Skip to content

Commit 839b651

Browse files
committed
Merge branch 'master' of https://github.com/MicrosoftDocs/azure-docs-pr into dt-blobs
2 parents c56f9b9 + 5cebc15 commit 839b651

File tree

252 files changed

+2422
-3994
lines changed

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

252 files changed

+2422
-3994
lines changed

.openpublishing.redirection.json

Lines changed: 85 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -140,6 +140,11 @@
140140
"redirect_url": "https://docs.microsoft.com/azure/architecture/topics/high-performance-computing/",
141141
"redirect_document_id": false
142142
},
143+
{
144+
"source_path": "articles/virtual-machines/workloads/oracle/oracle-considerations.md",
145+
"redirect_url": "/azure/virtual-machines/workloads/oracle/oracle-overview/",
146+
"redirect_document_id": false
147+
},
143148
{
144149
"source_path": "articles/machine-learning/studio/consume-web-service-with-web-app-template.md",
145150
"redirect_url": "/azure/machine-learning/studio/consume-web-services",
@@ -26809,6 +26814,86 @@
2680926814
"redirect_url": "/azure/marketplace/cloud-partner-portal/test-drive/what-is-test-drive",
2681026815
"redirect_document_id": false
2681126816
},
26817+
{
26818+
"source_path": "articles/marketplace/cloud-partner-portal/saas-app/cpp-channel-info-tab.md",
26819+
"redirect_url": "/azure/marketplace/partner-center-portal/create-new-saas-offer",
26820+
"redirect_document_id": false
26821+
},
26822+
{
26823+
"source_path": "articles/marketplace/cloud-partner-portal/saas-app/cpp-contacts-tab.md",
26824+
"redirect_url": "/azure/marketplace/partner-center-portal/create-new-saas-offer",
26825+
"redirect_document_id": false
26826+
},
26827+
{
26828+
"source_path": "articles/marketplace/cloud-partner-portal/saas-app/cpp-create-offer.md",
26829+
"redirect_url": "/azure/marketplace/partner-center-portal/create-new-saas-offer",
26830+
"redirect_document_id": false
26831+
},
26832+
{
26833+
"source_path": "articles/marketplace/cloud-partner-portal/saas-app/cpp-offer-settings-tab.md",
26834+
"redirect_url": "/azure/marketplace/partner-center-portal/create-new-saas-offer",
26835+
"redirect_document_id": false
26836+
},
26837+
{
26838+
"source_path": "articles/marketplace/cloud-partner-portal/saas-app/cpp-plans-tab.md",
26839+
"redirect_url": "/azure/marketplace/partner-center-portal/create-new-saas-offer",
26840+
"redirect_document_id": false
26841+
},
26842+
{
26843+
"source_path": "articles/marketplace/cloud-partner-portal/saas-app/cpp-prerequisites.md",
26844+
"redirect_url": "/azure/marketplace/partner-center-portal/offer-creation-checklist",
26845+
"redirect_document_id": false
26846+
},
26847+
{
26848+
"source_path": "articles/marketplace/cloud-partner-portal/saas-app/cpp-publish-offer.md",
26849+
"redirect_url": "/azure/marketplace/partner-center-portal/create-new-saas-offer",
26850+
"redirect_document_id": false
26851+
},
26852+
{
26853+
"source_path": "articles/marketplace/cloud-partner-portal/saas-app/cpp-saas-subscription-apis.md",
26854+
"redirect_url": "/azure/marketplace/partner-center-portal/create-new-saas-offer",
26855+
"redirect_document_id": false
26856+
},
26857+
{
26858+
"source_path": "articles/marketplace/cloud-partner-portal/saas-app/cpp-storefront-tab.md",
26859+
"redirect_url": "/azure/marketplace/partner-center-portal/create-new-saas-offer",
26860+
"redirect_document_id": false
26861+
},
26862+
{
26863+
"source_path": "articles/marketplace/cloud-partner-portal/saas-app/cpp-technical-info-tab.md",
26864+
"redirect_url": "/azure/marketplace/partner-center-portal/create-new-saas-offer",
26865+
"redirect_document_id": false
26866+
},
26867+
{
26868+
"source_path": "articles/marketplace/cloud-partner-portal/saas-app/cpp-testdrive-tab.md",
26869+
"redirect_url": "/azure/marketplace/partner-center-portal/create-new-saas-offer",
26870+
"redirect_document_id": false
26871+
},
26872+
{
26873+
"source_path": "articles/marketplace/cloud-partner-portal/saas-app/cpp-update-existing-offer.md",
26874+
"redirect_url": "/azure/marketplace/partner-center-portal/create-new-saas-offer",
26875+
"redirect_document_id": false
26876+
},
26877+
{
26878+
"source_path": "articles/marketplace/cloud-partner-portal/saas-app/cpp-saas-fulfillment-api-v1.md",
26879+
"redirect_url": "/azure/marketplace/partner-center-portal/pc-saas-fulfillment-api-v1",
26880+
"redirect_document_id": false
26881+
},
26882+
{
26883+
"source_path": "articles/marketplace/cloud-partner-portal/saas-app/cpp-saas-fulfillment-api-v2.md",
26884+
"redirect_url": "/azure/marketplace/partner-center-portal/pc-saas-fulfillment-api-v2",
26885+
"redirect_document_id": false
26886+
},
26887+
{
26888+
"source_path": "articles/marketplace/cloud-partner-portal/saas-app/cpp-saas-fulfillment-apis.md",
26889+
"redirect_url": "/azure/marketplace/partner-center-portal/pc-saas-fulfillment-apis",
26890+
"redirect_document_id": false
26891+
},
26892+
{
26893+
"source_path": "articles/marketplace/cloud-partner-portal/saas-app/cpp-saas-registration.md",
26894+
"redirect_url": "/azure/marketplace/partner-center-portal/pc-saas-registration",
26895+
"redirect_document_id": false
26896+
},
2681226897
{
2681326898
"source_path": "articles/marketplace/grow-your-business-azure-marketplace.md",
2681426899
"redirect_url": "/azure/marketplace/grow-your-business-with-azure-marketplace",

