Skip to content

Commit 785f940

Browse files
authored
Merge pull request #265400 from MicrosoftDocs/main
2/6 11:00 AM IST Publish
2 parents 1e629cc + 9049a05 commit 785f940

File tree

120 files changed

+3372
-1788
lines changed

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

120 files changed

+3372
-1788
lines changed

.openpublishing.publish.config.json

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1215,6 +1215,7 @@
12151215
".openpublishing.redirection.container-service.json",
12161216
".openpublishing.redirection.defender-for-cloud.json",
12171217
".openpublishing.redirection.defender-for-iot.json",
1218+
".openpublishing.redirection.guidance.json",
12181219
".openpublishing.redirection.iot-hub-device-update.json",
12191220
".openpublishing.redirection.key-vault.json",
12201221
".openpublishing.redirection.machine-configuration.json",

.openpublishing.redirection.guidance.json

Lines changed: 419 additions & 0 deletions
Large diffs are not rendered by default.

.openpublishing.redirection.json

Lines changed: 0 additions & 415 deletions
Large diffs are not rendered by default.

articles/azure-government/compliance/azure-services-in-fedramp-auditscope.md

Lines changed: 8 additions & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,7 @@ ms.topic: article
77
ms.service: azure-government
88
ms.custom: references_regions
99
recommendations: false
10-
ms.date: 11/09/2023
10+
ms.date: 02/05/2023
1111
---
1212

1313
# Azure, Dynamics 365, Microsoft 365, and Power Platform services compliance scope
@@ -50,7 +50,7 @@ For current Azure Government regions and available services, see [Products avail
5050
This article provides a detailed list of Azure, Dynamics 365, Microsoft 365, and Power Platform cloud services in scope for FedRAMP High, DoD IL2, DoD IL4, DoD IL5, and DoD IL6 authorizations across Azure, Azure Government, and Azure Government Secret cloud environments. For other authorization details in Azure Government Secret and Azure Government Top Secret, contact your Microsoft account representative.
5151

5252
## Azure public services by audit scope
53-
*Last updated: November 2023*
53+
*Last updated: January 2024*
5454

