Skip to content

Commit a411580

Browse files
Learn Build Service GitHub AppLearn Build Service GitHub App
authored andcommitted
Merging changes synced from https://github.com/MicrosoftDocs/azure-docs-pr (branch live)
2 parents f331c58 + bab71f5 commit a411580

File tree

142 files changed

+3120
-2839
lines changed

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

142 files changed

+3120
-2839
lines changed

.openpublishing.redirection.json

Lines changed: 16 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -13841,7 +13841,7 @@
1384113841
{
1384213842
"source_path_from_root": "/articles/load-balancer/use-existing-lb-vmss-cli.md",
1384313843
"redirect_url": "/azure/load-balancer/configure-vm-scale-set-cli",
13844-
"redirect_document_id": ""
13844+
"redirect_document_id": false
1384513845
},
1384613846
{
1384713847
"source_path_from_root": "/articles/load-balancer/load-balancer-get-started-internet-classic-portal.md",
@@ -23998,6 +23998,21 @@
2399823998
"redirect_url": "/azure/networking/manage-apps/connectivity-interoperability-data-plane",
2399923999
"redirect_document_id": false
2400024000
},
24001+
{
24002+
"source_path_from_root": "/articles/operator-nexus/howto-hybrid-aks.md",
24003+
"redirect_url": "/azure/operator-nexus/howto-kubernetes-cluster-agent-pools",
24004+
"redirect_document_id": false
24005+
},
24006+
{
24007+
"source_path_from_root": "/articles/operator-nexus/template-virtualized-network-function-deployment.md",
24008+
"redirect_url": "/azure/operator-nexus/quickstarts-tenant-workload-deployment",
24009+
"redirect_document_id": false
24010+
},
24011+
{
24012+
"source_path_from_root": "/articles/operator-nexus/template-cloud-native-network-function-deployment.md",
24013+
"redirect_url": "/azure/operator-nexus/quickstarts-kubernetes-cluster-deployment-cli",
24014+
"redirect_document_id": false
24015+
},
2400124016
{
2400224017
"source_path_from_root": "/articles/container-registry/github-action-scan.md",
2400324018
"redirect_url": "/azure/developer/github/",