articles/active-directory/authentication/howto-password-ban-bad-configure.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -21,7 +21,7 @@ Many organizations find their users create passwords using common local words su
2121

2222
## Add to the custom list
2323

24-
Configuring the custom banned password list requires an Azure Active Directory Premium P1 or P2 license. For more detailed information about Azure Active Directory licensing, see the [Azure Active Directory pricing page](https://azure.microsoft.com/pricing/details/active-directory/).|
24+
Configuring the custom banned password list requires an Azure Active Directory Premium P1 or P2 license. For more detailed information about Azure Active Directory licensing, see the [Azure Active Directory pricing page](https://azure.microsoft.com/pricing/details/active-directory/).
2525

2626
1. Sign in to the [Azure portal](https://portal.azure.com) and browse to **Azure Active Directory**, **Authentication methods**, then **Password protection**.
2727
1. Set the option **Enforce custom list**, to **Yes**.

articles/active-directory/develop/about-microsoft-identity-platform.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -55,7 +55,7 @@ The **application API in Microsoft Graph** is currently in preview. Use this API
5555

5656
### MSAL libraries
5757

58-
You can use the MSAL library to build applications that authenticate all Microsoft identities. The MSAL libraries in .NET are generally available. MSAL libraries for JavaScript, iOS, and Android are in preview and suitable for use in a production environment. We provide the same production level support for MSAL libraries in preview as we do for versions of MSAL and ADAL that are generally available.
58+
You can use the MSAL library to build applications that authenticate all Microsoft identities. The MSAL libraries in .NET and JavaScript are generally available. MSAL libraries for iOS and Android are in preview and suitable for use in a production environment. We provide the same production level support for MSAL libraries in preview as we do for versions of MSAL and ADAL that are generally available.
5959

