Skip to content

Commit 77f0c8a

Browse files
committed
Merge branch 'master' of https://github.com/MicrosoftDocs/azure-docs-pr into connector-health
2 parents 527df98 + 4907881 commit 77f0c8a

File tree

823 files changed

+10632
-5261
lines changed

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

823 files changed

+10632
-5261
lines changed

.github/workflows/stale.yml

Lines changed: 1 addition & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -19,8 +19,7 @@ jobs:
1919
close-pr-label: auto-close
2020
exempt-pr-labels: keep-open
2121
operations-per-run: 1200
22-
ascending: true
23-
start-date: '2021-07-29'
22+
ascending: false
2423
stale-pr-message: >
2524
This pull request has been inactive for at least 14 days.
2625
If you are finished with your changes, don't forget to sign off. See the [contributor guide](https://review.docs.microsoft.com/help/contribute/contribute-how-to-write-pull-request-automation) for instructions.

.openpublishing.redirection.active-directory.json

Lines changed: 26 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -10,6 +10,11 @@
1010
"redirect_url": "/azure/active-directory/manage-apps/what-is-application-management",
1111
"redirect_document_id": false
1212
},
13+
{
14+
"source_path_from_root": "/articles/active-directory/authentication/how-to-nudge-authenticator-app.md",
15+
"redirect_url": "/azure/active-directory/authentication/how-to-mfa-registration-campaign",
16+
"redirect_document_id": false
17+
},
1318
{
1419
"source_path_from_root": "/articles/active-directory/develop/active-directory-v2-limitations.md",
1520
"redirect_url": "/azure/active-directory/azuread-dev/azure-ad-endpoint-comparison",
@@ -1670,6 +1675,26 @@
16701675
"redirect_url": "/azure/active-directory/authentication/tutorial-enable-azure-mfa",
16711676
"redirect_document_id": false
16721677
},
1678+
{
1679+
"source_path_from_root": "/articles/active-directory/conditional-access/require-managed-devices.md",
1680+
"redirect_url": "/azure/active-directory/conditional-access/concept-conditional-access-grant",
1681+
"redirect_document_id": false
1682+
},
1683+
{
1684+
"source_path_from_root": "/articles/active-directory/conditional-access/untrusted-networks.md",
1685+
"redirect_url": "/azure/active-directory/conditional-access/howto-conditional-access-policy-all-users-mfa",
1686+
"redirect_document_id": true
1687+
},
1688+
{
1689+
"source_path_from_root": "/articles/active-directory/conditional-access/app-based-conditional-access.md",
1690+
"redirect_url": "/azure/active-directory/conditional-access/howto-policy-approved-app-or-app-protection",
1691+
"redirect_document_id": false
1692+
},
1693+
{
1694+
"source_path_from_root": "/articles/active-directory/conditional-access/app-protection-based-conditional-access.md",
1695+
"redirect_url": "/azure/active-directory/conditional-access/howto-policy-approved-app-or-app-protection",
1696+
"redirect_document_id": true
1697+
},
16731698
{
16741699
"source_path_from_root": "/articles/active-directory/authentication/quickstart-sspr.md",
16751700
"redirect_url": "/azure/active-directory/authentication/tutorial-enable-sspr",
@@ -9888,7 +9913,7 @@
98889913
{
98899914
"source_path_from_root": "/articles/active-directory/active-directory-saas-workplacebyfacebook-provisioning-tutorial.md",
98909915
"redirect_url": "/azure/active-directory/saas-apps/workplace-by-facebook-provisioning-tutorial",
9891-
"redirect_document_id": true
9916+
"redirect_document_id": false
98929917
},
98939918
{
98949919
"source_path_from_root": "/articles/active-directory/active-directory-saas-workplacebyfacebook-tutorial.md",