5555
### Terminology used
5656

@@ -88,6 +88,7 @@ This article provides a detailed list of Azure, Dynamics 365, Microsoft 365, and
8888
| [Azure for Education](https://azureforeducation.microsoft.com/) | ✅ | ✅ |
8989
| [Azure Information Protection](/azure/information-protection/) | ✅ | ✅ |
9090
| [Azure Kubernetes Service (AKS)](../../aks/index.yml) | ✅ | ✅ |
91+
| [Azure Managed Grafana](../../managed-grafana/index.yml) | ✅ | ✅ |
9192
| [Azure Marketplace portal](https://azuremarketplace.microsoft.com/) | ✅ | ✅ |
9293
| [Azure Maps](../../azure-maps/index.yml) | ✅ | ✅ |
9394
| [Azure Monitor](../../azure-monitor/index.yml) (incl. [Application Insights](../../azure-monitor/app/app-insights-overview.md), [Log Analytics](../../azure-monitor/logs/data-platform-logs.md), and [Application Change Analysis](../../azure-monitor/app/change-analysis.md)) | ✅ | ✅ |
@@ -117,7 +118,8 @@ This article provides a detailed list of Azure, Dynamics 365, Microsoft 365, and
117118
| [Bot Service](/azure/bot-service/) | ✅ | ✅ |
118119
| [Cloud Services](../../cloud-services/index.yml) | ✅ | ✅ |
119120
| [Cloud Shell](../../cloud-shell/overview.md) | ✅ | ✅ |
120-
| [Cognitive Search](../../search/index.yml) (formerly Azure Search) | ✅ | ✅ |
121+
| [Azure AI Health Bot](/healthbot/) | ✅ | ✅ |
122+
| [Azure AI Search](../../search/index.yml) (formerly Azure Cognitive Search) | ✅ | ✅ |
121123
| [Azure AI services: Anomaly Detector](../../ai-services/anomaly-detector/index.yml) | ✅ | ✅ |
122124
| [Azure AI services: Computer Vision](../../ai-services/computer-vision/index.yml) | ✅ | ✅ |
123125
| [Azure AI services: Content Moderator](../../ai-services/content-moderator/index.yml) | ✅ | ✅ |
@@ -147,7 +149,7 @@ This article provides a detailed list of Azure, Dynamics 365, Microsoft 365, and
147149
| [Dedicated HSM](../../dedicated-hsm/index.yml) | ✅ | ✅ |
148150
| [DevTest Labs](../../devtest-labs/index.yml) | ✅ | ✅ |
149151
| [DNS](../../dns/index.yml) | ✅ | ✅ |
150-
| [Dynamics 365 Chat (Omnichannel Engagement Hub)](/dynamics365/omnichannel/introduction-omnichannel) | ✅ | ✅ |
152+
| [Omnichannel for Customer Service (Formerly Dynamics 365 Chat and Omnichannel Engagement Hub)](/dynamics365/omnichannel/introduction-omnichannel) | ✅ | ✅ |
151153
| [Dynamics 365 Commerce](/dynamics365/commerce/)| ✅ | ✅ |
152154
| [Dynamics 365 Customer Service](/dynamics365/customer-service/overview)| ✅ | ✅ |
153155
| [Dynamics 365 Field Service](/dynamics365/field-service/overview)| ✅ | ✅ |
@@ -167,8 +169,6 @@ This article provides a detailed list of Azure, Dynamics 365, Microsoft 365, and
167169
| [Azure AI Document Intelligence](../../ai-services/document-intelligence/index.yml) | ✅ | ✅ |
168170
| [Front Door](../../frontdoor/index.yml) | ✅ | ✅ |
169171
| [Functions](../../azure-functions/index.yml) | ✅ | ✅ |
170-
| [GitHub AE](https://docs.github.com/github-ae@latest/admin/overview/about-github-ae) | ✅ | ✅ |
171-
| [Health Bot](/healthbot/) | ✅ | ✅ |
172172
| [HDInsight](../../hdinsight/index.yml) | ✅ | ✅ |
173173
| [HPC Cache](../../hpc-cache/index.yml) | ✅ | ✅ |
174174
| [Immersive Reader](../../ai-services/immersive-reader/index.yml) | ✅ | ✅ |
@@ -194,7 +194,7 @@ This article provides a detailed list of Azure, Dynamics 365, Microsoft 365, and
194194
| [Microsoft Defender for Identity](/defender-for-identity/) (formerly Azure Advanced Threat Protection) | ✅ | ✅ |
195195
| **Service** | **FedRAMP High** | **DoD IL2** |
196196
| [Microsoft Defender for IoT](../../defender-for-iot/index.yml) (formerly Azure Security for IoT) | ✅ | ✅ |
197-
| [Microsoft Defender Vulnerability Management](../../defender-for-iot/index.yml) | ✅ | ✅ |
197+
| [Microsoft Defender Vulnerability Management](/microsoft-365/security/defender-vulnerability-management/) | ✅ | ✅ |
198198
| [Microsoft Graph](/graph/) | ✅ | ✅ |
199199
| [Microsoft Intune](/mem/intune/) | ✅ | ✅ |
200200
| [Microsoft Purview](../../purview/index.yml) (incl. Data Map, Data Estate Insights, and governance portal) | ✅ | ✅ |
@@ -229,7 +229,6 @@ This article provides a detailed list of Azure, Dynamics 365, Microsoft 365, and
229229
| [Site Recovery](../../site-recovery/index.yml) | ✅ | ✅ |
230230
| [SQL Database](/azure/azure-sql/database/sql-database-paas-overview) | ✅ | ✅ |
231231
| [SQL Managed Instance](/azure/azure-sql/managed-instance/sql-managed-instance-paas-overview) | ✅ | ✅ |
232-
| [SQL Server Registry](/sql/sql-server/end-of-support/sql-server-extended-security-updates) | ✅ | ✅ |
233232
| [SQL Server Stretch Database](../../sql-server-stretch-database/index.yml) | ✅ | ✅ |
234233
| [Storage: Archive](../../storage/blobs/access-tiers-overview.md) | ✅ | ✅ |
235234
| [Storage: Blobs](../../storage/blobs/index.yml) (incl. [Azure Data Lake Storage Gen2](../../storage/blobs/data-lake-storage-introduction.md)) | ✅ | ✅ |
@@ -312,7 +311,7 @@ This article provides a detailed list of Azure, Dynamics 365, Microsoft 365, and
312311
| [Azure Resource Manager](../../azure-resource-manager/management/index.yml) | ✅ | ✅ | ✅ | ✅ | ✅ |
313312
| [Azure Service Manager (RDFE)](/previous-versions/azure/ee460799(v=azure.100)) | ✅ | ✅ | ✅ | ✅ | ✅ |
314313
| [Azure Sign-up portal](https://signup.azure.com/) | ✅ | ✅ | ✅ | ✅ | |
315-
| [Azure Stack Bridge](/azure-stack/operator/azure-stack-usage-reporting) | ✅ | ✅ | ✅ | ✅ | ✅ |
314+
| [Azure Stack](/azure-stack/operator/azure-stack-usage-reporting) | ✅ | ✅ | ✅ | ✅ | ✅ |
316315
| [Azure Stack Edge](../../databox-online/index.yml) (formerly Data Box Edge) ***** | ✅ | ✅ | ✅ | ✅ | ✅ |
317316
| [Azure Stack HCI](/azure-stack/hci/) | ✅ | ✅ | ✅ | | |
318317
| [Azure Video Indexer](/azure/azure-video-indexer/) | ✅ | ✅ | ✅ | | |
@@ -413,7 +412,6 @@ This article provides a detailed list of Azure, Dynamics 365, Microsoft 365, and
413412
| [Power BI](/power-bi/fundamentals/) | ✅ | ✅ | ✅ | ✅ | ✅ |
414413
| [Power BI Embedded](/power-bi/developer/embedded/) | ✅ | ✅ | ✅ | ✅ | |
415414
| [Power Data Integrator for Dataverse](/power-platform/admin/data-integrator) (formerly Dynamics 365 Integrator App) | ✅ | ✅ | ✅ | ✅ | |
416-
| [Power Query Online](/power-query/) | ✅ | ✅ | ✅ | ✅ | ✅ |
417415
| [Power Virtual Agents](/power-virtual-agents/) | ✅ | ✅ | ✅ | | |
418416
| [Private Link](../../private-link/index.yml) | ✅ | ✅ | ✅ | ✅ | |
419417
| [Public IP](../../virtual-network/ip-services/public-ip-addresses.md) | ✅ | ✅ | ✅ | ✅ | |

