Skip to content

Commit 741617f

Browse files
authored
Merge pull request #268650 from msmbaldwin/lockbox
Customer Lockbox alt email
2 parents 716448a + 26da511 commit 741617f

13 files changed

+197
-40
lines changed

articles/security/fundamentals/TOC.yml

Lines changed: 10 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -177,10 +177,16 @@
177177
href: database-security-checklist.md
178178
- name: Storage security guide
179179
href: ../../storage/blobs/security-recommendations.md?toc=/azure/security/fundamentals/toc.json&bc=/azure/security/breadcrumb/toc.json
180-
- name: Customer Lockbox
181-
href: customer-lockbox-overview.md
182-
- name: Security baseline for Customer Lockbox
183-
href: /security/benchmark/azure/baselines/lockbox-security-baseline?toc=/azure/security/fundamentals/TOC.json
180+
- name: Customer Lockbox for Microsoft Azure
181+
items:
182+
- name: Overview
183+
href: customer-lockbox-overview.md
184+
- name: Alternate email notifications
185+
href: customer-lockbox-alternative-email.md
186+
- name: FAQ
187+
href: customer-lockbox-faq.yml
188+
- name: Security baseline for Customer Lockbox
189+
href: /security/benchmark/azure/baselines/lockbox-security-baseline?toc=/azure/security/fundamentals/TOC.json
184190
- name: Trusted Hardware Identity Management
185191
href: trusted-hardware-identity-management.md
186192