articles/active-directory-b2c/TOC.yml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -53,6 +53,7 @@
5353
href: ../active-directory/develop/v2-app-types.md?bc=%2fazure%2factive-directory-b2c%2fbread%2ftoc.json&toc=%2fazure%2factive-directory-b2c%2fTOC.json
5454
- name: Authentication library
5555
href: ../active-directory/develop/msal-overview.md?bc=%2fazure%2factive-directory-b2c%2fbread%2ftoc.json&toc=%2fazure%2factive-directory-b2c%2fTOC.json
56+
displayName: MSAL, client library, Microsoft Authentication Library
5657
- name: Azure AD B2C best practices
5758
href: best-practices.md
5859
- name: Application types
@@ -595,6 +596,7 @@
595596
href: app-registrations-training-guide.md
596597
- name: Billing model
597598
href: billing.md
599+
displayName: pricing model
598600
- name: Code samples
599601
href: /samples/browse/?terms=b2c
600602
- name: Cookie definitions

articles/active-directory-b2c/billing.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -8,7 +8,7 @@ manager: CelesteDG
88
ms.service: active-directory
99
ms.topic: reference
1010
ms.workload: identity
11-
ms.date: 11/11/2021
11+
ms.date: 11/16/2021
1212
ms.author: kengaderdus
1313
ms.subservice: B2C
1414
ms.custom: fasttrack-edit
@@ -48,7 +48,7 @@ MAU billing went into effect for Azure AD B2C tenants on **November 1, 2019**. A
4848

4949
Your Azure AD B2C tenant must also be linked to the appropriate Azure pricing tier based on the features you want to use. Premium features require Azure AD B2C [Premium P1 or P2 pricing](https://azure.microsoft.com/pricing/details/active-directory-b2c/). You might need to upgrade your pricing tier as you use new features. For example, for risk-based Conditional Access policies, you’ll need to select the Azure AD B2C Premium P2 pricing tier for your tenant.
5050
> [!NOTE]
51-
> Your first 50,000 MAUs per month are free for both Premium P1 and Premium P2 features, but **this free tier doesn’t apply to subscriptions with free trial credits**. To determine the total number of MAUs, we combine MAUs from all your tenants (both Azure AD and Azure AD B2C) that are linked to the same subscription.
51+
> Your first 50,000 MAUs per month are free for both Premium P1 and Premium P2 features, but the **free tier doesn’t apply to free trial, credit-based, or sponsorship subscriptions**. Once the free trial period or credits expire for these types of subscriptions, you'll begin to be charged for Azure AD B2C MAUs. To determine the total number of MAUs, we combine MAUs from all your tenants (both Azure AD and Azure AD B2C) that are linked to the same subscription.
5252
## Link an Azure AD B2C tenant to a subscription
5353

5454
Usage charges for Azure Active Directory B2C (Azure AD B2C) are billed to an Azure subscription. You need to explicitly link an Azure AD B2C tenant to an Azure subscription by creating an Azure AD B2C *resource* within the target Azure subscription. Several Azure AD B2C resources can be created in a single Azure subscription, along with other Azure resources like virtual machines, Storage accounts, and Logic Apps. You can see all of the resources within a subscription by going to the Azure Active Directory (Azure AD) tenant that the subscription is associated with.

articles/active-directory/app-provisioning/customize-application-attributes.md

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -8,7 +8,7 @@ ms.service: active-directory
88
ms.subservice: app-provisioning
99
ms.workload: identity
1010
ms.topic: tutorial
11-
ms.date: 07/07/2021
11+
ms.date: 11/15/2021
1212
ms.author: kenwith
1313
ms.reviewer: arvinh
1414
---
@@ -253,6 +253,7 @@ The request format in the PATCH and POST differ. To ensure that POST and PATCH a
253253
- **Things to consider**
254254
- All roles will be provisioned as primary = false.
255255
- The POST contains the role type. The PATCH request does not contain type. We are working on sending the type in both POST and PATCH requests.
256+
- AppRoleAssignmentsComplex is not compatible with setting scope to "Sync All users and groups."
256257

257258
- **Example output**
258259

articles/active-directory/app-provisioning/functions-for-customizing-application-data.md

Lines changed: 27 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,7 @@ ms.service: active-directory
77
ms.subservice: app-provisioning
88
ms.workload: identity
99
ms.topic: reference
10-
ms.date: 10/27/2021
10+
ms.date: 11/16/2021
1111
ms.author: kenwith
1212
ms.reviewer: arvinh
1313
---
@@ -33,7 +33,7 @@ The syntax for Expressions for Attribute Mappings is reminiscent of Visual Basic
3333

