You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/active-directory/cloud-infrastructure-entitlement-management/all-reports.md
+2-2Lines changed: 2 additions & 2 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -8,13 +8,13 @@ ms.service: active-directory
8
8
ms.subservice: ciem
9
9
ms.workload: identity
10
10
ms.topic: overview
11
-
ms.date: 02/23/2022
11
+
ms.date: 06/13/2023
12
12
ms.author: jfields
13
13
---
14
14
15
15
# View a list and description of system reports
16
16
17
-
Permissions Management has various types of system reports that capture specific sets of data. These reports allow management, auditors, and administrators to:
17
+
Microsoft Entra Permissions Management has various types of system reports that capture specific sets of data. These reports allow management, auditors, and administrators to:
Copy file name to clipboardExpand all lines: articles/active-directory/cloud-infrastructure-entitlement-management/faqs.md
+19-24Lines changed: 19 additions & 24 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -1,39 +1,39 @@
1
1
---
2
-
title: Frequently asked questions (FAQs) about Permissions Management
3
-
description: Frequently asked questions (FAQs) about Permissions Management.
2
+
title: Frequently asked questions (FAQs) about Microsoft Entra Permissions Management
3
+
description: Frequently asked questions (FAQs) about Microsoft Permissions Management.
4
4
services: active-directory
5
5
author: jenniferf-skc
6
6
manager: amycolannino
7
7
ms.service: active-directory
8
8
ms.subservice: ciem
9
9
ms.workload: identity
10
10
ms.topic: faq
11
-
ms.date: 01/25/2023
11
+
ms.date: 06/16/2023
12
12
ms.author: jfields
13
13
---
14
14
15
15
# Frequently asked questions (FAQs)
16
16
17
-
This article answers frequently asked questions (FAQs) about Permissions Management.
17
+
This article answers frequently asked questions (FAQs) about Microsoft Entra Permissions Management.
18
18
19
-
## What's Permissions Management?
19
+
## What's Microsoft Entra Permissions Management?
20
20
21
-
Permissions Management is a cloud infrastructure entitlement management (CIEM) solution that provides comprehensive visibility into permissions assigned to all identities. For example, over-privileged workload and user identities, actions, and resources across multicloud infrastructures in Microsoft Azure, Amazon Web Services (AWS), and Google Cloud Platform (GCP). Permissions Management detects, automatically right-sizes, and continuously monitors unused and excessive permissions. It deepens the Zero Trust security strategy by augmenting the least privilege access principle.
21
+
Microsoft Entra Permissions Management (Permissions Management) is a cloud infrastructure entitlement management (CIEM) solution that provides comprehensive visibility into permissions assigned to all identities. For example, over-privileged workload and user identities, actions, and resources across multicloud infrastructures in Microsoft Azure, Amazon Web Services (AWS), and Google Cloud Platform (GCP). Permissions Management detects, automatically right-sizes, and continuously monitors unused and excessive permissions. It deepens the Zero Trust security strategy by augmenting the least privilege access principle.
22
22
23
23
24
24
## What are the prerequisites to use Permissions Management?
25
25
26
26
Permissions Management supports data collection from AWS, GCP, and/or Microsoft Azure. For data collection and analysis, customers are required to have an Azure Active Directory (Azure AD) account to use Permissions Management.
27
27
28
-
## Can a customer use Permissions Management if they have other identities with access to their IaaS platform that aren't yet in Azure AD (for example, if part of their business has Okta or AWS Identity & Access Management (IAM))?
28
+
## Can a customer use Permissions Management if they have other identities with access to their IaaS platform that aren't yet in Azure AD?
29
29
30
-
Yes, a customer can detect, mitigate, and monitor the risk of 'backdoor' accounts that are local to AWS IAM, GCP, or from other identity providers such as Okta or AWS IAM.
30
+
Yes, a customer can detect, mitigate, and monitor the risk for AWS IAM or GCP accounts, or from other identity providers such as Okta or AWS IAM.
31
31
32
32
## Where can customers access Permissions Management?
33
33
34
34
Customers can access the Permissions Management interface from the [Microsoft Entra admin center](https://entra.microsoft.com/) .
