Skip to content

Commit a7a2a0c

Browse files
committed
Merge branch 'main' of https://github.com/MicrosoftDocs/azure-docs-pr into mwahl-aad-em-co
2 parents a3c3c91 + 0155307 commit a7a2a0c

File tree

691 files changed

+5184
-3207
lines changed

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

691 files changed

+5184
-3207
lines changed

.openpublishing.redirection.active-directory.json

Lines changed: 40 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1025,6 +1025,26 @@
10251025
"redirect_url": "/azure/active-directory/active-directory-b2b-admin-add-users",
10261026
"redirect_document_id": false
10271027
},
1028+
{
1029+
"source_path_from_root": "/articles/active-directory/external-identities/customers/how-to-browserless-app-dotnet-sign-in-overview.md",
1030+
"redirect_url": "/azure/active-directory/external-identities/customers/tutorial-browserless-app-dotnet-sign-in-prepare-tenant",
1031+
"redirect_document_id": true
1032+
},
1033+
{
1034+
"source_path_from_root": "/articles/active-directory/external-identities/customers/how-to-browserless-app-dotnet-sign-in-prepare-app.md",
1035+
"redirect_url": "/azure/active-directory/external-identities/customers/tutorial-browserless-app-dotnet-sign-in-build-app",
1036+
"redirect_document_id": false
1037+
},
1038+
{
1039+
"source_path_from_root": "/articles/active-directory/external-identities/customers/how-to-browserless-app-dotnet-sign-in-prepare-tenant.md",
1040+
"redirect_url": "/azure/active-directory/external-identities/customers/tutorial-browserless-app-dotnet-sign-in-prepare-tenant",
1041+
"redirect_document_id": false
1042+
},
1043+
{
1044+
"source_path_from_root": "/articles/active-directory/external-identities/customers/how-to-browserless-app-dotnet-sign-in-sign-in.md",
1045+
"redirect_url": "/azure/active-directory/external-identities/customers/tutorial-browserless-app-dotnet-sign-in-build-app",
1046+
"redirect_document_id": false
1047+
},
10281048
{
10291049
"source_path_from_root": "/articles/active-directory/external-identities/delegate-invitations.md",
10301050
"redirect_url": "/azure/active-directory/external-identities/external-collaboration-settings-configure",
@@ -1055,6 +1075,26 @@
10551075
"redirect_url": "/azure/active-directory/external-identities/customers/web-app-quickstart-portal-node-js-ciam",
10561076
"redirect_document_id": true
10571077
},
1078+
{
1079+
"source_path_from_root": "/articles/active-directory/external-identities/customers/how-to-daemon-node-call-api-overview.md",
1080+
"redirect_url": "/azure/active-directory/external-identities/customers/tutorial-daemon-node-call-api-prepare-tenant",
1081+
"redirect_document_id": true
1082+
},
1083+
{
1084+
"source_path_from_root": "/articles/active-directory/external-identities/customers/how-to-daemon-node-call-api-prepare-app.md",
1085+
"redirect_url": "/azure/active-directory/external-identities/customers/tutorial-daemon-node-call-api-prepare-tenant",
1086+
"redirect_document_id": false
1087+
},
1088+
{
1089+
"source_path_from_root": "/articles/active-directory/external-identities/customers/how-to-daemon-node-call-api-prepare-tenant.md",
1090+
"redirect_url": "/azure/active-directory/external-identities/customers/tutorial-daemon-node-call-api-prepare-tenant",
1091+
"redirect_document_id": false
1092+
},
1093+
{
1094+
"source_path_from_root": "/articles/active-directory/external-identities/customers/how-to-daemon-node-call-api-call-api.md",
1095+
"redirect_url": "/azure/active-directory/external-identities/customers/tutorial-daemon-node-call-api-prepare-tenant",
1096+
"redirect_document_id": false
1097+
},
10581098
{
10591099
"source_path_from_root": "/articles/active-directory/external-identities/conditional-access.md",
10601100
"redirect_url": "/azure/active-directory/external-identities/authentication-conditional-access",