6060
You can also use the MSAL libraries to integrate your application with Azure AD B2C.
6161

articles/active-directory/governance/access-reviews-overview.md

Lines changed: 3 additions & 23 deletions
Original file line numberDiff line numberDiff line change
@@ -12,7 +12,7 @@ ms.tgt_pltfrm: na
1212
ms.devlang: na
1313
ms.topic: conceptual
1414
ms.subservice: compliance
15-
ms.date: 05/31/2019
15+
ms.date: 06/05/2019
1616
ms.author: rolyon
1717
ms.reviewer: mwahl
1818
ms.collection: M365-identity-device-management
@@ -53,8 +53,8 @@ Depending on what you want to review, you will create your access review in Azur
5353
| --- | --- | --- | --- |
5454
| Security group members</br>Office group members | Specified reviewers</br>Group owners</br>Self-review | Azure AD access reviews</br>Azure AD groups | Access panel |
5555
| Assigned to a connected app | Specified reviewers</br>Self-review | Azure AD access reviews</br>Azure AD enterprise apps (in preview) | Access panel |
56-
| Azure AD role | Specified reviewers</br>Self-review | Azure AD PIM | Azure portal |
57-
| Azure resource role | Specified reviewers</br>Self-review | Azure AD PIM | Azure portal |
56+
| Azure AD role | Specified reviewers</br>Self-review | [Azure AD PIM](../privileged-identity-management/pim-how-to-start-security-review.md?toc=%2fazure%2factive-directory%2fgovernance%2ftoc.json) | Azure portal |
57+
| Azure resource role | Specified reviewers</br>Self-review | [Azure AD PIM](../privileged-identity-management/pim-resource-roles-start-access-review.md?toc=%2fazure%2factive-directory%2fgovernance%2ftoc.json) | Azure portal |
5858

5959
## Which users must have licenses?
6060

@@ -88,26 +88,6 @@ If you are ready to deploy access reviews in your organization, follow these ste
8888

8989
>[!VIDEO https://www.youtube.com/embed/X1SL2uubx9M]
9090
91-
## Onboard access reviews
92-
93-
To onboard access reviews, follow these steps.
94-
95-
1. As a Global administrator or User administrator, sign in to the [Azure portal](https://portal.azure.com) where you want to use access reviews.
96-
97-
1. In the left navigation, click **Azure Active Directory**.
98-
99-
1. In the left menu, click **Identity Governance**.
100-
101-
1. Click **Access reviews**.
102-
103-
![Access reviews start page](./media/access-reviews-overview/access-reviews-start.png)
104-
105-
1. On the page, click the **Onboard now** button.
106-
107-
![Access reviews onboard](./media/access-reviews-overview/onboard-button.png)
108-
109-
1. Follow the instructions to onboard access reviews in the current directory.
110-
11191
## License requirements
11292

11393
[!INCLUDE [Azure AD Premium P2 license](../../../includes/active-directory-p2-license.md)]

articles/active-directory/governance/create-access-review.md

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -26,7 +26,6 @@ This article describes how to create one or more access reviews for group member
2626
## Prerequisites
2727

2828
- Azure AD Premium P2
29-
- [Access reviews onboarded](access-reviews-overview.md)
3029
- Global administrator or User administrator
3130

3231
For more information, see [Which users must have licenses?](access-reviews-overview.md#which-users-must-have-licenses).

articles/active-directory/hybrid/cloud-governed-management-for-on-premises.md

Lines changed: 5 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -64,7 +64,7 @@ After a single sign-on to Azure AD, users can access both cloud and on-premises
6464

6565
Identity governance helps organizations achieve a balance between *productivity* --- how quickly can a person have access to the resources they need, such as when they join the organization? --- and *security* --- how should their access change over time, such as when that person's employment status changes? Identity lifecycle management is the foundation for identity governance, and effective governance at scale requires modernizing the identity lifecycle management infrastructure for applications.
6666