3434
## List of Functions
3535

36-
[Append](#append)      [AppRoleAssignmentsComplex](#approleassignmentscomplex)      [BitAnd](#bitand)      [CBool](#cbool)      [CDate](#cdate)      [Coalesce](#coalesce)      [ConvertToBase64](#converttobase64)      [ConvertToUTF8Hex](#converttoutf8hex)      [Count](#count)      [CStr](#cstr)      [DateAdd](#dateadd)      [DateDiff](#datediff)      [DateFromNum](#datefromnum)  [FormatDateTime](#formatdatetime)      [Guid](#guid)      [IgnoreFlowIfNullOrEmpty](#ignoreflowifnullorempty)     [IIF](#iif)     [InStr](#instr)      [IsNull](#isnull)      [IsNullOrEmpty](#isnullorempty)      [IsPresent](#ispresent)      [IsString](#isstring)      [Item](#item)      [Join](#join)      [Left](#left)      [Mid](#mid)      [NormalizeDiacritics](#normalizediacritics)       [Not](#not)      [Now](#now)      [NumFromDate](#numfromdate)      [PCase](#pcase)      [RandomString](#randomstring)      [RemoveDuplicates](#removeduplicates)      [Replace](#replace)      [SelectUniqueValue](#selectuniquevalue)     [SingleAppRoleAssignment](#singleapproleassignment)     [Split](#split)    [StripSpaces](#stripspaces)      [Switch](#switch)     [ToLower](#tolower)     [ToUpper](#toupper)     [Word](#word)
36+
[Append](#append)      [AppRoleAssignmentsComplex](#approleassignmentscomplex)      [BitAnd](#bitand)      [CBool](#cbool)      [CDate](#cdate)      [Coalesce](#coalesce)      [ConvertToBase64](#converttobase64)      [ConvertToUTF8Hex](#converttoutf8hex)      [Count](#count)      [CStr](#cstr)      [DateAdd](#dateadd)      [DateDiff](#datediff)      [DateFromNum](#datefromnum)  [FormatDateTime](#formatdatetime)      [Guid](#guid)      [IgnoreFlowIfNullOrEmpty](#ignoreflowifnullorempty)     [IIF](#iif)     [InStr](#instr)      [IsNull](#isnull)      [IsNullOrEmpty](#isnullorempty)      [IsPresent](#ispresent)      [IsString](#isstring)      [Item](#item)      [Join](#join)      [Left](#left)      [Mid](#mid)      [NormalizeDiacritics](#normalizediacritics)       [Not](#not)      [Now](#now)      [NumFromDate](#numfromdate)      [PCase](#pcase)      [RandomString](#randomstring)      [Redact](#redact)      [RemoveDuplicates](#removeduplicates)      [Replace](#replace)      [SelectUniqueValue](#selectuniquevalue)     [SingleAppRoleAssignment](#singleapproleassignment)     [Split](#split)    [StripSpaces](#stripspaces)      [Switch](#switch)     [ToLower](#tolower)     [ToUpper](#toupper)     [Word](#word)
3737

3838
---
3939
### Append
@@ -811,7 +811,32 @@ Generates a random string with 6 characters. The string contains 3 numbers and 3
811811
Generates a random string with 10 characters. The string contains at least 2 numbers, 2 special characters, 2 capital letters, 1 lower case letter and excludes the characters "?" and "," (1@!2BaRg53).
812812

813813
---
814+
### Redact
815+
**Function:**
816+
Redact()
817+
818+
**Description:**
819+
The Redact function replaces the attribute value with the string literal "[Redact]" in the provisioning logs.
820+
821+
**Parameters:**
822+
823+
| Name | Required/ Repeating | Type | Notes |
824+
| --- | --- | --- | --- |
825+
| **attribute/value** |Required |String|Specify the attribute or constant / string to redact from the logs.|
826+
827+
**Example 1:** Redact an attribute:
828+
`Redact([userPrincipalName])`
829+
Removes the userPrincipalName from the provisioning logs.
814830