Lines changed: 73 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,73 @@
1+
---
2+
title: Customer Lockbox for Microsoft Azure alternate email feature
3+
description: Customer Lockbox for Microsoft Azure alternate email feature
4+
author: msmbaldwin
5+
ms.service: information-protection
6+
ms.topic: article
7+
ms.author: mbaldwin
8+
ms.date: 03/15/2024
9+
---
10+
11+
# Customer Lockbox for Microsoft Azure alternate email notifications (public preview)
12+
13+
> [!NOTE]
14+
> To use this feature, your organization must have an [Azure support plan](https://azure.microsoft.com/support/plans/) with a minimal level of **Developer**.
15+
16+
Customer Lockbox for Microsoft Azure is launching a new feature that enables customers to use alternate email IDs for getting Customer Lockbox notifications. This enables Customer Lockbox for Microsoft Azure customers to receive notifications in scenarios where their Azure account is not email enabled or if they have a service principal defined as the tenant admin or subscription owner.
17+
18+
> [!IMPORTANT]
19+
> This feature only enables Customer Lockbox notifications to be sent to alternate email IDs. It does not enable alternate users to act as approvers for Customer Lockbox requests.
20+
>
21+
> For example, Alice has the subscription owner role for subscription X and she adds Bob's email address as alternate email/other email in her user profile who has a reader role. When a Customer Lockbox request is created for a resource scoped to subscription 'X', Bob will receive the email notification, but he'll not be able to approve/reject the Customer Lockbox request as he does not have the required privileges for it (subscription owner role).
22+
23+
## Prerequisites
24+
25+
To take advantage of the Customer Lockbox for Microsoft Azure alternate email feature, you must have:
26+
27+
- A Microsoft Entra ID tenant that has Customer Lockbox for Microsoft Azure enabled on it.
28+
- A Developer or above Azure support plan.
29+
- Role Assignments:
30+
- A user account with Tenant admin/privileged authentication administrator/User administrator role to update user settings.
31+
- [Optional] Subscription owner or the new Azure Customer Lockbox Approver for Subscription role if you’d like to approve/reject Customer Lockbox requests.
32+
33+
## Set up
34+
35+
Here are the steps to set up the Customer Lockbox for Microsoft Azure alternate email feature.
36+
37+
1. Access the [Azure portal](https://portal.azure.com/).
38+
1. Sign in with the user account with tenant/privileged authentication administrator/User administrator role privileges.
39+
1. Search for Users at the home page:
40+
:::image type="content" source="./media/customer-lockbox-overview/customer-lockbox-alternative-email-home.png" lightbox="./media/customer-lockbox-overview/customer-lockbox-alternative-email-home.png" alt-text="A screenshot of the home screen.":::
41+
1. Search for the user for whom you want to add alternate email address.
42+
43+
> [!NOTE]
44+
> The user must have tenant admin/subscription owner/Azure Customer Lockbox Approver for Subscription role privileges to act on Lockbox requests.
45+
46+
:::image type="content" source="./media/customer-lockbox-overview/customer-lockbox-alternative-email-user-search.png" lightbox="./media/customer-lockbox-overview/customer-lockbox-alternative-email-user-search.png" alt-text="A screenshot of the search for users interface.":::
47+
1. Select the user and select on edit properties.
48+
:::image type="content" source="./media/customer-lockbox-overview/customer-lockbox-alternative-email-edit-properties.png" lightbox="./media/customer-lockbox-overview/customer-lockbox-alternative-email-edit-properties.png" alt-text="A screenshot of the edit properties interface.":::
49+
1. Navigate to Contact Information tab.
50+
:::image type="content" source="./media/customer-lockbox-overview/customer-lockbox-alternative-email-contact-information.png" lightbox="./media/customer-lockbox-overview/customer-lockbox-alternative-email-contact-information.png" alt-text="A screenshot of the Contact Information tab.":::
51+
1. Select Add email under 'Other emails' category and then select Add.
52+
:::image type="content" source="./media/customer-lockbox-overview/customer-lockbox-alternative-email-add-email.png" lightbox="./media/customer-lockbox-overview/customer-lockbox-alternative-email-add-email.png" alt-text="A screenshot of the Other emails add interface.":::
53+
1. Add alternate email address in the text field and select save.
54+
:::image type="content" source="./media/customer-lockbox-overview/customer-lockbox-alternative-email-other-email.png" lightbox="./media/customer-lockbox-overview/customer-lockbox-alternative-email-other-email.png" alt-text="A screenshot of the alternative email input interface.":::
55+
1. Select the save button in the Contact Information tab to save the updates.
56+
:::image type="content" source="./media/customer-lockbox-overview/customer-lockbox-alternative-email-save.png" lightbox="./media/customer-lockbox-overview/customer-lockbox-alternative-email-save.png" alt-text="A screenshot of the Contact Information table, emphasizing the save interface.":::
57+
1. The contact information tab for this user should now show updated information with alternate email:
58+
:::image type="content" source="./media/customer-lockbox-overview/customer-lockbox-alternative-email-contact-information-updated.png" lightbox="./media/customer-lockbox-overview/customer-lockbox-alternative-email-contact-information-updated.png" alt-text="A screenshot of the updated information.":::
59+
1. Anytime a lockbox request is triggered and if the above user is identified as a Lockbox approver, the Lockbox email notification is sent to both primary and other email addresses, notifying that the Microsoft Support is trying to access a resource within their tenant, and they should take an action by logging into Azure portal to approve/reject the request. Here is an example screenshot:
60+
:::image type="content" source="./media/customer-lockbox-overview/customer-lockbox-alternative-email-notification.png" lightbox="./media/customer-lockbox-overview/customer-lockbox-alternative-email-notification.png" alt-text="A screenshot of the email notification.":::
61+
62+
## Known Issues
63+
64+
Here are the known issues with this feature:
65+
66+