articles/active-directory/develop/reference-claims-mapping-policy-type.md

Lines changed: 109 additions & 35 deletions
Original file line numberDiff line numberDiff line change
@@ -44,6 +44,7 @@ The following claims are in the restricted claim set for a JWT.
4444
- `acr`
4545
- `acrs`
4646
- `actor`
47+
- `actortoken`
4748
- `ageGroup`
4849
- `aio`
4950
- `altsecid`
@@ -55,41 +56,68 @@ The following claims are in the restricted claim set for a JWT.
5556
- `appctxsender`
5657
- `appid`
5758
- `appidacr`
59+
- `assertion`
5860
- `at_hash`
61+
- `aud`
62+
- `auth_data`
5963
- `auth_time`
64+
- `authorization_code`
6065
- `azp`
6166
- `azpacr`
67+
- `bk_claim`
68+
- `bk_enclave`
69+
- `bk_pub`
70+
- `brk_client_id`
71+
- `brk_redirect_uri`
6272
- `c_hash`
6373
- `ca_enf`
6474
- `ca_policy_result`
65-
- `capolids_latebind`
6675
- `capolids`
76+
- `capolids_latebind`
6777
- `cc`
78+
- `cert_token_use`
79+
- `child_client_id`
80+
- `child_redirect_uri`
81+
- `client_id`
82+
- `client_ip`
83+
- `cloud_graph_host_name`
84+
- `cloud_instance_host_name`
85+
- `cloud_instance_name`
86+
- `CloudAssignedMdmId`
6887
- `cnf`
6988
- `code`
70-
- `controls_auds`
7189
- `controls`
90+
- `controls_auds`
7291
- `credential_keys`
92+
- `csr`
93+
- `csr_type`
7394
- `ctry`
7495
- `deviceid`
96+
- `dns_names`
7597
- `domain_dns_name`
7698
- `domain_netbios_name`
7799
- `e_exp`
78100
- `email`
79101
- `endpoint`
80102
- `enfpolids`
103+
- `exp`
81104
- `expires_on`
105+
- `extn. as prefix`
82106
- `fido_auth_data`
83-
- `fwd_appidacr`
107+
- `fido_ver`
84108
- `fwd`
109+
- `fwd_appidacr`
110+
- `grant_type`
85111
- `graph`
86112
- `group_sids`
87113
- `groups`
88114
- `hasgroups`
115+
- `hash_alg`
89116
- `haswids`
90117
- `home_oid`
91118
- `home_puid`
92119
- `home_tid`
120+
- `iat`
93121
- `identityprovider`
94122
- `idp`
95123
- `idtyp`
@@ -98,16 +126,23 @@ The following claims are in the restricted claim set for a JWT.
98126
- `inviteTicket`
99127
- `ipaddr`
100128
- `isbrowserhostedapp`
129+
- `iss`
101130
- `isViral`
131+
- `jwk`
132+
- `key_id`
133+
- `key_type`
102134
- `login_hint`
103135
- `mam_compliance_url`
104136
- `mam_enrollment_url`
105137
- `mam_terms_of_use_url`
106138
- `mdm_compliance_url`
107139
- `mdm_enrollment_url`
108140
- `mdm_terms_of_use_url`
141+
- `msgraph_host`
109142
- `msproxy`
110143
- `nameid`
144+
- `nbf`
145+
- `netbios_name`
111146
- `nickname`
112147
- `nonce`
113148
- `oid`
@@ -116,25 +151,35 @@ The following claims are in the restricted claim set for a JWT.
116151
- `onprem_sid`
117152
- `openid2_id`
118153
- `origin_header`
154+
- `password`
119155
- `platf`
120156
- `polids`
121157
- `pop_jwk`
122158
- `preferred_username`
159+
- `previous_refresh_token`
123160
- `primary_sid`
124161
- `prov_data`
125162
- `puid`
126163
- `pwd_exp`
127164
- `pwd_url`
128165
- `rdp_bt`
166+
- `redirect_uri`
167+
- `refresh_token`
129168
- `refresh_token_issued_on`
130169
- `refreshtoken`
170+
- `request_nonce`
171+
- `resource`
131172
- `rh`
173+
- `role`
132174
- `roles`
175+
- `rp_id`
133176
- `rt_type`
177+
- `scope`
134178
- `scp`
135179
- `secaud`
136180
- `sid`
137181
- `sid`
182+
- `signature`
138183
- `signin_state`
139184
- `source_anchor`
140185
- `src1`
@@ -145,6 +190,7 @@ The following claims are in the restricted claim set for a JWT.
145190
- `tbidv2`
146191
- `tenant_ctry`
147192
- `tenant_display_name`
193+
- `tenant_id`
148194
- `tenant_region_scope`
149195
- `tenant_region_sub_scope`
150196
- `thumbnail_photo`
@@ -154,60 +200,88 @@ The following claims are in the restricted claim set for a JWT.
154200
- `ttr`
155201
- `unique_name`
156202
- `upn`
203+
- `user_agent`
157204
- `user_setting_sync_url`
205+
- `username`
158206
- `uti`
159207
- `ver`
160208
- `verified_primary_email`
161209
- `verified_secondary_email`
162210
- `vnet`
211+
- `vsm_binding_key`
163212
- `wamcompat_client_info`
164213
- `wamcompat_id_token`
165214
- `wamcompat_scopes`
166215
- `wids`
216+
- `win_ver`
217+
- `x5c_ca`
167218
- `xcb2b_rclient`
168219
- `xcb2b_rcloud`
169220
- `xcb2b_rtenant`
170221
- `ztdid`
171222

223+
172224
> [!NOTE]
173225
> Any claim starting with `xms_` is restricted.
174226
175227
### SAML restricted claim set
176228

