Skip to content

Commit 845042c

Browse files
authored
Merge pull request #225578 from MicrosoftDocs/main
1/30 AM Publish
2 parents c3b812f + d75edd6 commit 845042c

File tree

125 files changed

+838
-740
lines changed

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

125 files changed

+838
-740
lines changed

articles/active-directory/external-identities/cross-tenant-access-settings-b2b-collaboration.md

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -193,6 +193,12 @@ With inbound settings, you select which external users and groups will be able t
193193

194194
1. Select **Save**.
195195

196+
### Allow users to sync into this tenant
197+
198+
If you select **Inbound access** of the added organization, you'll see the **Cross-tenant sync (Preview)** tab and the **Allow users sync into this tenant** check box. Cross-tenant synchronization is a one-way synchronization service in Azure AD that automates creating, updating, and deleting B2B collaboration users across tenants in an organization. For more information, see [Configure cross-tenant synchronization](../../active-directory/multi-tenant-organizations/cross-tenant-synchronization-configure.md) and the [Multi-tenant organizations documentation](/azure/active-directory/multi-tenant-organizations).
199+
200+
:::image type="content" source="media/cross-tenant-access-settings-b2b-collaboration/cross-tenant-sync-tab.png" alt-text="Screenshot that shows the Cross-tenant sync tab with the Allow users sync into this tenant check box." lightbox="media/cross-tenant-access-settings-b2b-collaboration/cross-tenant-sync-tab.png":::
201+
196202
## Modify outbound access settings
197203

198204
With outbound settings, you select which of your users and groups will be able to access the external applications you choose. Whether you're configuring default settings or organization-specific settings, the steps for changing outbound cross-tenant access settings are the same. As described in this section, you'll navigate to either the **Default** tab or an organization on the **Organizational settings** tab, and then make your changes.

articles/active-directory/external-identities/cross-tenant-access-settings-b2b-direct-connect.md

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -187,6 +187,9 @@ With inbound settings, you select which external users and groups will be able t
187187

188188
1. Select **Save**.
189189

190+
> [!NOTE]
191+
> When configuring settings for an organization, you'll notice a **Cross-tenant sync (Preview)** tab. This tab doesn't apply to your B2B direct connect configuration. Instead, this feature is used by multi-tenant organizations to enable B2B collaboration across their tenants. For more information, see the [multi-tenant organization documentation](/azure/active-directory/multi-tenant-organizations).
192+
190193
## Modify outbound access settings
191194

192195
With outbound settings, you select which of your users and groups will be able to access the external applications you choose. The detailed steps for modifying outbound cross-tenant access settings are the same whether you're configuring default or organization-specific settings. As described in this section, navigate to the **Default** tab or an organization on the **Organizational settings** tab, and then make your changes.

articles/active-directory/external-identities/external-identities-overview.md

Lines changed: 11 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -29,6 +29,8 @@ The following capabilities make up External Identities:
2929

3030
- **Azure AD B2C** - Publish modern SaaS apps or custom-developed apps (excluding Microsoft apps) to consumers and customers, while using Azure AD B2C for identity and access management.
3131

32+
- **Azure AD multi-tenant organization** - Collaborate with multiple tenants in a single Azure AD organization via cross-tenant synchronization.
33+
3234
Depending on how you want to interact with external organizations and the types of resources you need to share, you can use a combination of these capabilities.
3335

3436
![External Identities overview diagram.](media/external-identities-overview/external-identities-b2b-overview.png)
@@ -87,6 +89,8 @@ The following table gives a detailed comparison of the scenarios you can enable
8789
| **Branding** | Host/inviting organization's brand is used. | For sign-in screens, the user’s home organization brand is used. In the shared channel, the resource organization's brand is used. | Fully customizable branding per application or organization. |
8890
| **More information** | [Blog post](https://blogs.technet.microsoft.com/enterprisemobility/2017/02/01/azure-ad-b2b-new-updates-make-cross-business-collab-easy/), [Documentation](what-is-b2b.md) | [Documentation](b2b-direct-connect-overview.md) | [Product page](https://azure.microsoft.com/services/active-directory-b2c/), [Documentation](../../active-directory-b2c/index.yml) |
8991

92+
Based on your organization’s requirements you might use cross-tenant synchronization (preview) in multi-tenant organizations. For more information about this new feature, see the [multi-tenant organization documentation](/azure/active-directory/multi-tenant-organizations) and the [feature comparison](../multi-tenant-organizations/overview.md#compare-multi-tenant-capabilities).
93+
9094
## Managing External Identities features
9195

9296
Azure AD B2B collaboration and B2B direct connect are features Azure AD, and they're managed in the Azure portal through the Azure Active Directory service. To control inbound and outbound collaboration, you can use a combination of *cross-tenant access settings* and *external collaboration settings*.
@@ -101,6 +105,8 @@ Cross-tenant access settings let you manage B2B collaboration and B2B direct con
101105

