-alternative-email-other-email.png" lightbox="./media/customer-lockbox-overview/customer-lockbox-alternative-email-other-email.png" alt-text="Alt Email 6":::
5555
1. Select the save button in the contact information tab to save the updates.
56-
:::image type="content" source="./media/customer-lockbox-overview/alt-email-7.png" lightbox="./media/customer-lockbox-overview/alt-email-7.png" alt-text="Alt Email 7":::
56+
:::image type="content" source="./media/customer-lockbox-overview/customer-lockbox-alternative-email-save.png" lightbox="./media/customer-lockbox-overview/customer-lockbox-alternative-email-save.png" alt-text="Alt Email 7":::
5757
1. The contact information tab for this user should now show updated information with alternate email:
58-
:::image type="content" source="./media/customer-lockbox-overview/alt-email-8.png" lightbox="./media/customer-lockbox-overview/alt-email-8.png" alt-text="Alt Email 8":::
59-
1. Anytime a lockbox request is triggered and if the above user is identified as a Lockbox approver, the Lockbox email notification will be sent to both primary and other email addresses, notifying that the Microsoft Support is trying to access a resource within their tenant, and they should take an action by logging into Azure portal to approve/reject the request. Here is an example screenshot:
60-
:::image type="content" source="./media/customer-lockbox-overview/alt-email-9.png" lightbox="./media/customer-lockbox-overview/alt-email-9.png" alt-text="Alt Email 9":::
58+
:::image type="content" source="./media/customer-lockbox-overview/customer-lockbox-alternative-email-contact-information-updated.png" lightbox="./media/customer-lockbox-overview/customer-lockbox-alternative-email-contact-information-updated.png" alt-text="Alt Email 8":::
59+
1. Anytime a lockbox request is triggered and if the above user is identified as a Lockbox approver, the Lockbox email notification is sent to both primary and other email addresses, notifying that the Microsoft Support is trying to access a resource within their tenant, and they should take an action by logging into Azure portal to approve/reject the request. Here is an example screenshot:
60+
:::image type="content" source="./media/customer-lockbox-overview/customer-lockbox-alternative-email-notification.png" lightbox="./media/customer-lockbox-overview/customer-lockbox-alternative-email-notification.png" alt-text="Alt Email 9":::
6161

6262
## Known Issues
6363

64-
Hefre are the known issues with this feature:
64+
Here are the known issues with this feature:
6565

6666
1. Duplicate emails are sent if the value for primary and other email is same.
6767
1. Notifications are sent to only the first email address in 'other emails' despite multiple email IDs configured in other email field.
@@ -70,4 +70,4 @@ Hefre are the known issues with this feature:
7070
## Next steps
7171

7272
- [Customer Lockbox for Microsoft Azure](customer-lockbox-overview.md)
73-
- [Frequently asked questions](customer-lockbox-faq.yml)
73+
- [Customer Lockbox for Microsoft Azure frequently asked questions](customer-lockbox-faq.yml)
Lines changed: 22 additions & 22 deletions
Original file line numberDiff line numberDiff line change
@@ -1,77 +1,77 @@
11
### YamlMime:FAQ
22
metadata:
3-
title: Customer Lockbox FAQ
3+
title: Customer Lockbox for Microsoft Azure frequently asked questions
44
description: Frequently asked questions about Customer Lockbox
55
services: information-protection
66
ms.service: information-protection
77
ms.topic: overview
88
ms.date: 03/15/2024
99
author: msmbaldwin
1010
ms.author: mbaldwin
11-
title: Customer Lockbox frequently Asked questions
12-
summary: This article answers frequently asked questions about Customer Lockbox.
11+
title: Customer Lockbox for Microsoft Azure frequently asked questions
12+
summary: This article answers frequently asked questions about Customer Lockbox for Microsoft Azure.
1313