.openpublishing.redirection.json

Lines changed: 10 additions & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,15 @@
11
{
22
"redirections": [
3+
{
4+
"source_path": "articles/route-server/tutorial-protect-route-server.md",
5+
"redirect_URL": "/azure/route-server/tutorial-protect-route-server-ddos",
6+
"redirect_document_id": false
7+
},
8+
{
9+
"source_path": "articles/route-server/routing-preference.md",
10+
"redirect_url": "/azure/route-server/overview",
11+
"redirect_document_id": false
12+
},
313
{
414
"source_path": "articles/cloud-services-extended-support/deploy-visual-studio.md",
515
"redirect_url": "/visualstudio/azure/cloud-services-extended-support?context=%2Fazure%2Fcloud-services-extended-support%2Fcontext%2Fcontext",
@@ -860,11 +870,6 @@
860870
"redirect_url": "/azure/ddos-protection/ddos-protection-sku-comparison#limitations",
861871
"redirect_document_id": false
862872
},
863-
{
864-
"source_path": "articles/route-server/routing-preference.md",
865-
"redirect_url": "/azure/route-server/overview",
866-
"redirect_document_id": false
867-
},
868873
{
869874
"source_path": "articles/storage/queues/storage-ruby-how-to-use-queue-storage.md",
870875
"redirect_url": "/previous-versions/azure/storage/queues/storage-ruby-how-to-use-queue-storage",
@@ -23558,11 +23563,6 @@
2355823563
"redirect_URL": "/azure/firewall/tutorial-protect-firewall-ddos",
2355923564
"redirect_document_id": false
2356023565
},
23561-
{
23562-
"source_path": "articles/route-server/tutorial-protect-route-server.md",
23563-
"redirect_URL": "/azure/route-server/tutorial-protect-route-server-ddos",
23564-
"redirect_document_id": false
23565-
},
2356623566
{
2356723567
"source_path": "articles/external-attack-surface-management/data-connections-overview.md",
2356823568
"redirect_URL": "/azure/external-attack-surface-management/index",

articles/active-directory-domain-services/policy-reference.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
---
22
title: Built-in policy definitions for Azure Active Directory Domain Services
33
description: Lists Azure Policy built-in policy definitions for Azure Active Directory Domain Services. These built-in policy definitions provide common approaches to managing your Azure resources.
4-
ms.date: 07/18/2023
4+
ms.date: 07/25/2023
55
ms.service: active-directory
66
ms.subservice: domain-services
77
author: justinha

articles/active-directory/authentication/fido2-compatibility.md

Lines changed: 74 additions & 22 deletions
Original file line numberDiff line numberDiff line change
@@ -6,7 +6,7 @@ services: active-directory
66
ms.service: active-directory
77
ms.subservice: authentication
88
ms.topic: conceptual
9-
ms.date: 06/29/2023
9+
ms.date: 07/26/2023
1010

1111
author: justinha
1212
ms.author: justinha
@@ -21,32 +21,84 @@ Azure Active Directory allows [FIDO2 security keys](./concept-authentication-pas
2121

2222
## Supported browsers
2323

24-
This table shows support for authenticating Azure Active Directory (Azure AD) and Microsoft Accounts (MSA). Microsoft accounts are created by consumers for services such as Xbox, Skype, or Outlook.com. Supported device types include **USB**, near-field communication (**NFC**), and bluetooth low energy (**BLE**).
24+
This table shows support for authenticating Azure Active Directory (Azure AD) and Microsoft Accounts (MSA). Microsoft accounts are created by consumers for services such as Xbox, Skype, or Outlook.com.
2525

