You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
>Get notified about when to revisit this page for updates by copying and pasting this URL: `https://docs.microsoft.com/api/search/rss?search=%22release+notes+for+azure+AD%22&locale=en-us` into your  feed reader.
24
+
>Get notified about when to revisit this page for updates by copying and pasting this URL: `https://docs.microsoft.com/api/search/rss?search=%22Release+notes+-+Azure+Active+Directory%22&locale=en-us` into your  feed reader.
25
25
26
26
Azure AD receives improvements on an ongoing basis. To stay up to date with the most recent developments, this article provides you with information about:
### Creating access review on a group that can be assigned to Azure AD role
77
+
If you are on the newest version of Access Reviews (your reviewers are directed to **My Access** by default) , then only Global Administrator can create access review on role-assignable groups. However, if you are on older version of Access Reviews (your reviewers are directed to the **Access Panel** by default), then both Global Administrator and User Administrator can create access review on role-assignable groups.
78
+
79
+
The new experience will be rolled out to all customers on August 1st, 2020 but if you’d like to upgrade sooner, please make a request here - [Azure AD Access Reviews - Updated reviewer experience in My Access Signup](https://forms.microsoft.com/Pages/ResponsePage.aspx?id=v4j5cvGGr0GRqy180BHbR5dv-S62099HtxdeKIcgO-NUOFJaRDFDWUpHRk8zQ1BWVU1MMTcyQ1FFUi4u).
80
+
81
+
[Learn more about assigning groups to Azure AD roles](https://go.microsoft.com/fwlink/?linkid=2103037).
Copy file name to clipboardExpand all lines: articles/active-directory/hybrid/how-to-connect-sso-quick-start.md
+7-6Lines changed: 7 additions & 6 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -1,5 +1,5 @@
1
1
---
2
-
title: 'Azure AD Connect: Seamless Single Sign-On - quick start | Microsoft Docs'
2
+
title: 'Azure AD Connect: Seamless Single Sign-On - quickstart | Microsoft Docs'
3
3
description: This article describes how to get started with Azure Active Directory Seamless Single Sign-On
4
4
services: active-directory
5
5
keywords: what is Azure AD Connect, install Active Directory, required components for Azure AD, SSO, Single Sign-on
@@ -18,7 +18,7 @@ ms.author: billmath
18
18
ms.collection: M365-identity-device-management
19
19
---
20
20
21
-
# Azure Active Directory Seamless Single Sign-On: Quick start
21
+
# Azure Active Directory Seamless Single Sign-On: Quickstart
22
22
23
23
## Deploy Seamless Single Sign-On
24
24
@@ -32,7 +32,7 @@ Ensure that the following prerequisites are in place:
32
32
33
33
***Set up your Azure AD Connect server**: If you use [Pass-through Authentication](how-to-connect-pta.md) as your sign-in method, no additional prerequisite check is required. If you use [password hash synchronization](how-to-connect-password-hash-synchronization.md) as your sign-in method, and if there is a firewall between Azure AD Connect and Azure AD, ensure that:
34
34
- You use version 1.1.644.0 or later of Azure AD Connect.
35
-
- If your firewall or proxy allows DNS whitelisting, whitelist the connections to the **\*.msappproxy.net** URLs over port 443. If not, allow access to the [Azure datacenter IP ranges](https://www.microsoft.com/download/details.aspx?id=41653), which are updated weekly. This prerequisite is applicable only when you enable the feature. It is not required for actual user sign-ins.
35
+
- If your firewall or proxy allows, add the connections to the allowed list for**\*.msappproxy.net** URLs over port 443. If not, allow access to the [Azure datacenter IP ranges](https://www.microsoft.com/download/details.aspx?id=41653), which are updated weekly. This prerequisite is applicable only when you enable the feature. It is not required for actual user sign-ins.
36
36
37
37
>[!NOTE]
38
38
>Azure AD Connect versions 1.1.557.0, 1.1.558.0, 1.1.561.0, and 1.1.614.0 have a problem related to password hash synchronization. If you _don't_ intend to use password hash synchronization in conjunction with Pass-through Authentication, read the [Azure AD Connect release notes](https://docs.microsoft.com/azure/active-directory/connect/active-directory-aadconnect-version-history#116470) to learn more.
@@ -95,8 +95,9 @@ Follow these instructions to verify that you have enabled Seamless SSO correctly
95
95
96
96
## Step 3: Roll out the feature
97
97
98
-
You can gradually roll out Seamless SSO to your users using the instructions provided below. You start by adding the following Azure AD URL to all or selected users' Intranet zone settings by using Group Policy in Active Directory:
98
+
You can gradually roll out Seamless SSO to your users using the instructions provided below. You start by adding the following Azure AD URLs to all or selected users' Intranet zone settings by using Group Policy in Active Directory:
99
99
100
+
-`https://aadg.windows.net.nsatc.net`
100
101
-`https://autologon.microsoftazuread-sso.com`
101
102
102
103
In addition, you need to enable an Intranet zone policy setting called **Allow updates to status bar via script** through Group Policy.
