You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/active-directory/cloud-infrastructure-entitlement-management/cloudknox-onboard-enable-tenant.md
+2-2Lines changed: 2 additions & 2 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -66,7 +66,7 @@ To view a video on how to enable CloudKnox in your Azure AD tenant, select
66
66
67
67
1. Copy the script on the **Welcome** screen:
68
68
69
-
`az ad ap create --id b46c3ac5-9da6-418f-a849-0a7a10b3c6c`
69
+
`az ad sp create --id b46c3ac5-9da6-418f-a849-0a07a10b3c6c`
70
70
71
71
1. If you have an Azure subscription, return to the Azure AD portal and select **Cloud Shell** on the navigation bar.
72
72
If you don't have an Azure subscription, open a command prompt on a Windows Server.
@@ -106,4 +106,4 @@ Use the **Data Collectors** dashboard in CloudKnox to configure data collection
106
106
107
107
- For an overview of CloudKnox, see [What's CloudKnox Permissions Management?](cloudknox-overview.md)
108
108
- For a list of frequently asked questions (FAQs) about CloudKnox, see [FAQs](cloudknox-faqs.md).
109
-
- For information on how to start viewing information about your authorization system in CloudKnox, see [View key statistics and data about your authorization system](cloudknox-ui-dashboard.md).
109
+
- For information on how to start viewing information about your authorization system in CloudKnox, see [View key statistics and data about your authorization system](cloudknox-ui-dashboard.md).
Copy file name to clipboardExpand all lines: articles/active-directory/cloud-infrastructure-entitlement-management/cloudknox-ui-remediation.md
+45-45Lines changed: 45 additions & 45 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -36,29 +36,29 @@ This article provides an overview of the components of the **Remediation** dashb
36
36
37
37
-**Roles/Policies**: Use this subtab to perform Create Read Update Delete (CRUD) operations on roles/policies.
38
38
-**Permissions**: Use this subtab to perform Read Update Delete (RUD) on granted permissions.
39
-
-**Role/Policy template**: Use this subtab to create a template for roles/policies template.
39
+
-**Role/Policy Template**: Use this subtab to create a template for roles/policies template.
40
40
-**Requests**: Use this subtab to view approved, pending, and processed Permission on Demand (POD) requests.
41
-
-**My requests**: Use this tab to manage lifecycle of the POD request either created by you or needs your approval.
42
-
-**Settings**: Use this subtab to select **Request role/policy filters**, **Request settings**, and **Auto-approve** settings.
41
+
-**My Requests**: Use this tab to manage lifecycle of the POD request either created by you or needs your approval.
42
+
-**Settings**: Use this subtab to select **Request Role/Policy Filters**, **Request Settings**, and **Auto-Approve** settings.
43
43
44
44
1. Use the dropdown to select the **Authorization System Type** and **Authorization System**, and then select **Apply**.
45
45
46
46
## View and create roles/policies
47
47
48
48
The **Role/Policies** subtab provides the following settings that you can use to view and create a role/policy.
49
49
50
-
-**Authorization system type**: Displays a dropdown with authorization system types you can access, Amazon Web Services (AWS), Microsoft Azure, and Google Cloud Platform (GCP).
51
-
-**Authorization system**: Displays a list of authorization systems accounts you can access.
52
-
-**Role/Policy type**: A dropdown with available role/policy types. You can select **All**, **Custom**, **System**, or **CloudKnox only**.
53
-
-**Role/Policy status**: A dropdown with available role/policy statuses. You can select **All**, **Assigned**, or **Unassigned**.
54
-
-**Role/Policy usage**: A dropdown with **All** or **Unused** roles/policies.
50
+
-**Authorization System Type**: Displays a dropdown with authorization system types you can access, Amazon Web Services (AWS), Microsoft Azure, and Google Cloud Platform (GCP).
51
+
-**Authorization System**: Displays a list of authorization systems accounts you can access.
52
+
-**Policy Type**: A dropdown with available role/policy types. You can select **All**, **Custom**, **System**, or **CloudKnox Only**.
53
+
-**Policy Status**: A dropdown with available role/policy statuses. You can select **All**, **Assigned**, or **Unassigned**.
54
+
-**Policy Usage**: A dropdown with **All** or **Unused** roles/policies.
55
55
-**Apply**: Select this option to save the changes you've made.
56
56
-**Reset Filter**: Select this option to discard the changes you've made.
57
57
58
-
The **Role/Policies list** displays a list of existing roles/policies and the following information about each role/policy.
58
+
The **Policy list** displays a list of existing roles/policies and the following information about each role/policy.
59
59
60
-
-**Role/Policy name**: The name of the roles/policies available to you.
61
-
-**Role/Policy type**: **Custom**, **System**, or **CloudKnox only**
60
+
-**Policy Name**: The name of the roles/policies available to you.