26-
| OS | Chrome | Chrome | Chrome | Edge | Edge | Edge | Firefox | Firefox | Firefox | Safari | Safari | Safari
27-
|:---:|:---:|:---:|:---:|:---:|:---:|:---:|:---:|:---:|:---:|:---:|:---:|:---:|
28-
| | USB | NFC | BLE | USB | NFC | BLE | USB | NFC | BLE | USB | NFC | BLE |
29-
| **Windows** | ![Chrome supports USB on Windows for Azure AD accounts.][y] | ![Chrome supports NFC on Windows for Azure AD accounts.][y] | ![Chrome supports BLE on Windows for Azure AD accounts.][y] | ![Edge supports USB on Windows for Azure AD accounts.][y] | ![Edge supports NFC on Windows for Azure AD accounts.][y] | ![Edge supports BLE on Windows for Azure AD accounts.][y] | ![Firefox supports USB on Windows for Azure AD accounts.][y] | ![Firefox supports NFC on Windows for Azure AD accounts.][y] | ![Firefox supports BLE on Windows for Azure AD accounts.][y] | ![Safari supports USB on Windows for Azure AD accounts.][n] | ![Safari supports NFC on Windows for Azure AD accounts.][n] | ![Safari supports BLE on Windows for Azure AD accounts.][n] |
30-
| **macOS** | ![Chrome supports USB on macOS for Azure AD accounts.][y] | ![Chrome supports NFC on macOS for Azure AD accounts.][n] | ![Chrome supports BLE on macOS for Azure AD accounts.][n] | ![Edge supports USB on macOS for Azure AD accounts.][y] | ![Edge supports NFC on macOS for Azure AD accounts.][n] | ![Edge supports BLE on macOS for Azure AD accounts.][n] | ![Firefox supports USB on macOS for Azure AD accounts.][n] | ![Firefox supports NFC on macOS for Azure AD accounts.][n] | ![Firefox supports BLE on macOS for Azure AD accounts.][n] | ![Safari supports USB on macOS for Azure AD accounts.][y] | ![Safari supports NFC on macOS for Azure AD accounts.][n] | ![Safari supports BLE on macOS for Azure AD accounts.][n] |
31-
| **ChromeOS** | ![Chrome supports USB on ChromeOS for Azure AD accounts.][y] | ![Chrome supports NFC on ChromeOS for Azure AD accounts.][n] | ![Chrome supports BLE on ChromeOS for Azure AD accounts.][n] | ![Edge supports USB on ChromeOS for Azure AD accounts.][n] | ![Edge supports NFC on ChromeOS for Azure AD accounts.][n] | ![Edge supports BLE on ChromeOS for Azure AD accounts.][n] | ![Firefox supports USB on ChromeOS for Azure AD accounts.][n] | ![Firefox supports NFC on ChromeOS for Azure AD accounts.][n] | ![Firefox supports BLE on ChromeOS for Azure AD accounts.][n] | ![Safari supports USB on ChromeOS for Azure AD accounts.][n] | ![Safari supports NFC on ChromeOS for Azure AD accounts.][n] | ![Safari supports BLE on ChromeOS for Azure AD accounts.][n] |
32-