@@ -186,15 +187,15 @@ If you have overridden the [AuthNegotiateDelegateAllowlist](https://docs.microso
186
187
187
188
#### Microsoft Edge based on Chromium (macOS and other non-Windows platforms)
188
189
189
-
For Microsoft Edge based on Chromium on Mac OS and other non-Windows platforms, refer to [the Microsoft Edge based on Chromium Policy List](https://docs.microsoft.com/DeployEdge/microsoft-edge-policies#authserverallowlist) for information on how to add the Azure AD URL for integrated authentication to your allow-list.
190
+
For Microsoft Edge based on Chromium on macOS and other non-Windows platforms, refer to [the Microsoft Edge based on Chromium Policy List](https://docs.microsoft.com/DeployEdge/microsoft-edge-policies#authserverallowlist) for information on how to add the Azure AD URL for integrated authentication to your allow-list.
190
191
191
192
#### Google Chrome (all platforms)
192
193
193
194
If you have overridden the [AuthNegotiateDelegateWhitelist](https://www.chromium.org/administrators/policy-list-3#AuthNegotiateDelegateWhitelist) or the [AuthServerWhitelist](https://www.chromium.org/administrators/policy-list-3#AuthServerWhitelist) policy settings in your environment, ensure that you add Azure AD's URL (`https://autologon.microsoftazuread-sso.com`) to them as well.
194
195
195
196
#### Google Chrome (macOS and other non-Windows platforms)
196
197
197
-
For Google Chrome on Mac OS and other non-Windows platforms, refer to [The Chromium Project Policy List](https://dev.chromium.org/administrators/policy-list-3#AuthServerWhitelist) for information on how to whitelist the Azure AD URL for integrated authentication.
198
+
For Google Chrome on macOS and other non-Windows platforms, refer to [The Chromium Project Policy List](https://dev.chromium.org/administrators/policy-list-3#AuthServerWhitelist) for information on how to control the allow list for the Azure AD URL for integrated authentication.
198
199
199
200
The use of third-party Active Directory Group Policy extensions to roll out the Azure AD URL to Firefox and Google Chrome on Mac users is outside the scope of this article.
> The **Reply URL** value isn't real. Update this value with the actual reply URL. Contact the [Trelica Client support team](mailto:[email protected]) to get this value. You can also refer to the patterns shown in the **Basic SAML Configuration** section in the Azure portal.
90
+
> [!NOTE]
91
+
> The Reply URL value is not real. Update this value with the actual Reply URL (also known as the ACS).
92
+
> You can find this by logging in to Trelica and going to the [SAML identity providers configuration page](https://app.trelica.com/Admin/Profile/SAML) (Admin > Account > SAML). Click on the copy button next to the **Assertion Consumer Service (ACS) URL** to put this onto the clipboard, ready for pasting into the **Reply URL** text box in Azure AD.
93
+
> Read the [Trelica help documentation](https://docs.trelica.com/admin/saml/azure-ad) or contact the [Trelica Client support team](mailto:[email protected]) if you have questions.
92
94
93
-
1. On the **Set up Single Sign-on with SAML** page, go to the **SAML Signing Certificate** section. To the right of **App Federation Metadata Url**, select the copy button to copy the URL. Save the URL on your computer.
95
+
1. On the **Set up single sign-on with SAML** page, In the **SAML Signing Certificate** section, click the copy button to copy **App Federation Metadata Url** and save it on your computer.
94
96
95
97

96
98
@@ -126,11 +128,11 @@ In this section, you enable B.Simon to use Azure single sign-on by granting acce
126
128
127
129
## Configure Trelica SSO
128
130
129
-
To configure single sign-on on the **Trelica** side, send the copied **App Federation Metadata Url** value to the [Trelica support team](mailto:[email protected]). They configure this setting to have the SAML SSO connection set properly on both sides.
131
+
To configure single sign-on on the **Trelica** side, go to the [SAML identity providers configuration page](https://app.trelica.com/Admin/Profile/SAML) (Admin > Account > SAML). Click on the **New** button. Enter **Azure AD** as the Name and choose **Metadata from url** for the Metadata type. Paste the **App Federation Metadata Url** you took from Azure AD into the **Metadata url** field in Trelica.