177229
The following table lists the SAML claims that are in the restricted claim set.
178230

179-
| Claim type (URI) |
180-
| ----- |
181-
|`http://schemas.microsoft.com/2012/01/devicecontext/claims/ismanaged`|
182-
|`http://schemas.microsoft.com/2014/02/devicecontext/claims/isknown`|
183-
|`http://schemas.microsoft.com/2014/03/psso`|
184-
|`http://schemas.microsoft.com/2014/09/devicecontext/claims/iscompliant`|
185-
|`http://schemas.microsoft.com/claims/authnmethodsreferences`|
186-
|`http://schemas.microsoft.com/claims/groups.link`|
187-
|`http://schemas.microsoft.com/identity/claims/accesstoken`|
188-
|`http://schemas.microsoft.com/identity/claims/acct`|
189-
|`http://schemas.microsoft.com/identity/claims/agegroup`|
190-
|`http://schemas.microsoft.com/identity/claims/aio`|
191-
|`http://schemas.microsoft.com/identity/claims/identityprovider`|
192-
|`http://schemas.microsoft.com/identity/claims/objectidentifier`|
193-
|`http://schemas.microsoft.com/identity/claims/openid2_id`|
194-
|`http://schemas.microsoft.com/identity/claims/puid`|
195-
|`http://schemas.microsoft.com/identity/claims/tenantid`|
196-
|`http://schemas.microsoft.com/identity/claims/xms_et`|
197-
|`http://schemas.microsoft.com/ws/2008/06/identity/claims/authenticationinstant`|
198-
|`http://schemas.microsoft.com/ws/2008/06/identity/claims/authenticationmethod`|
199-
|`http://schemas.microsoft.com/ws/2008/06/identity/claims/expiration`|
200-
|`http://schemas.microsoft.com/ws/2008/06/identity/claims/groups`|
201-
|`http://schemas.microsoft.com/ws/2008/06/identity/claims/role`|
202-
|`http://schemas.microsoft.com/ws/2008/06/identity/claims/wids`|
203-
|`http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier`|
204-
| `http://schemas.microsoft.com/ws/2008/06/identity/claims/windowsaccountname` |
205-
| `http://schemas.microsoft.com/ws/2008/06/identity/claims/primarysid` |
206-
| `http://schemas.microsoft.com/ws/2008/06/identity/claims/primarygroupsid` |
207-
| `http://schemas.xmlsoap.org/ws/2005/05/identity/claims/sid` |
208-
| `http://schemas.xmlsoap.org/ws/2005/05/identity/claims/x500distinguishedname` |
209-
| `http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn` |
210-
| `http://schemas.microsoft.com/ws/2008/06/identity/claims/role` |
231+
Restricted Claim type (URI):
232+
- `http://schemas.microsoft.com/2012/01/devicecontext/claims/ismanaged`
233+
- `http://schemas.microsoft.com/2014/02/devicecontext/claims/isknown`
234+
- `http://schemas.microsoft.com/2014/03/psso`
235+
- `http://schemas.microsoft.com/2014/09/devicecontext/claims/iscompliant`
236+
- `http://schemas.microsoft.com/claims/authnmethodsreferences`
237+
- `http://schemas.microsoft.com/claims/groups.link`
238+
- `http://schemas.microsoft.com/identity/claims/accesstoken`
239+
- `http://schemas.microsoft.com/identity/claims/acct`
240+
- `http://schemas.microsoft.com/identity/claims/agegroup`
241+
- `http://schemas.microsoft.com/identity/claims/aio`
242+
- `http://schemas.microsoft.com/identity/claims/identityprovider`
243+
- `http://schemas.microsoft.com/identity/claims/objectidentifier`