| **Linux** | ![Chrome supports USB on Linux for Azure AD accounts.][y] | ![Chrome supports NFC on Linux for Azure AD accounts.][n] | ![Chrome supports BLE on Linux for Azure AD accounts.][n] | ![Edge supports USB on Linux for Azure AD accounts.][n] | ![Edge supports NFC on Linux for Azure AD accounts.][n] | ![Edge supports BLE on Linux for Azure AD accounts.][n] | ![Firefox supports USB on Linux for Azure AD accounts.][n] | ![Firefox supports NFC on Linux for Azure AD accounts.][n] | ![Firefox supports BLE on Linux for Azure AD accounts.][n] | ![Safari supports USB on Linux for Azure AD accounts.][n] | ![Safari supports NFC on Linux for Azure AD accounts.][n] | ![Safari supports BLE on Linux for Azure AD accounts.][n] |
33-
| **iOS** | ![Chrome supports USB on iOS for Azure AD accounts.][y] | ![Chrome supports NFC on iOS for Azure AD accounts.][y] | ![Chrome supports BLE on iOS for Azure AD accounts.][n] | ![Edge supports USB on iOS for Azure AD accounts.][y] | ![Edge supports NFC on iOS for Azure AD accounts.][y] | ![Edge supports BLE on iOS for Azure AD accounts.][n] | ![Firefox supports USB on Linux for Azure AD accounts.][n] | ![Firefox supports NFC on iOS for Azure AD accounts.][n] | ![Firefox supports BLE on iOS for Azure AD accounts.][n] | ![Safari supports USB on iOS for Azure AD accounts.][y] | ![Safari supports NFC on iOS for Azure AD accounts.][y] | ![Safari supports BLE on iOS for Azure AD accounts.][n] |
34-
| **Android** | ![Chrome supports USB on Android for Azure AD accounts.][n] | ![Chrome supports NFC on Android for Azure AD accounts.][n] | ![Chrome supports BLE on Android for Azure AD accounts.][n] | ![Edge supports USB on Android for Azure AD accounts.][n] | ![Edge supports NFC on Android for Azure AD accounts.][n] | ![Edge supports BLE on Android for Azure AD accounts.][n] | ![Firefox supports USB on Android for Azure AD accounts.][n] | ![Firefox supports NFC on Android for Azure AD accounts.][n] | ![Firefox supports BLE on Android for Azure AD accounts.][n] | ![Safari supports USB on Android for Azure AD accounts.][n] | ![Safari supports NFC on Android for Azure AD accounts.][n] | ![Safari supports BLE on Android for Azure AD accounts.][n] |
35-
36-
- Key registration is currently not supported with ChromeOS/Chrome Browser.
37-
- For iOS and macOS on Safari browser, PIN requests fail if the PIN isn't already set on the security key.
38-
- Security key PIN for user verification isn't currently supported with Android.
26+
| OS | Chrome | Edge | Firefox | Safari |
27+
|:---:|:------:|:----:|:-------:|:------:|
28+
| **Windows** | ✅ | ✅ | ✅ | N/A |
29+
| **macOS** | ✅ | ✅ | ✅ | ✅ |
30+
| **ChromeOS** | ✅ | N/A | N/A | N/A |
31+
| **Linux** | ✅ | ❌ | ❌ | N/A |
32+
| **iOS** | ✅ | ✅ | ✅ | ✅ |
33+
| **Android** | ❌ | ❌ | ❌ | N/A |
3934