102106
For more information, see [Cross-tenant access in Azure AD External Identities](cross-tenant-access-overview.md).
103107

108+
Azure AD has a new feature for multi-tenant organizations called cross-tenant synchronization (preview), which allows for a seamless collaboration experience across Azure AD tenants. Cross-tenant synchronization settings are configured under the **Organization-specific access settings**. To learn more about multi-tenant organizations and cross-tenant synchronization see the [Multi-tenant organizations documentation](/azure/active-directory/multi-tenant-organizations).
109+
104110
### Microsoft cloud settings for B2B collaboration (preview)
105111

106112
Microsoft Azure cloud services are available in separate national clouds, which are physically isolated instances of Azure. Increasingly, organizations are finding the need to collaborate with organizations and users across global cloud and national cloud boundaries. With Microsoft cloud settings, you can establish mutual B2B collaboration between the following Microsoft Azure clouds:
@@ -162,8 +168,13 @@ Organizations can enforce Conditional Access policies for external B2B collabora
162168

163169
If you offer a Software as a Service (SaaS) application to many organizations, you can configure your application to accept sign-ins from any Azure Active Directory (Azure AD) tenant. This configuration is called making your application multi-tenant. Users in any Azure AD tenant will be able to sign in to your application after consenting to use their account with your application. See how to [enable multitenant sign-ins](../develop/howto-convert-app-to-be-multi-tenant.md).
164170

171+
### Multi-tenant organizations
172+
173+
A multi-tenant organization is an organization that has more than one instance of Azure AD. There are various reasons for [multi-tenancy](../../active-directory/multi-tenant-organizations/overview.md#what-is-a-multi-tenant-organization), like using multiple clouds or having multiple geographical boundaries. Multi-tenant organizations use a one-way synchronization service in Azure AD, called [cross-tenant synchronization](../../active-directory/multi-tenant-organizations/overview.md#cross-tenant-synchronization-preview). Cross-tenant synchronization enables seamless collaboration for a multi-tenant organization. It improves user experience and ensures that users can access resources, without receiving an invitation email and having to accept a consent prompt in each tenant. Cross-tenant synchronization is currently in preview.
174+
165175
## Next steps
166176

167177
- [What is Azure AD B2B collaboration?](what-is-b2b.md)
168178
- [What is Azure AD B2B direct connect?](b2b-direct-connect-overview.md)
169179
- [About Azure AD B2C](../../active-directory-b2c/overview.md)
180+
- [About Azure AD multi-tenant organizations](../../active-directory/multi-tenant-organizations/overview.md)

articles/active-directory/external-identities/index.yml

Lines changed: 16 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -85,4 +85,19 @@ landingContent:
8585
- text: Add a self-service sign-up user flow
8686
url: self-service-sign-up-user-flow.md
8787
- text: Define custom attributes for user flows
88-
url: user-flow-add-custom-attributes.md
88+
url: user-flow-add-custom-attributes.md
89+
- title: Multi-tenant organizations
90+
linkLists:
91+
- linkListType: overview
92+
links:
93+
- text: What is a multi-tenant organization in Azure AD?
94+
url: ../../active-directory/multi-tenant-organizations/overview.md
95+
- linkListType: concept
96+
links:
97+
- text: Topologies for cross-tenant synchronization
98+
url: ../../active-directory/multi-tenant-organizations/cross-tenant-synchronization-topology.md
99+
- linkListType: how-to-guide
100+
links:
101+
- text: Configure cross-tenant synchronization
102+
url: ../../active-directory/multi-tenant-organizations/cross-tenant-synchronization-overview.md
103+
Loading
Loading

articles/active-directory/external-identities/toc.yml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -70,6 +70,8 @@
7070
href: authentication-conditional-access.md
7171
- name: Azure AD B2C (link to documentation)
7272
href: ../../active-directory-b2c/overview.md
73+
- name: Multi-tenant organizations documentation (link to documentation)
74+
href: ../../active-directory/multi-tenant-organizations/overview.md
7375
- name: How-to guides
7476
expanded: false
7577
items:

articles/active-directory/governance/on-demand-workflow.md

Lines changed: 6 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -8,22 +8,23 @@ ms.service: active-directory
88
ms.subservice: compliance
99
ms.workload: identity
1010
ms.topic: how-to
11-
ms.date: 01/26/2023
11+
ms.date: 01/30/2023
1212
ms.custom: template-how-to
1313
---
1414

1515

1616
# Run a workflow on-demand (Preview)
1717

18-
While most workflows by default are scheduled to run every 3 hours, workflows created using Lifecycle Workflows can also run on-demand so that they can be applied to specific users whenever you see fit. A workflow can be run on demand for any user and doesn't take into account whether or not a user meets the workflow's execution conditions. Workflows created in the Azure portal are disabled by default. Running a workflow on-demand allows you to run workflows that can't be run on schedule currently such as leaver workflows. It also allows you to test workflows before their scheduled run. You can test the workflow on a smaller group of users before enabling it for a broader audience.
18+
Scheduled workflows by default run every 3 hours, but can also run on-demand so that they can be applied to specific users whenever you see fit. A workflow can be run on demand for any user, and doesn't take into account whether or not a user meets the workflow's execution conditions. Running a workflow on-demand allows you to test workflows before their scheduled run. This testing, on a set of users up to 10 at a time, allows you to see how a workflow will run before it processes a larger set of users. Testing your workflow before their scheduled runs helps you proactively solve potential lifecycle issues more quickly.
1919