244+
- `http://schemas.microsoft.com/identity/claims/openid2_id`
245+
- `http://schemas.microsoft.com/identity/claims/puid`
246+
- `http://schemas.microsoft.com/identity/claims/scope`
247+
- `http://schemas.microsoft.com/identity/claims/tenantid`
248+
- `http://schemas.microsoft.com/identity/claims/xms_et`
249+
- `http://schemas.microsoft.com/ws/2008/06/identity/claims/authenticationinstant`
250+
- `http://schemas.microsoft.com/ws/2008/06/identity/claims/authenticationmethod`
251+
- `http://schemas.microsoft.com/ws/2008/06/identity/claims/confirmationkey`
252+
- `http://schemas.microsoft.com/ws/2008/06/identity/claims/denyonlyprimarygroupsid`
253+
- `http://schemas.microsoft.com/ws/2008/06/identity/claims/denyonlyprimarysid`
254+
- `http://schemas.microsoft.com/ws/2008/06/identity/claims/denyonlywindowsdevicegroup`
255+
- `http://schemas.microsoft.com/ws/2008/06/identity/claims/expiration`
256+
- `http://schemas.microsoft.com/ws/2008/06/identity/claims/expired`
257+
- `http://schemas.microsoft.com/ws/2008/06/identity/claims/groups`
258+
- `http://schemas.microsoft.com/ws/2008/06/identity/claims/groupsid`
259+
- `http://schemas.microsoft.com/ws/2008/06/identity/claims/ispersistent`
260+
- `http://schemas.microsoft.com/ws/2008/06/identity/claims/primarygroupsid`
261+
- `http://schemas.microsoft.com/ws/2008/06/identity/claims/primarysid`
262+
- `http://schemas.microsoft.com/ws/2008/06/identity/claims/role`
263+
- `http://schemas.microsoft.com/ws/2008/06/identity/claims/role`
264+
- `http://schemas.microsoft.com/ws/2008/06/identity/claims/samlissuername`
265+
- `http://schemas.microsoft.com/ws/2008/06/identity/claims/wids`
266+
- `http://schemas.microsoft.com/ws/2008/06/identity/claims/windowsaccountname`
267+
- `http://schemas.microsoft.com/ws/2008/06/identity/claims/windowsdeviceclaim`
268+
- `http://schemas.microsoft.com/ws/2008/06/identity/claims/windowsdevicegroup`
269+
- `http://schemas.microsoft.com/ws/2008/06/identity/claims/windowsfqbnversion`
270+
- `http://schemas.microsoft.com/ws/2008/06/identity/claims/windowssubauthority`
271+
- `http://schemas.microsoft.com/ws/2008/06/identity/claims/windowsuserclaim`
272+
- `http://schemas.xmlsoap.org/ws/2005/05/identity/claims/authentication`
273+
- `http://schemas.xmlsoap.org/ws/2005/05/identity/claims/authorizationdecision`
274+
- `http://schemas.xmlsoap.org/ws/2005/05/identity/claims/denyonlysid`
275+
- `http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress`
276+
- `http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name`
277+
- `http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier`
278+
- `http://schemas.xmlsoap.org/ws/2005/05/identity/claims/privatepersonalidentifier`
279+
- `http://schemas.xmlsoap.org/ws/2005/05/identity/claims/sid`
280+
- `http://schemas.xmlsoap.org/ws/2005/05/identity/claims/spn`
281+
- `http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn`
282+
- `http://schemas.xmlsoap.org/ws/2005/05/identity/claims/x500distinguishedname`
283+
- `http://schemas.xmlsoap.org/ws/2009/09/identity/claims/actor`
284+
211285