- Duplicate emails are sent if the value for primary and other email is same.
67+
- Notifications are sent to only the first email address in 'other emails' despite multiple email IDs configured in other email field.
68+
- If the primary email is not set, and the other email is set, two emails are sent to the alternate email address.
69+
70+
## Next steps
71+
72+
- [Customer Lockbox for Microsoft Azure](customer-lockbox-overview.md)
73+
- [Customer Lockbox for Microsoft Azure frequently asked questions](customer-lockbox-faq.yml)
Lines changed: 77 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,77 @@
1+
### YamlMime:FAQ
2+
metadata:
3+
title: Customer Lockbox for Microsoft Azure frequently asked questions
4+
description: Frequently asked questions about Customer Lockbox
5+
services: information-protection
6+
ms.service: information-protection
7+
ms.topic: overview
8+
ms.date: 03/15/2024
9+
author: msmbaldwin
10+
ms.author: mbaldwin
11+
title: Customer Lockbox for Microsoft Azure frequently asked questions
12+
summary: This article answers frequently asked questions about Customer Lockbox for Microsoft Azure.
13+
14+
sections:
15+
- name: General
16+
questions:
17+
- question: |
18+
Can I enable Customer Lockbox for Microsoft Azure at management group or subscription level?
19+
answer: |
20+
No, Customer Lockbox for Microsoft Azure can only be enabled at tenant-level, and is applicable to all the subscriptions and resources under that tenant.
21+
- question: |
22+
What does Microsoft do when a customer rejects a Customer Lockbox request?
23+
answer: |
24+
If a customer rejects a Customer Lockbox request, no access to customer content occurs. If a user in your organization continues to experience a service issue requiring Microsoft to access customer content to resolve the issue, then the service issue might persist and Microsoft will inform the user.
25+
- question: |
26+
Can I assign the Customer Lockbox approver role at the management group level?
27+
answer: |
28+
No, role assignments scoped to management groups are not supported in Customer Lockbox for Microsoft Azure at this time.
29+
- question: |
30+
Can I use Privileged Identity Management (PIM) to activate the Customer Lockbox approver role after a Customer Lockbox request is initiated?
31+
answer: |
32+
Role assignments must be in place before Customer Lockbox for Microsoft Azure starts to process a request. Any role assignments made after Customer Lockbox for Microsoft Azure starts to process a given request will not be recognized. Using PIM eligible assignments for the Customer Lockbox approver role requires users to activate the role before the Customer Lockbox request is initiated.
33+
34+
- name: Customer Lockbox Approver Role for Subscriptions (public preview)
35+
questions:
36+
- question: |
37+
Can I use the new Customer Lockbox approver role for tenant-scoped requests as well?
38+
answer: |
39+
No, Azure Customer Lockbox Approver for Subscription role works only for subscription-scoped requests. The Customer Lockbox for Microsoft Azure team will be creating a lesser privilege role for tenant-scoped requests in subsequent releases.
40+
- question: |
41+
Can I use the new Customer Lockbox approver role with Microsoft Purview Customer Lockbox or Customer Lockbox for Power Platform and Dynamics 365?
42+
answer: |
43+
No, the Azure Customer Lockbox Approver for Subscription role works only for subscription-scoped requests created by Customer Lockbox for Microsoft Azure.
44+
- question: |
45+
Can I use PIM to activate the new Customer Lockbox approver role after a Customer Lockbox request is initiated?
46+
answer: |
47+
Role assignments must be in place before Customer Lockbox starts to process a request. Any role assignments made after Customer Lockbox for Microsoft Azure starts to process a given request will not be recognized. Because of this, to use PIM eligible assignments for the Customer Lockbox approver role, users are required to activate the role before the Customer Lockbox request is initiated.
48+
49+
- name: Alternative email feature (public preview)
50+
questions:
51+
- question: |
52+
Can I add a different user email address as an alternate email to another user's account?
53+
answer: |
54+
Yes, you can add any email address in the other emails field to be used as alternate email for receiving Customer Lockbox notifications.
55+
- question: |
56+
If I add a second user's email address as an alternate email to an existing Customer Lockbox approver user's account, will the second user be able to see and approve/reject Customer Lockbox requests?
57+
answer: |
58+
No, this feature only allows customers to receive Customer Lockbox request notifications on alternate email addresses, but it does not provide the ability to configure other users as Customer Lockbox approvers. For example, Alice has the subscription owner role for subscription X and she adds Bob's email address as alternate email/other email in her user profile who has a reader role. When a Customer Lockbox request is created for a resource scoped to subscription "X", Bob receives the email notification, but he'll not be able to approve/reject the Customer Lockbox request as he does not have the required privileges for it (subscription owner role).
59+
- question: |
60+
Can I add more than one alternate email address to a user account?
61+
answer: |
62+
You can add multiple email addresses in the other field but currently Customer Lockbox for Microsoft Azure supports sending notifications only to the first email address in "other emails" despite multiple email IDs configured.
63+
- question: |
64+
Can I use alternate email notification functionality with Microsoft Purview Customer Lockbox or Customer Lockbox for Power Platform and Dynamics 365?
65+
answer: |
66+
No, this feature is limited to Customer Lockbox for Microsoft Azure.
67+
- question: |
68+
Will the alternate email notification work for both tenant-scoped and subscription-scoped Customer Lockbox requests?
69+
answer: |
70+
Yes, alternate email notifications work for all Customer Lockbox requests.
71+
72+
additionalContent: |
73+
74+
## Next steps
75+
76+
- [Customer Lockbox for Microsoft Azure overview](customer-lockbox-overview.md)
77+
- [Customer Lockbox for Microsoft Azure alternate email notifications](customer-lockbox-overview.md)

0 commit comments

Comments
 (0)