articles/batch/batch-account-create-portal.md

Lines changed: 13 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -120,13 +120,13 @@ For detailed steps, see [Assign Azure roles by using the Azure portal](../role-b
120120

121121
### Create a key vault
122122

123-
User subscription mode requires [Azure Key Vault](/azure/key-vault/general/overview). The key vault must be in the same subscription and region as the Batch account and use a [Vault Access Policy](/azure/key-vault/general/assign-access-policy).
123+
User subscription mode requires [Azure Key Vault](/azure/key-vault/general/overview). The key vault must be in the same subscription and region as the Batch account.
124124

125125
To create a new key vault:
126126

127127
1. Search for and select **key vaults** from the Azure Search box, and then select **Create** on the **Key vaults** page.
128128
1. On the **Create a key vault** page, enter a name for the key vault, and choose an existing resource group or create a new one in the same region as your Batch account.
129-
1. On the **Access configuration** tab, select **Vault access policy** under **Permission model**.
129+
1. On the **Access configuration** tab, select either **Azure role-based access control** or **Vault access policy** under **Permission model**, and under **Resource access**, check all 3 checkboxes for **Azure Virtual Machine for deployment**, **Azure Resource Manager for template deployment** and **Azure Disk Encryption for volume encryption**.
130130
1. Leave the remaining settings at default values, select **Review + create**, and then select **Create**.
131131