212286
These claims are restricted by default, but aren't restricted if you [set the AcceptMappedClaims property](saml-claims-customization.md) to `true` in your app manifest *or* have a [custom signing key](saml-claims-customization.md):
213287

articles/active-directory/external-identities/customers/how-to-register-ciam-app.md

Lines changed: 19 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -4,7 +4,7 @@ description: Learn about how to register an app in the customer tenant.
44
services: active-directory
55
author: csmulligan
66
ms.author: cmulligan
7-
manager: celestedg
7+
manager: CelesteDG
88
ms.service: active-directory
99
ms.workload: identity
1010
ms.subservice: ciam
@@ -71,7 +71,7 @@ This app signs in users. You can add delegated permissions to it, by following t
7171

7272
[!INCLUDE [grant permision for signing in users](../customers/includes/register-app/grant-api-permission-sign-in.md)]
7373

74-
### If you want to call an API follow the steps below (optional):
74+
### To call an API follow the steps below (optional):
7575
[!INCLUDE [grant permisions for calling an API](../customers/includes/register-app/grant-api-permission-call-api.md)]
7676

7777
If you'd like to learn how to expose the permissions by adding a link, go to the [Web API](how-to-register-ciam-app.md?tabs=webapi) section.
@@ -122,7 +122,7 @@ This app signs in users. You can add delegated permissions to it, by following t
122122
### Create a client secret 
123123
[!INCLUDE [add a client secret](../customers/includes/register-app/add-app-client-secret.md)]
124124

125-
### If you want to call an API follow the steps below (optional):
125+
### To call an API follow the steps below (optional):
126126
[!INCLUDE [grant permissions for calling an API](../customers/includes/register-app/grant-api-permission-call-api.md)]
127127

128128
## Next steps
@@ -139,7 +139,7 @@ This app signs in users. You can add delegated permissions to it, by following t
139139

140140
[!INCLUDE [expose permissions](../customers/includes/register-app/add-api-scopes.md)]
141141

142-
### If you want to add app roles follow the steps below (optional):
142+
### To add app roles follow the steps below (optional):
143143

144144
[!INCLUDE [configure app roles](../customers/includes/register-app/add-app-role.md)]
145145

@@ -181,7 +181,7 @@ The following steps show you how to register your app in the admin center:
181181
### Add delegated permissions
182182
[!INCLUDE [grant permission for signing in users](../customers/includes/register-app/grant-api-permission-sign-in.md)]
183183

184-
### If you want to call an API follow the steps below (optional):
184+
### To call an API follow the steps below (optional):
185185
[!INCLUDE [grant permissions for calling an API](../customers/includes/register-app/grant-api-permission-call-api.md)]
186186

187187
## Next steps
@@ -194,7 +194,7 @@ The following steps show you how to register your app in the admin center:
194194

195195
[!INCLUDE [register daemon app](../customers/includes/register-app/register-daemon-app.md)]
196196

197-
### If you want to call an API follow the steps below (optional)
197+
### To call an API follow the steps below (optional)
198198
A daemon app signs-in as itself using the [OAuth 2.0 client credentials flow](/azure/active-directory/develop/v2-oauth2-client-creds-grant-flow), you add application permissions, which is required by apps that authenticate as themselves:
199199

200200
[!INCLUDE [register daemon app](../customers/includes/register-app/grant-api-permissions-app-permissions.md)]
@@ -203,3 +203,16 @@ A daemon app signs-in as itself using the [OAuth 2.0 client credentials flow](/a
203203

204204
- Learn more about a [daemon app that calls a web API in the daemon's name](/azure/active-directory/develop/authentication-flows-app-scenarios#daemon-app-that-calls-a-web-api-in-the-daemons-name)
205205
- [Create a sign-up and sign-in user flow](how-to-user-flow-sign-up-sign-in-customers.md)
206+
207+
# [Microsoft Graph API](#tab/graphapi)
208+
## How to register a Microsoft Graph API application?
209+
[!INCLUDE [register client app](../customers/includes/register-app/register-client-app-common.md)]
210+
211+
### Grant API Access to your application
212+
[!INCLUDE [grant api access to app](../customers/includes/register-app/grant-api-access-app.md)]
213+
214+
### Create a client secret
215+
[!INCLUDE [add app client secret](../customers/includes/register-app/add-app-client-secret.md)]
216+
217+
## Next steps
218+
- Learn more how to manage [Azure Active Directory for customers resources with Microsoft Graph](microsoft-graph-operations.md)

0 commit comments

Comments
 (0)