20-
>[!NOTE]
21-
>Be aware that you currently cannot run a workflow on-demand if it is set to disabled, which is the default state of newly created workflows using the Azure portal. You need to set the workflow to enabled to use the on-demand feature.
2220

2321
## Run a workflow on-demand in the Azure portal
2422

2523
Use the following steps to run a workflow on-demand.
2624

25+
>[!NOTE]
26+
>To be run on demand, the workflow must be enabled.
27+
2728
1. Sign in to the [Azure portal](https://portal.azure.com).
2829

2930
1. Select **Azure Active Directory** and then select **Identity Governance**.
@@ -50,6 +51,7 @@ Use the following steps to run a workflow on-demand.
5051

5152
:::image type="content" source="media/on-demand-workflow/on-demand-run.png" alt-text="Screenshot of a workflow being run on-demand.":::
5253

54+
5355
## Run a workflow on-demand using Microsoft Graph
5456

5557
To run a workflow on-demand using API via Microsoft Graph, see: [workflow: activate (run a workflow on-demand)](/graph/api/identitygovernance-workflow-activate).

articles/active-directory/governance/understanding-lifecycle-workflows.md

Lines changed: 23 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -23,14 +23,31 @@ The following document provides an overview of a workflow created using Lifecycl
2323

2424
[!INCLUDE [Azure AD Premium P2 license](../../../includes/lifecycle-workflows-license.md)]
2525

26-
## Permissions
26+
## Permissions and Roles
2727

28-
The following permissions are required for Lifecycle Workflows:
28+
For a full list of supported delegate and application permissions required to use Lifecycle Workflows, see: [Lifecycle workflows permissions](/graph/permissions-reference#lifecycle-workflows-permissions).
2929

30-
|Parameter |Display String |Description |Admin Consent Required |
31-
|---------|---------|---------|---------|
32-
|LifecycleWorkflows.Read.All | Read all lifecycle workflows and tasks.| Allows the app to list and read all workflows and tasks related to lifecycle workflows on behalf of the signed-in user.| Yes
33-
|LifecycleWorkflows.ReadWrite.All | Read and write all lifecycle workflows and tasks.| Allows the app to create, update, list, read and delete all workflows and tasks related to lifecycle workflows on behalf of the signed-in user.| Yes
30+
For delegated scenarios, the admin needs one of the following [Azure AD roles](/azure/active-directory/users-groups-roles/directory-assign-admin-roles#available-roles):
31+
32+
- Global administrator
33+
- Global reader
34+
- Lifecycle workflows administrator
35+
36+
## Restrictions
37+
38+
39+
|Column1 |Limit |
40+
|---------|---------|
41+
|Number of Workflows | 50 per tenant |
42+
|Number of Tasks | 25 per workflow |
43+
|Number of Custom Task Extensions | 100 per tenant |
44+
|offsetInDays range of triggerAndScopeBasedConditions executionConditions | 60 days |
45+
|Workflow schedule interval in hours | 1-24 hours |
46+
|Number of users per on-demand selection | 10 |
47+
|durationBeforeTimeout range of custom task extensions | 5 minutes-3 hours |
48+
49+
> [!NOTE]
50+
> If creating, or updating, a workflow via API the offsetInDays range will be between -60-60 days. The negative value will signal happening before the timeBasedAttribute, while the positive value will signal happening afterwards.
3451
3552
## Parts of a workflow
3653

articles/active-directory/reports-monitoring/reports-faq.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -9,7 +9,7 @@ metadata:
99
ms.workload: identity
1010
ms.topic: faq
1111
ms.subservice: report-monitor
12-
ms.date: 10/04/2022
12+
ms.date: 01/30/2023
1313
ms.author: sarahlipsey
1414
ms.reviewer: besiler
1515
ms.collection: M365-identity-device-management
@@ -71,7 +71,7 @@ sections:
7171
- question: |
7272
How many records I can download from the Azure portal?
7373
answer: |
74-
You can download up to 250,000 records from the Azure portal. The records are sorted by *most recent* and by default. You can use [Azure AD Reporting APIs](concept-reporting-api.md) to fetch up to a million records at any given point.
74+
You can download up to 250,000 records from the Azure portal. To download data sets larger than 250,000 records, use the [reporting API](/graph/api/resources/azure-ad-auditlog-overview?view=graph-rest-1.0) to download the data.
7575
7676
- question: |
7777
How long does Azure AD store activity logs?

0 commit comments

Comments
 (0)