831+
**Example 2:** Redact a string:
832+
`Redact("StringToBeRedacted")`
833+
Removes a constant string from the provisioning logs.
834+
835+
**Example 3:** Redact a random string:
836+
`Redact(RandomString(6,3,0,0,3))`
837+
Removes the random string from the provisioning logs.
838+
839+
---
815840
### RemoveDuplicates
816841
**Function:**
817842
RemoveDuplicates(attribute)

articles/active-directory/authentication/TOC.yml

Lines changed: 6 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -162,8 +162,12 @@
162162
href: howto-password-ban-bad-on-premises-faq.yml
163163
- name: Agent version history
164164
href: howto-password-ban-bad-on-premises-agent-versions.md
165-
- name: Nudge Microsoft Authenticator setup (Preview)
166-
href: how-to-nudge-authenticator-app.md
165+
- name: Run a registration campaign
166+
href: how-to-mfa-registration-campaign.md
167+
- name: Use number matching (Preview)
168+
href: how-to-mfa-number-match.md
169+
- name: Use additional context (Preview)
170+
href: how-to-mfa-additional-context.md
167171
- name: Use Microsoft managed settings
168172
href: how-to-mfa-microsoft-managed.md
169173
- name: Use a Temporary Access Pass (Preview)

articles/active-directory/authentication/concept-authentication-passwordless.md

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -124,7 +124,6 @@ The following providers offer FIDO2 security keys of different form factors that
124124
| KONA I | ![y] | ![n]| ![y]| ![y]| ![n] | https://konai.com/business/security/fido |
125125
| NEOWAVE | ![n] | ![y]| ![y]| ![n]| ![n] | https://neowave.fr/en/products/fido-range/ |
126126
| Nymi | ![y] | ![n]| ![y]| ![n]| ![n] | https://www.nymi.com/nymi-band |
127-
| Octatco | ![y] | ![y]| ![n]| ![n]| ![n] | https://octatco.com/ |
128127
| OneSpan Inc. | ![n] | ![y]| ![n]| ![y]| ![n] | https://www.onespan.com/products/fido |
129128
| Thales Group | ![n] | ![y]| ![y]| ![n]| ![n] | https://cpl.thalesgroup.com/access-management/authenticators/fido-devices |
130129
| Thetis | ![y] | ![y]| ![y]| ![y]| ![n] | https://thetis.io/collections/fido2 |

articles/active-directory/authentication/how-to-authentication-find-coverage-gaps.md

Lines changed: 3 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -47,16 +47,14 @@ Based on gaps you found, require administrators to use multi-factor authenticati
4747

4848
- Run the [MFA enablement wizard](https://aka.ms/MFASetupGuide) to choose your MFA policy.
4949

50-
- If you assign custom or built-in admin roles in [Privileged Identity Management](https://docs.microsoft.com/azure/active-directory/privileged-identity-management/pim-configure), require multi-factor authentication upon role activation.
50+
- If you assign custom or built-in admin roles in [Privileged Identity Management](../privileged-identity-management/pim-configure.md), require multi-factor authentication upon role activation.
5151

5252
## Use Passwordless and phishing resistant authentication methods for your administrators
5353

5454
After your admins are enforced for multi-factor authentication and have been using it for a while, it is time to raise the bar on strong authentication and use Passwordless and phishing resistant authentication method:
5555

5656
- [Phone Sign-in (with Microsoft Authenticator)](concept-authentication-authenticator-app.md)
5757
- [FIDO2](concept-authentication-passwordless.md#fido2-security-keys)
58-
- [Windows Hello for Business](https://docs.microsoft.com/windows/security/identity-protection/hello-for-business/hello-overview)
59-
60-
You can read more about these authentication methods and their security considerations in [Azure AD authentication methods](concept-authentication-methods.md).
61-
58+
- [Windows Hello for Business](/windows/security/identity-protection/hello-for-business/hello-overview)
6259

60+
You can read more about these authentication methods and their security considerations in [Azure AD authentication methods](concept-authentication-methods.md).

0 commit comments

Comments
 (0)