Skip to content

Commit aa81c17

Browse files
Merge branch 'main' of https://github.com/MicrosoftDocs/azure-docs-pr into pauljewell-get-endpoint-srp
2 parents 1a2f816 + 3df9013 commit aa81c17

25 files changed

+575
-410
lines changed

articles/active-directory/privileged-identity-management/groups-activate-roles.md

Lines changed: 6 additions & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -10,7 +10,7 @@ ms.topic: how-to
1010
ms.tgt_pltfrm: na
1111
ms.workload: identity
1212
ms.subservice: pim
13-
ms.date: 01/12/2023
13+
ms.date: 3/15/2023
1414
ms.author: amsliu
1515
ms.reviewer: ilyal
1616
ms.custom: pim
@@ -23,6 +23,11 @@ In Azure Active Directory (Azure AD), part of Microsoft Entra, you can use Privi
2323

2424
This article is for eligible members or owners who want to activate their group membership or ownership in PIM.
2525

26+
>[!IMPORTANT]
27+
>When a group membership or ownership is activated, Azure AD PIM temporarily adds an active assignment. Azure AD PIM creates an active assignment (adds user as member or owner of the group) within seconds. When deactivation (manual or through activation time expiration) happens, Azure AD PIM removes user’s group membership or ownership within seconds as well.
28+
>
29+
>Application may provide access to users based on their group membership. In some situations, application access may not immediately reflect the fact that user was added to the group or removed from it. If application previously cached the fact that user is not member of the group – when user tries to access application again, access may not be provided. Similarly, if application previously cached the fact that user is member of the group – when group membership is deactivated, user may still get access. Specific situation depends on the application’s architecture. For some applications, signing out and signing back in may help to get access added or removed.
30+
2631
## Activate a role
2732

2833
When you need to take on a group membership or ownership, you can request activation by using the **My roles** navigation option in PIM.
@@ -76,15 +81,6 @@ You can view the status of your pending requests to activate. It is specifically
7681

7782
When you select **Cancel**, the request will be canceled. To activate the role again, you will have to submit a new request for activation.
7883

79-
## Troubleshoot
80-
81-
### Permissions are not granted after activating a role
82-
83-
When you activate a role in PIM, the activation may not instantly propagate to all portals that require the privileged role. Sometimes, even if the change is propagated, web caching in a portal may result in the change not taking effect immediately. If your activation is delayed, here is what you should do.
84-
85-
1. Sign out of the Azure portal and then sign back in.
86-
1. In PIM, verify that you are listed as the member of the role.
87-
8884
## Next steps
8985

9086
- [Approve activation requests for group members and owners (preview)](groups-approval-workflow.md)

articles/active-directory/privileged-identity-management/pim-how-to-activate-role.md

Lines changed: 8 additions & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -6,14 +6,13 @@ documentationcenter: ''
66
author: amsliu
77
manager: amycolannino
88
editor: ''
9-
109
ms.service: active-directory
1110
ms.topic: how-to
1211
ms.workload: identity
1312
ms.subservice: pim
14-
ms.date: 02/02/2022
13+
ms.date: 3/15/2023
1514
ms.author: amsliu
16-
ms.reviewer: shaunliu
15+
ms.reviewer: ilyal
1716
ms.custom: pim
1817
ms.collection: M365-identity-device-management
1918
---
@@ -25,6 +24,11 @@ If you have been made *eligible* for an administrative role, then you must *acti
2524

2625
This article is for administrators who need to activate their Azure AD role in Privileged Identity Management.
2726

27+
>[!IMPORTANT]
28+
>When a role is activated, Azure AD PIM temporarily adds active assignment for the role. Azure AD PIM creates active assignment (assigns user to a role) within seconds. When deactivation (manual or through activation time expiration) happens, Azure AD PIM removes the active assignment within seconds as well.
29+
>
30+
>Application may provide access based on the role the user has. In some situations, application access may not immediately reflect the fact that user got role assigned or removed. If application previously cached the fact that user does not have a role – when user tries to access application again, access may not be provided. Similarly, if application previously cached the fact that user has a role – when role is deactivated, user may still get access. Specific situation depends on the application’s architecture. For some applications, signing out and signing back in may help get access added or removed.
31+
2832
## Activate a role
2933

3034
When you need to assume an Azure AD role, you can request activation by opening **My roles** in Privileged Identity Management.
@@ -230,13 +234,7 @@ If you don't require activation of a role that requires approval, you can cancel
230234

231235
## Deactivate a role assignment
232236

233-
When a role assignment is activated, you'll see a **Deactivate** option in the PIM portal for the role assignment. When you select **Deactivate**, there's a short time lag before the role is deactivated. Also, you can't deactivate a role assignment within five minutes after activation.
234-
235-
## Troubleshoot portal delay
236-
237-
### Permissions aren't granted after activating a role
238-
239-
When you activate a role in Privileged Identity Management, the activation might not instantly propagate to all portals that require the privileged role. Sometimes, even if the change is propagated, web caching in a portal may cause a delay before the change takes effect. If your activation is delayed, sign out of the portal you're trying to perform the action and then sign back in. In the Azure portal, PIM signs you out and back in automatically.
237+
When a role assignment is activated, you'll see a **Deactivate** option in the PIM portal for the role assignment. Also, you can't deactivate a role assignment within five minutes after activation.
240238