130
132
131
-
### Create a Trelica test user
133
+
Read the [Trelica help documentation](https://docs.trelica.com/admin/saml/azure-ad) or contact the [Trelica Client support team](mailto:[email protected]) if you have questions.
132
134
133
-
In this section, you create a user called B.Simon in Trelica.
135
+
### Create a Trelica test user
134
136
135
137
Trelica supports just-in-time user provisioning, which is enabled by default. There's no action for you to take in this section. If a user doesn't already exist in Trelica, a new one is created after authentication.
Copy file name to clipboardExpand all lines: articles/application-gateway/configuration-overview.md
+1-3Lines changed: 1 addition & 3 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -219,9 +219,7 @@ When you create a rule, you choose between [*basic* and *path-based*](https://do
219
219
220
220
#### Order of processing rules
221
221
222
-
For the v1 SKU, pattern matching of incoming requests is processed in the order that the paths are listed in the URL path map of the path-based rule. If a request matches the pattern in two or more paths in the path map, the path that's listed first is matched. And the request is forwarded to the back end that's associated with that path.
223
-
224
-
For the v2 SKU, an exact match is higher priority than path order in the URL path map. If a request matches the pattern in two or more paths, the request is forwarded to the back end that's associated with the path that exactly matches the request. If the path in the incoming request doesn't exactly match any path in the map, pattern matching of the request is processed in the path map order list for the path-based rule.
222
+
For the v1 and v2 SKU, pattern matching of incoming requests is processed in the order that the paths are listed in the URL path map of the path-based rule. If a request matches the pattern in two or more paths in the path map, the path that's listed first is matched. And the request is forwarded to the back end that's associated with that path.
Copy file name to clipboardExpand all lines: articles/azure-monitor/app/app-insights-overview.md
+3-3Lines changed: 3 additions & 3 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -11,7 +11,7 @@ ms.custom: mvc
11
11
Application Insights, a feature of [Azure Monitor](../overview.md), is an extensible Application Performance Management (APM) service for developers and DevOps professionals. Use it to monitor your live applications. It will automatically detect performance anomalies, and includes powerful analytics tools to help you diagnose issues and to understand what users actually do with your app. It's designed to help you continuously improve performance and usability. It works for apps on a wide variety of platforms including .NET, Node.js, Java, and Python hosted on-premises, hybrid, or any public cloud. It integrates with your DevOps process, and has connection points to a variety of development tools. It can monitor and analyze telemetry from mobile apps by integrating with Visual Studio App Center.
12
12
13
13
## How does Application Insights work?
14
-
You install a small instrumentation package (SDK) in your application or enable Application Insights codelessly when [supported](../../azure-monitor/app/platforms.md). The instrumentation monitors your app and directs the telemetry data to an Azure Application Insights Resource using a unique GUID that we refer to as an Instrumentation Key.
14
+
You install a small instrumentation package (SDK) in your application or enable Application Insights using the Application Insights Agent when [supported](../../azure-monitor/app/platforms.md). The instrumentation monitors your app and directs the telemetry data to an Azure Application Insights Resource using a unique GUID that we refer to as an Instrumentation Key.
15
15
16
16
You can instrument not only the web service application, but also any background components, and the JavaScript in the web pages themselves. The application and its components can run anywhere - it doesn't have to be hosted in Azure.
17
17
@@ -22,7 +22,7 @@ In addition, you can pull in telemetry from the host environments such as perfor
22
22
All these telemetry streams are integrated into Azure Monitor. In the Azure portal, you can apply powerful analytic and search tools to the raw data.
23
23
24
24
### What's the overhead?
25
-
The impact on your app's performance is very small. Tracking calls are non-blocking, and are batched and sent in a separate thread.
25
+
The impact on your app's performance is small. Tracking calls are non-blocking, and are batched and sent in a separate thread.
26
26
27
27
## What does Application Insights monitor?
28
28
@@ -65,7 +65,7 @@ There are plenty of ways to explore your data. Check out these articles:
65
65
### Monitor
66
66
Install Application Insights in your app, set up [availability web tests](../../azure-monitor/app/monitor-web-app-availability.md), and:
67
67
68
-
* Check-out the default [application dashboard](../../azure-monitor/app/overview-dashboard.md) for your team room to keep an eye on load, responsiveness, and the performance of your dependencies, page loads, and AJAX calls.
68
+
* Checkout the default [application dashboard](../../azure-monitor/app/overview-dashboard.md) for your team room to keep an eye on load, responsiveness, and the performance of your dependencies, page loads, and AJAX calls.
69
69
* Discover which are the slowest and most failing requests.
70
70
* Watch [Live Stream](../../azure-monitor/app/live-stream.md) when you deploy a new release, to know immediately about any degradation.
0 commit comments