132132
### Create a Batch account in user subscription mode
@@ -140,8 +140,18 @@ To create a Batch account in user subscription mode:
140140

141141
### Grant access to the key vault manually
142142

143-
You can also grant access to the key vault manually.
143+
You can also grant access to the key vault manually in [Azure portal](https://portal.azure.com).
144144

145+
#### If the Key Vault permission model is **Azure role-based access control**:
146+
1. Select **Access control (IAM)** from the left navigation of the key vault page.
147+
1. At the top of the **Access control (IAM)** page, select **Add** > **Add role assignment**.
148+
1. On the **Add role assignment** screen, under **Role** tab, under **Job function roles** sub tab, select either **Key Vault Secrets Officer** or **Key Vault Administrator** role for the Batch account, and then select **Next**.
149+
1. On the **Members** tab, select **Select members**. On the **Select members** screen, search for and select **Microsoft Azure Batch**, and then select **Select**.
150+
1. Click the **Review + create** button on the bottom to go to **Review + assign** tab, and click the **Review + create** button on the bottom again.
151+
152+
For detailed steps, see [Assign Azure roles by using the Azure portal](../role-based-access-control/role-assignments-portal.md).
153+
154+
#### If the Key Vault permission model is **Vault access policy**:
145155
1. Select **Access policies** from the left navigation of the key vault page.
146156
1. On the **Access policies** page, select **Create**.
147157
1. On the **Create an access policy** screen, select a minimum of **Get**, **List**, **Set**, and **Delete** permissions under **Secret permissions**. For [key vaults with soft-delete enabled](/azure/key-vault/general/soft-delete-overview), also select **Recover**.

articles/certification/how-to-test-pnp.md

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -26,19 +26,19 @@ This article shows you how to:
2626
The application code that runs on your IoT Plug and Play must:
2727

2828
- Connect to Azure IoT Hub using the [Device Provisioning Service (DPS)](../iot-dps/about-iot-dps.md).
29-
- Follow the [IoT Plug an Play conventions](../iot-develop/concepts-developer-guide-device.md) to implement of telemetry, properties, and commands.
29+
- Follow the [IoT Plug an Play conventions](../iot/concepts-developer-guide-device.md) to implement of telemetry, properties, and commands.
3030

3131
The application is software that's installed separately from the operating system or is bundled with the operating system in a firmware image that's flashed to the device.
3232

33-
Prior to certifying your device through the certification process for IoT Plug and Play, you will want to validate that the device implementation matches the telemetry, properties and commands defined in the [Digital Twins Definition Language (DTDL)](https://github.com/Azure/opendigitaltwins-dtdl) device model locally prior to submitting to the [Azure IoT Public Model Repository](../iot-develop/concepts-model-repository.md).
33+
Prior to certifying your device through the certification process for IoT Plug and Play, you will want to validate that the device implementation matches the telemetry, properties and commands defined in the [Digital Twins Definition Language (DTDL)](https://github.com/Azure/opendigitaltwins-dtdl) device model locally prior to submitting to the [Azure IoT Public Model Repository](../iot/concepts-model-repository.md).
3434

3535
To meet the certification requirements, your device must:
3636

3737
- Connects to Azure IoT Hub using the [DPS](../iot-dps/about-iot-dps.md).
3838
- Implement of telemetry, properties, or commands following the IoT Plug and Play convention.
3939
- Describe the device interactions with a [DTDL v2](https://aka.ms/dtdl) model.
40-
- Send the model ID during [DPS registration](../iot-develop/concepts-developer-guide-device.md#dps-payload) in the DPS provisioning payload.
41-
- Announce the model ID during the [MQTT connection](../iot-develop/concepts-developer-guide-device.md#model-id-announcement).
40+
- Send the model ID during [DPS registration](../iot/concepts-developer-guide-device.md#dps-payload) in the DPS provisioning payload.
41+
- Announce the model ID during the [MQTT connection](../iot/concepts-developer-guide-device.md#model-id-announcement).
4242