67-
For many organizations, identity lifecycle for employees is tied to the representation of that user in a human capital management (HCM) system. For organizations using Workday as their HCM system, Azure AD can ensure user accounts in AD are [automatically provisioned and deprovisioned for workers in Workday](https://docs.microsoft.com/azure/active-directory/saas-apps/workday-inbound-tutorial). Doing so leads to improved user productivity through automation of birthright accounts and manages risk by ensuring application access is automatically updated when a user changes roles or leaves the organization. The Workday-driven user provisioning deployment plan (<https://aka.ms/WorkdayDeploymentPlan>) is a step-by-step guide that walks organizations through the best practices implementation of Workday to Active Directory User Provisioning solution in a five-step process.
67+
For many organizations, identity lifecycle for employees is tied to the representation of that user in a human capital management (HCM) system. For organizations using Workday as their HCM system, Azure AD can ensure user accounts in AD are [automatically provisioned and deprovisioned for workers in Workday](https://docs.microsoft.com/azure/active-directory/saas-apps/workday-inbound-tutorial). Doing so leads to improved user productivity through automation of birthright accounts and manages risk by ensuring application access is automatically updated when a user changes roles or leaves the organization. The Workday-driven user provisioning [deployment plan](https://aka.ms/WorkdayDeploymentPlan) is a step-by-step guide that walks organizations through the best practices implementation of Workday to Active Directory User Provisioning solution in a five-step process.
6868

6969
Azure AD Premium also includes Microsoft Identity Manager, which can import records from other on-premises HCM systems, including SAP, Oracle eBusiness, and Oracle PeopleSoft.
7070

@@ -73,7 +73,7 @@ Business-to-business collaboration increasingly requires granting access to peop
7373
Azure AD can [automatically create accounts in AD for guest users](https://docs.microsoft.com/azure/active-directory/b2b/hybrid-cloud-to-on-premises) as needed, enabling business guests to access on-premises AD-integrated applications without needing another password. Organizations can set up [multi-factor authentication (MFA) policies for guest user](https://docs.microsoft.com/azure/active-directory/b2b/conditional-access)s so MFA checks are done during application proxy authentication. Also, any [access reviews](https://docs.microsoft.com/azure/active-directory/governance/manage-guest-access-with-access-reviews) that are done on cloud B2B users apply to on-premises users. For example, if the cloud user is deleted through lifecycle management policies, the on-premises user is also deleted.
7474

7575
**Credential management for Active Directory accounts**
76-
Azure AD's self-service password reset allows users who have forgotten their passwords to be reauthenticated and reset their passwords, with the changed passwords [written to on-premises Active Directory](https://docs.microsoft.com/azure/active-directory/authentication/concept-sspr-writeback). The password reset process can also use the on-premises Active Directory password policies: When a user resets their password, it's checked to ensure it meets the on-premises Active Directory policy before committing it to that directory. The self-service password reset deployment plan at <https://aka.ms/deploymentplans/sspr> outlines best practices to roll out self-service password reset to users via web and Windows-integrated experiences.
76+
Azure AD's self-service password reset allows users who have forgotten their passwords to be reauthenticated and reset their passwords, with the changed passwords [written to on-premises Active Directory](https://docs.microsoft.com/azure/active-directory/authentication/concept-sspr-writeback). The password reset process can also use the on-premises Active Directory password policies: When a user resets their password, it's checked to ensure it meets the on-premises Active Directory policy before committing it to that directory. The self-service password reset [deployment plan](https://aka.ms/deploymentplans/sspr) outlines best practices to roll out self-service password reset to users via web and Windows-integrated experiences.
7777

7878
![Azure AD SSPR architecture](media/cloud-governed-management-for-on-premises/image3.png)
7979

@@ -83,13 +83,13 @@ When an organization is ready to move an AD-integrated application to the cloud
8383