4035
>[!NOTE]
41-
>This is the view for web support. Authentication for native apps in iOS and Android are not available yet.
36+
>This is the view for web support. Authentication for native apps in iOS and Android isn't available yet.
4237
43-
## Unsupported browsers
38+
## Browser support for each platform
4439

45-
The following operating system and browser combinations aren't supported, but future support and testing is being investigated. If you would like to see other operating system and browser support, please leave feedback on our [product feedback site](https://feedback.azure.com/d365community/).
40+
The following tables show which transports are supported for each platform. Supported device types include **USB**, near-field communication (**NFC**), and bluetooth low energy (**BLE**).
4641

47-
| Operating system | Browser |
48-
| ---- | ---- |
49-
| Android | Chrome |
42+
### Windows
43+
44+
| Browser | USB | NFC | BLE |
45+
|---------|------|-----|-----|
46+
| Edge | ✅ | ✅ | ✅ |
47+
| Chrome | ✅ | ✅ | ✅ |
48+
| Firefox | ✅ | ✅ | ✅ |
49+
50+
### macOS
51+
52+
| Browser | USB | NFC<sup>1</sup> | BLE<sup>1</sup> |
53+
|---------|------|-----|-----|
54+
| Edge | &#x2705; | N/A | N/A |
55+
| Chrome | &#x2705; | N/A | N/A |
56+
| Firefox<sup>2</sup> | &#x2705; | N/A | N/A |
57+
| Safari<sup>2</sup> | &#x2705; | N/A | N/A |
58+
59+
<sup>1</sup>NFC and BLE security keys aren't supported on macOS by Apple.
60+
61+
<sup>2</sup>New security key registration doesn't work on these macOS browsers because they don't prompt to set up biometrics or PIN.
62+
63+
### ChromeOS
64+
65+
| Browser<sup>1</sup> | USB | NFC | BLE |
66+
|---------|------|-----|-----|
67+
| Chrome | &#x2705; | &#10060; | &#10060; |
68+
69+
<sup>1</sup>Security key registration isn't supported on ChromeOS or Chrome browser.
70+
71+
### Linux
72+
73+
| Browser | USB | NFC | BLE |
74+
|---------|------|-----|-----|
75+
| Edge | &#10060; | &#10060; | &#10060; |
76+
| Chrome | &#x2705; | &#10060; | &#10060; |
77+
| Firefox | &#10060; | &#10060; | &#10060; |
78+
79+
80+
### iOS
81+
82+
| Browser<sup>1</sup> | Lightning | NFC | BLE<sup>2</sup> |
83+
|---------|------------|-----|-----|
84+
| Edge | &#x2705; | &#x2705; | N/A |
85+
| Chrome | &#x2705; | &#x2705; | N/A |
86+
| Firefox | &#x2705; | &#x2705; | N/A |
87+
| Safari | &#x2705; | &#x2705; | N/A |
88+
89+
<sup>1</sup>New security key registration doesn't work on iOS browsers because they don't prompt to set up biometrics or PIN.
90+
91+
<sup>2</sup>BLE security keys aren't supported on iOS by Apple.
92+
93+
### Android
94+
95+
| Browser<sup>1</sup> | USB | NFC | BLE |
96+
|---------|------|-----|-----|
97+
| Edge | &#10060; | &#10060; | &#10060; |
98+
| Chrome | &#10060; | &#10060; | &#10060; |
99+
| Firefox | &#10060; | &#10060; | &#10060; |
100+
101+
<sup>1</sup>Security key biometrics or PIN for user verficiation isn't currently supported on Android by Google. Azure AD requires user verification for all FIDO2 authentications.
50102

51103
## Minimum browser version
52104

@@ -58,7 +110,7 @@ The following are the minimum browser version requirements.
58110
| Edge | Windows 10 version 1903<sup>1</sup> |
59111
| Firefox | 66 |
60112

61-
<sup>1</sup>All versions of the new Chromium-based Microsoft Edge support Fido2. Support on Microsoft Edge legacy was added in 1903.
113+
<sup>1</sup>All versions of the new Chromium-based Microsoft Edge support FIDO2. Support on Microsoft Edge legacy was added in 1903.
62114

63115
## Next steps
64116
[Enable passwordless security key sign-in](./howto-authentication-passwordless-security-key.md)

articles/active-directory/cloud-infrastructure-entitlement-management/product-reports.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -77,8 +77,8 @@ Permissions Management offers the following reports for management associated wi
7777
- **Permissions Analytics Report**
7878
- **Summary of report**: Provides information about the violation of key security best practices.
7979
- **Applies to**: AWS, Azure, and GCP
80-
- **Report output type**: CSV, PDF
81-
- **Ability to collate report**: Yes
80+
- **Report output type**: XSLX, PDF
81+
- **Ability to collate report**: Yes (XSLX only)
8282
- **Type of report**: **Detailed**
8383
- **Use cases**:
8484
- This report lists the different key findings in the selected auth systems. The key findings include super identities, inactive identities, over provisioned active identities, storage bucket hygiene, and access key age (for AWS only). The report helps administrators to visualize the findings across the organization.

articles/active-directory/conditional-access/TOC.yml

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -68,6 +68,8 @@
6868
items:
6969
- name: Require MFA for administrators
7070
href: howto-conditional-access-policy-admin-mfa.md
71+
- name: Require phishing-resistant MFA for administrators
72+
href: how-to-policy-phish-resistant-admin-mfa.md
7173
- name: Secure security info registration
7274
href: howto-conditional-access-policy-registration.md
7375
- name: Block legacy authentication
@@ -76,6 +78,8 @@
7678
href: howto-policy-guest-mfa.md
7779
- name: Require MFA for all users
7880
href: howto-conditional-access-policy-all-users-mfa.md
81+
- name: Require MFA for Microsoft admin portals
82+
href: how-to-policy-mfa-admin-portals.md
7983
- name: Require MFA for Azure management
8084
href: howto-conditional-access-policy-azure-management.md
8185
- name: Require MFA for risky sign-in

0 commit comments

Comments
 (0)