4343
## Test with the Azure IoT Extension CLI
4444

articles/certification/how-to-troubleshoot-pnp.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -37,7 +37,7 @@ While running the tests, if you receive a result of `Passed with warnings`, this
3737

3838
## When you need help with the model repository
3939

40-
For IoT Plug and Play issues related to the model repository, refer to [our Docs guidance about the device model repository](../iot-develop/concepts-model-repository.md).
40+
For IoT Plug and Play issues related to the model repository, refer to [our Docs guidance about the device model repository](../iot/concepts-model-repository.md).
4141

4242
## Next steps
4343

articles/certification/program-requirements-pnp.md

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -24,7 +24,7 @@ IoT Plug and Play enables solution builders to integrate smart devices with thei
2424
Promise of IoT Plug and Play certification are:
2525

2626
1. Defined device models and interfaces are compliant with the [Digital Twin Definition Language](https://github.com/Azure/opendigitaltwins-dtdl)
27-
1. Easy integration with Azure IoT based solutions using the [Digital Twin APIs](../iot-develop/concepts-digital-twin.md) : Azure IoT Hub and Azure IoT Central
27+
1. Easy integration with Azure IoT based solutions using the [Digital Twin APIs](../iot/concepts-digital-twin.md) : Azure IoT Hub and Azure IoT Central
2828
1. Product truth validated through testing telemetry from end point to cloud using DTDL
2929

3030
> [!Note]
@@ -63,7 +63,7 @@ Promise of IoT Plug and Play certification are:
6363
| **OS** | Agnostic |
6464
| **Validation Type** | Automated |
6565
| **Validation** | The [portal workflow](https://certify.azure.com) validates: **1.** Model ID announcement and ensure the device is connected using either the MQTT or MQTT over WebSockets protocol **2.** Models are compliant with the DTDL v2 **3.** Telemetry, properties, and commands are properly implemented and interact between IoT Hub Digital Twin and Device Twin on the device |
66-
| **Resources** | [Public Preview Refresh updates](../iot-develop/overview-iot-plug-and-play.md) |
66+
| **Resources** | [Public Preview Refresh updates](../iot/overview-iot-plug-and-play.md) |
6767

6868
**[Required] Device models are published in public model repository**
6969

@@ -74,7 +74,7 @@ Promise of IoT Plug and Play certification are:
7474
| **OS** | Agnostic |
7575
| **Validation Type** | Automated |
7676
| **Validation** | All device models are required to be published in public repository. Device models are resolved via models available in public repository **1.** User must manually publish the models to the public repository before submitting for the certification. **2.** Note that once the models are published, it is immutable. We strongly recommend publishing only when the models and embedded device code are finalized.*1 *1 User must contact Microsoft support to revoke the models once published to the model repository **3.** [Portal workflow](https://certify.azure.com) checks the existence of the models in the public repository when the device is connected to the certification service |
77-
| **Resources** | [Model repository](../iot-develop/overview-iot-plug-and-play.md) |
77+
| **Resources** | [Model repository](../iot/overview-iot-plug-and-play.md) |
7878

7979

8080
**[If implemented] Device info Interface: The purpose of test is to validate device info interface is implemented properly in the device code**
@@ -86,7 +86,7 @@ Promise of IoT Plug and Play certification are:
8686
| **OS** | Agnostic |
8787
| **Validation Type** | Automated |
8888
| **Validation** | [Portal workflow](https://certify.azure.com) validates the device code implements device info interface **1.** Checks the values are emitted by the device code to IoT Hub **2.** Checks the interface is implemented in the DCM (this implementation will change in DTDL v2) **3.** Checks properties are not write-able (read only) **4.** Checks the schema type is string and/or long and not null |
89-
| **Resources** | [Microsoft defined interface](../iot-develop/overview-iot-plug-and-play.md) |
89+
| **Resources** | [Microsoft defined interface](../iot/overview-iot-plug-and-play.md) |
9090
| **Azure Recommended** | N/A |
9191

9292
**[If implemented] Cloud to device: The purpose of test is to make sure messages can be sent from cloud to devices**

0 commit comments

Comments
 (0)