8484
![Azure AD Domain Services](media/cloud-governed-management-for-on-premises/image4.png)
8585

86-
## [Cloud governed management for on-premises federation-based applications]{.underline}
86+
## Cloud governed management for on-premises federation-based applications
8787

8888
For an organization that already uses an on-premises identity provider, moving applications to Azure AD enables more secure access and an easier administrative experience for federation management. Azure AD enables configuring granular per-application access controls, including Azure Multi-Factor Authentication, by using Azure AD conditional access. Azure AD supports more capabilities, including application-specific token signing certificates and configurable certificate expiration dates. These capabilities, tools, and guidance enable organizations to retire their on-premises identity providers. Microsoft's own IT, for one example, has moved 17,987 applications from Microsoft's internal Active Directory Federation Services (AD FS) to Azure AD.
8989

9090
![Azure AD evolution](media/cloud-governed-management-for-on-premises/image5.png)
9191

92-
To begin migrating federated applications to Azure AD as the identity provider, refer to, that, includes links to:
92+
To begin migrating federated applications to Azure AD as the identity provider, refer to https://aka.ms/migrateapps that includes links to:
9393

9494
* The white paper [Migrating Your Applications to Azure Active Directory](https://aka.ms/migrateapps/whitepaper), which presents the benefits of migration and describes how to plan for migration in four clearly-outlined phases: discovery, classification, migration, and ongoing management. You'll be guided through how to think about the process and break down your project into easy-to-consume pieces. Throughout the document are links to important resources that will help you along the way.
9595

@@ -107,7 +107,7 @@ Organizations can automate the access lifecycle process through technologies suc
107107

108108
## Future directions
109109

110-
In hybrid environments, Microsoft's strategy is to enable deployments where the cloud is the control plane for identity**,** and on-premises directories and other identity systems, such as Active Directory and other on-premises applications, are the target for provisioning users with access. This strategy will continue to ensure the rights, identities, and access in those applications and workloads that rely upon them. At this end state, organizations will be able to drive end-user productivity entirely from the cloud.
110+
In hybrid environments, Microsoft's strategy is to enable deployments where the **cloud is the control plane for identity**, and on-premises directories and other identity systems, such as Active Directory and other on-premises applications, are the target for provisioning users with access. This strategy will continue to ensure the rights, identities, and access in those applications and workloads that rely upon them. At this end state, organizations will be able to drive end-user productivity entirely from the cloud.
111111

112112
![Azure AD architecture](media/cloud-governed-management-for-on-premises/image6.png)
113113

articles/active-directory/manage-apps/application-sign-in-problem-application-error.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -68,7 +68,7 @@ Next time the user signs in to the application, Azure AD send the new attribute
6868

6969
The sign-in to the application is failing because the SAML response is missing attributes such as roles or because the application is expecting a different format or value for the EntityID attribute.
7070

71-
If you're using [Azure AD automated user provisioning](https://docs.microsoft.com/en-us/azure/active-directory/manage-apps/user-provisioning) to create, maintain, and remove users in the application. Then, verify that the user has been successfully provisioned to the SaaS application. For more information, see [No users are being provisioned to an Azure AD Gallery application](https://docs.microsoft.com/en-us/azure/active-directory/manage-apps/application-provisioning-config-problem-no-users-provisioned)
71+
If you're using [Azure AD automated user provisioning](https://docs.microsoft.com/azure/active-directory/manage-apps/user-provisioning) to create, maintain, and remove users in the application. Then, verify that the user has been successfully provisioned to the SaaS application. For more information, see [No users are being provisioned to an Azure AD Gallery application](https://docs.microsoft.com/azure/active-directory/manage-apps/application-provisioning-config-problem-no-users-provisioned)
7272

7373
## Add an attribute in the Azure AD application configuration:
7474

-2.98 KB
Loading

0 commit comments

Comments
 (0)