61
+
-**Policy Type**: **Custom**, **System**, or **CloudKnox Only**
62
62
-**Actions**
63
63
- Select **Clone** to create a duplicate copy of the role/policy.
64
64
- Select **Modify** to change the existing role/policy.
@@ -69,7 +69,7 @@ Other options available to you:
69
69
-**Reload**: Select this option to refresh the displayed list of roles/policies.
70
70
-**Export CSV**: Select this option to export the displayed list of roles/policies as a comma-separated values (CSV) file.
71
71
72
-
When the file is successfully exported, a message appears: **Exported successfully.**
72
+
When the file is successfully exported, a message appears: **Exported Successfully.**
73
73
74
74
- Check your email for a message from the CloudKnox Customer Success Team. This email contains a link to:
75
75
- The **Role Policy Details** report in CSV format.
@@ -81,19 +81,19 @@ Other options available to you:
81
81
82
82
The **Permissions** subtab provides the following settings that you can use to add filters to your permissions.
83
83
84
-
-**Authorization system type**: Displays a dropdown with authorization system types you can access, AWS, Azure, and GCP.
85
-
-**Authorization system**: Displays a list of authorization systems accounts you can access.
86
-
-**Search for**: A dropdown from which you can select **Group**, **User**, or **Role**.
87
-
-**User status**: A dropdown from which you can select **Any**, **Active**, or **Inactive**.
88
-
-**Privilege creep index** (PCI): A dropdown from which you can select a PCI rating of **Any**, **High**, **Medium**, or **Low**.
84
+
-**Authorization System Type**: Displays a dropdown with authorization system types you can access, AWS, Azure, and GCP.
85
+
-**Authorization System**: Displays a list of authorization systems accounts you can access.
86
+
-**Search For**: A dropdown from which you can select **Group**, **User**, or **Role**.
87
+
-**User Status**: A dropdown from which you can select **Any**, **Active**, or **Inactive**.
88
+
-**Privilege Creep Index** (PCI): A dropdown from which you can select a PCI rating of **Any**, **High**, **Medium**, or **Low**.
89
89
-**Task Usage**: A dropdown from which you can select **Any**, **Granted**, **Used**, or **Unused**.
90
-
-**Enter a username**: A dropdown from which you can select a username.
90
+
-**Enter a Username**: A dropdown from which you can select a username.
91
91
-**Enter a Group Name**: A dropdown from which you can select a group name.
92
92
-**Apply**: Select this option to save the changes you've made and run the filter.
93
93
-**Reset Filter**: Select this option to discard the changes you've made.
94
94
-**Export CSV**: Select this option to export the displayed list of roles/policies as a comma-separated values (CSV) file.
95
95
96
-
When the file is successfully exported, a message appears: **Exported successfully.**
96
+
When the file is successfully exported, a message appears: **Exported Successfully.**
97
97
98
98
- Check your email for a message from the CloudKnox Customer Success Team. This email contains a link to:
99
99
- The **Role Policy Details** report in CSV format.
@@ -102,17 +102,17 @@ The **Permissions** subtab provides the following settings that you can use to a
102
102
103
103
## Create templates for roles/policies
104
104
105
-
Use the **Role/Policy template** subtab to create a template for roles/policies.
105
+
Use the **Role/Policy Template** subtab to create a template for roles/policies.
106
106
107
107
1. Select:
108
-
-**Authorization system type**: Displays a dropdown with authorization system types you can access, WS, Azure, and GCP.
109
-
-**Create template**: Select this option to create a template.
108
+
-**Authorization System Type**: Displays a dropdown with authorization system types you can access, WS, Azure, and GCP.
109
+
-**Create Template**: Select this option to create a template.
110
110
111
111
1. In the **Details** page, make the required selections:
112
-
-**Authorization system type**: Select the authorization system types you want, **AWS**, **Azure**, or **GCP**.
113
-
-**Template name**: Enter a name for your template, and then select **Next**.
112
+
-**Authorization System Type**: Select the authorization system types you want, **AWS**, **Azure**, or **GCP**.
113
+
-**Template Name**: Enter a name for your template, and then select **Next**.
114
114
115
-
1. In the **Statements** page, complete the **Tasks**, **Resources**, **Request conditions** and **Effect** sections. Then select **Save** to save your role/policy template.
115
+
1. In the **Statements** page, complete the **Tasks**, **Resources**, **Request Conditions** and **Effect** sections. Then select **Save** to save your role/policy template.
116
116
117
117
Other options available to you:
118
118
-**Search**: Select this option to search for a specific role/policy.
@@ -123,22 +123,22 @@ Other options available to you:
123
123
Use the **Requests** tab to view a list of **Pending**, **Approved**, and **Processed** requests for permissions your team members have made.
124
124
125
125
- Select:
126
-
-**Authorization system type**: Displays a dropdown with authorization system types you can access, AWS, Azure, and GCP.