35
35
36
-
## Can non-cloud customers use Permissions Management on-premises?
36
+
## Can noncloud customers use Permissions Management on-premises?
37
37
38
38
No, Permissions Management is a hosted cloud offering.
39
39
@@ -47,9 +47,9 @@ Yes, Permissions Management is currently for tenants hosted in the European Unio
47
47
48
48
## If I'm already using Azure AD Privileged Identity Management (PIM) for Azure, what value does Permissions Management provide?
49
49
50
-
Permissions Management complements Azure AD PIM. Azure AD PIM provides just-in-time access for admin roles in Azure (as well as Microsoft Online Services and apps that use groups), while Permissions Management allows multicloud discovery, remediation, and monitoring of privileged access across Azure, AWS, and GCP.
50
+
Permissions Management complements Azure AD PIM. Azure AD PIM provides just-in-time access for admin roles in Azure and Microsoft Online Services and apps that use groups. Permissions Management allows multicloud discovery, remediation, and monitoring of privileged access across Azure, AWS, and GCP.
51
51
52
-
## What public cloud infrastructures are supported by Permissions Management?
52
+
## What public cloud infrastructures does Permissions Management support?
53
53
54
54
Permissions Management currently supports the three major public clouds: Amazon Web Services (AWS), Google Cloud Platform (GCP), and Microsoft Azure.
55
55
@@ -71,11 +71,11 @@ No, Permissions Management is currently not available in sovereign Clouds.
71
71
72
72
## How does Permissions Management collect insights about permissions usage?
73
73
74
-
Permissions Management has a data collector that collects access permissions assigned to various identities, activity logs, and resources metadata. This gathers full visibility into permissions granted to all identities to access the resources and details on usage of granted permissions.
74
+
Permissions Management has a data collector that collects access permissions that are assigned to various identities, activity logs, and resources metadata. The data collector provides full visibility into permissions granted to all identities to access the resources and details on usage of granted permissions.
75
75
76
76
## How does Permissions Management evaluate cloud permissions risk?
77
77
78
-
Permissions Management offers granular visibility into all identities and their permissions granted versus used, across cloud infrastructures to uncover any action performed by any identity on any resource. This isn't limited to just user identities, but also workload identities such as virtual machines, access keys, containers, and scripts. The dashboard gives an overview of permission profile to locate the riskiest identities and resources.
78
+
Permissions Management offers granular visibility into all identities and their permissions granted versus used, across cloud infrastructures to uncover any action performed by any identity on any resource. The visibility isn't limited to just user identities, but also workload identities such as virtual machines, access keys, containers, and scripts. The dashboard gives an overview of permission profile to locate the riskiest identities and resources.
79
79
80
80
## What is the Permissions Creep Index?
81
81
@@ -95,7 +95,7 @@ Just-in-time (JIT) access is a method used to enforce the principle of least pri
95
95
96
96
## How can customers monitor permissions usage with Permissions Management?
97
97
98
-
Customers only need to track the evolution of their Permission Creep Index to monitor permissions usage. They can do this in the "Analytics" tab in their Permissions Management dashboard where they can see how the PCI of each identity or resource is evolving over time.
98
+
Customers only need to track the evolution of their Permission Creep Index (PCI) to monitor permissions usage. Customers can monitor PCI in the **Analytics** tab from their Permissions Management dashboard.
99
99
100
100
## Can customers generate permissions usage reports?
101
101
@@ -140,7 +140,7 @@ We also have the ability to remove, export or modify specific data should the Gl
140
140
141
141
## Do I require a license to use Entra Permissions Management?
142
142
143
-
Yes, as of July 1st, 2022, new customers must acquire a free 45-day trial license or a paid license to use the service. You can enable a trial here: [https://aka.ms/TryPermissionsManagement](https://aka.ms/TryPermissionsManagement) or you can directly purchase resource-based licenses here: [https://aka.ms/BuyPermissionsManagement](https://aka.ms/BuyPermissionsManagement)
143
+
Yes, as of July 1, 2022, new customers must acquire a free 45-day trial license or a paid license to use the service. You can enable a trial here: [https://aka.ms/TryPermissionsManagement](https://aka.ms/TryPermissionsManagement) or you can directly purchase resource-based licenses here: [https://aka.ms/BuyPermissionsManagement](https://aka.ms/BuyPermissionsManagement)