1414
sections:
1515
- name: General
1616
questions:
1717
- question: |
18-
Can I enable lockbox at management group or subscription level?
18+
Can I enable Customer Lockbox for Microsoft Azure at management group or subscription level?
1919
answer: |
20-
No, Lockbox can only be enabled at tenant-level, and is applicable to all the subscriptions and resources under that tenant.
20+
No, Customer Lockbox for Microsoft Azure can only be enabled at tenant-level, and is applicable to all the subscriptions and resources under that tenant.
2121
- question: |
2222
What does Microsoft do when a customer rejects a Customer Lockbox request?
2323
answer: |
2424
If a customer rejects a Customer Lockbox request, no access to customer content occurs. If a user in your organization continues to experience a service issue requiring Microsoft to access customer content to resolve the issue, then the service issue might persist and Microsoft will inform the user about this.
2525
- question: |
26-
Can I assign the lockbox approver role at the management group level?
26+
Can I assign the Customer Lockbox approver role at the management group level?
2727
answer: |
28-
No, role assignments scoped to management groups are not supported in lockbox at this time.
28+
No, role assignments scoped to management groups are not supported in Customer Lockbox for Microsoft Azure at this time.
2929
- question: |
30-
Can I use PIM to activate the lockbox approver role after a lockbox request is initiated?
30+
Can I use PIM to activate the Customer Lockbox approver role after a Customer Lockbox request is initiated?
3131
answer: |
32-
Role assignments must be in place before Lockbox starts to process a request. Any role assignments made after Lockbox starts to process a given request will not be recognized by Lockbox. Because of this, to use PIM eligible assignments for the lockbox approver role, users are required to activate the role before the Customer Lockbox request is initiated.
32+
Role assignments must be in place before Customer Lockbox for Microsoft Azure starts to process a request. Any role assignments made after Customer Lockbox for Microsoft Azure starts to process a given request will not be recognized. Because of this, to use PIM eligible assignments for the Customer Lockbox approver role, users are required to activate the role before the Customer Lockbox request is initiated.
3333
3434
- name: Customer Lockbox Approver Role for Subscriptions (public preview)
3535
questions:
3636
- question: |
37-
Can I use the new lockbox approver role for tenant-scoped requests as well?
37+
Can I use the new Customer Lockbox approver role for tenant-scoped requests as well?
3838
answer: |
39-
No, Azure Customer Lockbox Approver for Subscription role works only for subscription-scoped requests. The Lockbox team will be creating a lesser privilege role for tenant-scoped requests in subsequent releases.
39+
No, Azure Customer Lockbox Approver for Subscription role works only for subscription-scoped requests. The Customer Lockbox for Microsoft Azure team will be creating a lesser privilege role for tenant-scoped requests in subsequent releases.
4040
- question: |
41-
Can I use the new lockbox approver role with Microsoft Purview Customer Lockbox or Customer Lockbox for Power Platform and Dynamics 365?
41+
Can I use the new Customer Lockbox approver role with Microsoft Purview Customer Lockbox or Customer Lockbox for Power Platform and Dynamics 365?
4242
answer: |
4343
No, the Azure Customer Lockbox Approver for Subscription role works only for subscription-scoped requests created by Customer Lockbox for Microsoft Azure.
4444
- question: |
45-
Can I use PIM to activate the new lockbox approver role after a lockbox request is initiated?
45+
Can I use PIM to activate the new Customer Lockbox approver role after a Customer Lockbox request is initiated?
4646
answer: |
47-
Role assignments must be in place before Lockbox starts to process a request. Any role assignments made after Lockbox starts to process a given request will not be recognized by Lockbox. Because of this, to use PIM eligible assignments for the lockbox approver role, users are required to activate the role before the Customer Lockbox request is initiated.
47+
Role assignments must be in place before Customer Lockbox starts to process a request. Any role assignments made after Customer Lockbox for Microsoft Azure starts to process a given request will not be recognized. Because of this, to use PIM eligible assignments for the Customer Lockbox approver role, users are required to activate the role before the Customer Lockbox request is initiated.
4848
4949
- name: Alternative email feature (public preview)
5050
questions:
5151
- question: |
5252
Can I add a different user email address as an alternate email to another user's account?
5353
answer: |
54-
Yes, you can add any email address in the other emails field to be used as alternate email for receiving lockbox notifications.
54+
Yes, you can add any email address in the other emails field to be used as alternate email for receiving Customer Lockbox notifications.
5555
- question: |
56-
If I add a second user's email address as an alternate email to an existing lockbox approver user's account, will the second user be able to see and approve/reject lockbox requests?
56+
If I add a second user's email address as an alternate email to an existing Customer Lockbox approver user's account, will the second user be able to see and approve/reject Customer Lockbox requests?
5757
answer: |
58-
No, this feature only allows customers to receive lockbox request notifications on alternate email addresses, but it does not provide the ability to configure other users as lockbox approvers. For example, Alice has the subscription owner role for subscription X and she adds Bob's email address as alternate email/other email in her user profile who has a reader role. When a lockbox request is created for a resource scoped to subscription ‘X', Bob will receive the email notification, but he'll not be able to approve/reject the Lockbox request as he does not have the required privileges for it (subscription owner role).
58+
No, this feature only allows customers to receive Customer Lockbox request notifications on alternate email addresses, but it does not provide the ability to configure other users as Customer Lockbox approvers. For example, Alice has the subscription owner role for subscription X and she adds Bob's email address as alternate email/other email in her user profile who has a reader role. When a Customer Lockbox request is created for a resource scoped to subscription ‘X', Bob will receive the email notification, but he'll not be able to approve/reject the Customer Lockbox request as he does not have the required privileges for it (subscription owner role).
5959
- question: |
6060
Can I add more than one alternate email address to a user account?
6161
answer: |
62-
You can add multiple email addresses in the other field but currently lockbox supports sending notifications only to the first email address in other emails' despite multiple email ids configured.
62+
You can add multiple email addresses in the other field but currently Customer Lockbox for Microsoft Azure supports sending notifications only to the first email address in "other emails" despite multiple email ids configured.
6363
- question: |
6464
Can I use alternate email notification functionality with Microsoft Purview Customer Lockbox or Customer Lockbox for Power Platform and Dynamics 365?
6565
answer: |
6666
No, this feature is limited to Customer Lockbox for Microsoft Azure.
6767
- question: |
68-
Will the alternate email notification work for both tenant-scoped and subscription-scoped lockbox requests?
68+
Will the alternate email notification work for both tenant-scoped and subscription-scoped Customer Lockbox requests?
6969
answer: |
70-
Yes, alternate email notifications will work for all lockbox requests.ents for the lockbox approver role, users are required to activate the role before the Customer Lockbox request is initiated.
70+
Yes, alternate email notifications will work for all Customer Lockbox requests.
7171
7272
additionalContent: |
7373
7474
## Next steps
7575
76-
- [Azure Customer Lockbox overview](customer-lockbox-overview.md)
77-
- [Azure Customer Lockbox alternate email notifications](customer-lockbox-overview.md)
76+
- [Customer Lockbox for Microsoft Azure overview](customer-lockbox-overview.md)
77+
- [Customer Lockbox for Microsoft Azure alternate email notifications](customer-lockbox-overview.md)

0 commit comments

Comments
 (0)