127
-
-**Authorization system**: Displays a list of authorization systems accounts you can access.
126
+
-**Authorization System Type**: Displays a dropdown with authorization system types you can access, AWS, Azure, and GCP.
127
+
-**Authorization System**: Displays a list of authorization systems accounts you can access.
128
128
129
129
Other options available to you:
130
130
131
131
-**Reload**: Select this option to refresh the displayed list of roles/policies.
132
132
-**Search**: Select this option to search for a specific role/policy.
133
133
-**Columns**: Select one or more of the following to view more information about the request:
134
-
-**Submitted by**
135
-
-**On behalf of**
136
-
-**Authorization system**
137
-
-**Tasks/scope/policies**
138
-
-**Request date**
134
+
-**Submitted By**
135
+
-**On Behalf Of**
136
+
-**Authorization System**
137
+
-**Tasks/Scope/Policies**
138
+
-**Request Date**
139
139
-**Schedule**
140
140
-**Submitted**
141
-
-**Reset to default**: Select this option to discard your settings.
141
+
-**Reset to Default**: Select this option to discard your settings.
142
142
143
143
### View pending requests
144
144
@@ -174,21 +174,21 @@ The **Processed** table displays information about the requests that have been p
174
174
Use the **My Requests** subtab to view a list of **Pending**, **Approved**, and **Processed** requests for permissions your team members have made and you must approve or reject.
175
175
176
176
- Select:
177
-
-**Authorization system type**: Displays a dropdown with authorization system types you can access, AWS, Azure, and GCP.
178
-
-**Authorization system**: Displays a list of authorization systems accounts you can access.
177
+
-**Authorization System Type**: Displays a dropdown with authorization system types you can access, AWS, Azure, and GCP.
178
+
-**Authorization System**: Displays a list of authorization systems accounts you can access.
179
179
180
180
Other options available to you:
181
181
182
182
-**Reload**: Select this option to refresh the displayed list of roles/policies.
183
183
-**Search**: Select this option to search for a specific role/policy.
184
184
-**Columns**: Select one or more of the following to view more information about the request:
185
-
-**On behalf of**
186
-
-**Authorization system**
187
-
-**Tasks/scope/policies**
188
-
-**Request date**
185
+
-**On Behalf Of**
186
+
-**Authorization System**
187
+
-**Tasks/Scope/Policies**
188
+
-**Request Date**
189
189
-**Schedule**
190
-
-**Reset to default**: Select this option to discard your settings.
191
-
-**New request**: Select this option to create a new request for permissions. For more information, see Create a request for permissions.
190
+
-**Reset to Default**: Select this option to discard your settings.
191
+
-**New Request**: Select this option to create a new request for permissions. For more information, see Create a request for permissions.
192
192
193
193
### View pending requests
194
194
@@ -218,12 +218,12 @@ The **Processed** table displays information about the requests that have been p
218
218
219
219
## Make setting selections for requests and auto-approval
220
220
221
-
The **Settings** subtab provides the following settings that you can use to make setting selections to **Request role/policy filters**, **Request settings**, and **Auto-approve** requests.
221
+
The **Settings** subtab provides the following settings that you can use to make setting selections to **Request Role/Policy Filters**, **Request Settings**, and **Auto-Approve** requests.
222
222
223
-
-**Authorization system type**: Displays a dropdown with authorization system types you can access, AWS, Azure, and GCP.
224
-
-**Authorization system**: Displays a list of authorization systems accounts you can access.
223
+
-**Authorization System Type**: Displays a dropdown with authorization system types you can access, AWS, Azure, and GCP.
224
+
-**Authorization System**: Displays a list of authorization systems accounts you can access.
225
225
-**Reload**: Select this option to refresh the displayed list of role/policy filters.
226
-
-**Create filter**: Select this option to create a new filter.
226
+
-**Create Filter**: Select this option to create a new filter.
Copy file name to clipboardExpand all lines: articles/active-directory/develop/scenario-web-api-call-api-overview.md
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -32,7 +32,7 @@ This scenario, in which a protected web API calls other web APIs, builds on [Sce
32
32
33
33
## Specifics
34
34
35
-
The app registration part that's related to API permissions is classical. The app configuration involves using the OAuth 2.0 On-Behalf-Of flow to exchange the JWT bearer token against a token for a downstream API. This token is added to the token cache, where it's available in the web API's controllers, and it can then acquire a token silently to call downstream APIs.
35
+
The app registration part that's related to API permissions is classical. The app configuration involves using the OAuth 2.0 On-Behalf-Of flow to use the JWT bearer token for obtaining a second token for a downstream API. The second token in this case is added to the token cache, where it's available in the web API's controllers. This second token can be used to acquire an access token silently to call downstream APIs whenever required.
0 commit comments