144
144
145
145
## How is Permissions Management priced?
146
146
@@ -152,13 +152,7 @@ Although Permissions Management supports all resources, Microsoft only requires
152
152
153
153
## How do I figure out how many resources I have?
154
154
155
-
To find out how many resources you have across your multicloud infrastructure, select Settings (gear icon) and view the Billable Resources tab in Permissions Management.
156
-
157
-
## What do I do if I’m using Public Preview version of Entra Permissions Management?
158
-
159
-
If you are using the Public Preview version of Entra Permissions Management, your current deployment(s) will continue to work through October 1st.
160
-
161
-
After October 1st you will need to move over to use the newly released version of the service and enable a 45-day trial or purchase licenses to continue using the service.
155
+
To find out how many resources you have across your multicloud infrastructure, select Settings (gear icon) and view the Billable Resources tab in Permissions Management.
162
156
163
157
## What do I do if I’m using the legacy version of the CloudKnox service?
164
158
@@ -178,13 +172,14 @@ Where xx-XX is one of the following available language parameters: 'cs-CZ', 'de-
-[Permissions Management web page](https://microsoft.com/security/business/identity-access-management/permissions-management)
183
177
- For more information about Microsoft's privacy and security terms, see [Commercial Licensing Terms](https://www.microsoft.com/licensing/terms/product/ForallOnlineServices/all).
184
178
- For more information about Microsoft's data processing and security terms when you subscribe to a product, see [Microsoft Products and Services Data Protection Addendum (DPA)](https://www.microsoft.com/licensing/docs/view/Microsoft-Products-and-Services-Data-Protection-Addendum-DPA).
185
179
- For more information, see [Azure Data Subject Requests for the GDPR and CCPA](/compliance/regulatory/gdpr-dsr-azure).
186
180
187
181
## Next steps
188
182
189
-
- For an overview of Permissions Management, see [What's Permissions Management?](overview.md).
183
+
- For an overview of Permissions Management, see [What's Microsoft Entra Permissions Management?](overview.md).
184
+
- Deepen your learning with the [Introduction to Microsoft Entra Permissions Management](https://go.microsoft.com/fwlink/?linkid=2240016) learn module.
190
185
- For information on how to onboard Permissions Management in your organization, see [Enable Permissions Management in your organization](onboard-enable-tenant.md).
Copy file name to clipboardExpand all lines: articles/active-directory/cloud-infrastructure-entitlement-management/how-to-add-remove-role-task.md
+4-6Lines changed: 4 additions & 6 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -8,7 +8,7 @@ ms.service: active-directory
8
8
ms.subservice: ciem
9
9
ms.workload: identity
10
10
ms.topic: how-to
11
-
ms.date: 02/23/2022
11
+
ms.date: 06/16/2023
12
12
ms.author: jfields
13
13
---
14
14
@@ -103,11 +103,9 @@ This article describes how you can add and remove roles and tasks for Microsoft
103
103
104
104
105
105
- For information on how to view existing roles/policies, requests, and permissions, see [View roles/policies, requests, and permission in the Remediation dashboard](ui-remediation.md).
106
+
- To view information about roles/policies, see [View information about roles/policies](how-to-view-role-policy.md).
106
107
- For information on how to create a role/policy, see [Create a role/policy](how-to-create-role-policy.md).
107
108
- For information on how to clone a role/policy, see [Clone a role/policy](how-to-clone-role-policy.md).
108
109
- For information on how to delete a role/policy, see [Delete a role/policy](how-to-delete-role-policy.md).
109
-
- For information on how to modify a role/policy, see Modify a role/policy](how-to-modify-role-policy.md).
110
-
- To view information about roles/policies, see [View information about roles/policies](how-to-view-role-policy.md).
111
-
- For information on how to attach and detach permissions for Amazon Web Services (AWS) identities, see [Attach and detach policies for AWS identities](how-to-attach-detach-permissions.md).
112
-
- For information on how to revoke high-risk and unused tasks or assign read-only status for Microsoft Azure and Google Cloud Platform (GCP) identities, see [Revoke high-risk and unused tasks or assign read-only status for Azure and GCP identities](how-to-revoke-task-readonly-status.md)
113
-
For information on how to create or approve a request for permissions, see [Create or approve a request for permissions](how-to-create-approve-privilege-request.md).
110
+
- For information on how to modify a role/policy, see [Modify a role/policy](how-to-modify-role-policy.md).
111
+
- For information on how to attach and detach permissions for Amazon Web Services (AWS) identities, see [Attach and detach policies for AWS identities](how-to-attach-detach-permissions.md).
Copy file name to clipboardExpand all lines: articles/active-directory/cloud-infrastructure-entitlement-management/how-to-attach-detach-permissions.md
+9-9Lines changed: 9 additions & 9 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -1,5 +1,5 @@
1
1
---
2
-
title: Attach and detach permissions for users, roles, and groups for Amazon Web Services (AWS) identities in the Remediation dashboard in Permissions Management
2
+
title: Attach and detach permissions for users, roles, and groups for Amazon Web Services (AWS) identities in the Remediation dashboard
3
3
description: How to attach and detach permissions for users, roles, and groups for Amazon Web Services (AWS) identities in the Remediation dashboard in Permissions Management.
4
4
services: active-directory
5
5
author: jenniferf-skc
@@ -8,7 +8,7 @@ ms.service: active-directory
8
8
ms.subservice: ciem
9
9
ms.workload: identity
10
10
ms.topic: how-to
11
-
ms.date: 02/23/2022
11
+
ms.date: 06/16/2023
12
12
ms.author: jfields
13
13
---
14
14
@@ -68,11 +68,11 @@ This article describes how you can attach and detach permissions for users, role
68
68
## Next steps
69
69
70
70
71
-
-For information on how to view existing roles/policies, requests, and permissions, see [View roles/policies, requests, and permission in the Remediation dashboard](ui-remediation.md).
72
-
-For information on how to create a role/policy, see [Create a role/policy](how-to-create-role-policy.md).
73
-
-For information on how to clone a role/policy, see [Clone a role/policy](how-to-clone-role-policy.md).
74
-
-For information on how to delete a role/policy, see [Delete a role/policy](how-to-delete-role-policy.md).
75
-
-For information on how to modify a role/policy, see Modify a role/policy](how-to-modify-role-policy.md).
71
+
-To view existing roles/policies, requests, and permissions, see [View roles/policies, requests, and permission in the Remediation dashboard](ui-remediation.md).
72
+
-To create a role/policy, see [Create a role/policy](how-to-create-role-policy.md).
73
+
-To clone a role/policy, see [Clone a role/policy](how-to-clone-role-policy.md).
74
+
-To delete a role/policy, see [Delete a role/policy](how-to-delete-role-policy.md).
75
+
-To modify a role/policy, see [Modify a role/policy](how-to-modify-role-policy.md).
76
76
- To view information about roles/policies, see [View information about roles/policies](how-to-view-role-policy.md).
77
-
-For information on how to revoke high-risk and unused tasks or assign read-only status for Microsoft Azure and Google Cloud Platform (GCP) identities, see [Revoke high-risk and unused tasks or assign read-only status for Azure and GCP identities](how-to-revoke-task-readonly-status.md)
78
-
For information on how to create or approve a request for permissions, see [Create or approve a request for permissions](how-to-create-approve-privilege-request.md).
77
+
-To revoke high-risk and unused tasks or assign read-only status for Microsoft Azure and Google Cloud Platform (GCP) identities, see [Revoke high-risk and unused tasks or assign read-only status for Azure and GCP identities](how-to-revoke-task-readonly-status.md)
78
+
To create or approve a request for permissions, see [Create or approve a request for permissions](how-to-create-approve-privilege-request.md).
0 commit comments