241239
## Next steps
242240

articles/active-directory/privileged-identity-management/pim-resource-roles-activate-your-roles.md

Lines changed: 7 additions & 11 deletions
Original file line numberDiff line numberDiff line change
@@ -10,7 +10,7 @@ ms.topic: how-to
1010
ms.tgt_pltfrm: na
1111
ms.workload: identity
1212
ms.subservice: pim
13-
ms.date: 3/1/2023
13+
ms.date: 3/15/2023
1414
ms.author: amsliu
1515
ms.reviewer: rianakarim
1616
ms.custom: pim
@@ -26,6 +26,11 @@ This article is for members who need to activate their Azure resource role in Pr
2626
>[!NOTE]
2727
>As of March 2023, you may now activate your assignments and view your access directly from blades outside of PIM in the Azure portal. Read more [here](pim-resource-roles-activate-your-roles.md#activate-with-azure-portal).
2828
29+
>[!IMPORTANT]
30+
>When a role is activated, Azure AD PIM temporarily adds active assignment for the role. Azure AD PIM creates active assignment (assigns user to a role) within seconds. When deactivation (manual or through activation time expiration) happens, Azure AD PIM removes the active assignment within seconds as well.
31+
>
32+
>Application may provide access based on the role the user has. In some situations, application access may not immediately reflect the fact that user got role assigned or removed. If application previously cached the fact that user does not have a role – when user tries to access application again, access may not be provided. Similarly, if application previously cached the fact that user has a role – when role is deactivated, user may still get access. Specific situation depends on the application’s architecture. For some applications, signing out and signing back in may help get access added or removed.
33+
2934
## Activate a role
3035

3136
When you need to take on an Azure resource role, you can request activation by using the **My roles** navigation option in Privileged Identity Management.
@@ -215,7 +220,7 @@ If you do not require activation of a role that requires approval, you can cance
215220

216221
## Deactivate a role assignment
217222

218-
When a role assignment is activated, you'll see a **Deactivate** option in the PIM portal for the role assignment. When you select **Deactivate**, there's a short time lag before the role is deactivated. Also, you can't deactivate a role assignment within five minutes after activation.
223+
When a role assignment is activated, you'll see a **Deactivate** option in the PIM portal for the role assignment. Also, you can't deactivate a role assignment within five minutes after activation.
219224

220225
## Activate with Azure portal
221226

@@ -233,15 +238,6 @@ In Access control (IAM) for a resource, you can now select “View my access”
233238

234239
By integrating PIM capabilities into different Azure portal blades, this new feature allows you to gain temporary access to view or edit subscriptions and resources more easily.
235240

236-
## Troubleshoot
237-
238-
### Permissions are not granted after activating a role
239-
240-
When you activate a role in Privileged Identity Management, the activation may not instantly propagate to all portals that require the privileged role. Sometimes, even if the change is propagated, web caching in a portal may result in the change not taking effect immediately. If your activation is delayed, here is what you should do.
241-
242-
1. Sign out of the Azure portal and then sign back in.
243-
1. In Privileged Identity Management, verify that you are listed as the member of the role.
244-
245241
## Next steps
246242

247243
- [Extend or renew Azure resource roles in Privileged Identity Management](pim-resource-roles-renew-extend.md)

articles/azure-monitor/app/convert-classic-resource.md

Lines changed: 4 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -15,12 +15,13 @@ Workspace-based resources:
1515
> [!div class="checklist"]
1616
> - Support full integration between Application Insights and [Log Analytics](../logs/log-analytics-overview.md).
1717
> - Send Application Insights telemetry to a common [Log Analytics workspace](../logs/log-analytics-workspace-overview.md).
18-
> - Allow you to access [the latest features of Azure Monitor](#new-capabilities) while keeping application, infrastructure, and platform logs in a consolidated location.
18+
> - - Allow you to access [the latest features of Azure Monitor](#new-capabilities) while keeping application, infrastructure, and platform logs in a consolidated location.
1919
> - Enable common [Azure role-based access control](../../role-based-access-control/overview.md) across your resources.
2020
> - Eliminate the need for cross-app/workspace queries.
2121
> - Are available in all commercial regions and [Azure US Government](../../azure-government/index.yml).
2222
> - Don't require changing instrumentation keys after migration from a classic resource.
2323
24+
2425
> [!IMPORTANT]
2526
> * On February 29, 2024, continuous export will be deprecated as part of the classic Application Insights deprecation.
2627
> * When you [migrate to a workspace-based Application Insights resource](convert-classic-resource.md), you must use [diagnostic settings](export-telemetry.md#diagnostic-settings-based-export) for exporting telemetry. All [workspace-based Application Insights resources](./create-workspace-resource.md) must use [diagnostic settings](./create-workspace-resource.md#export-telemetry).
@@ -782,7 +783,7 @@ Legacy table: traces
782783
|message|string|Message|string|
783784
|operation_Id|string|OperationId|string|
784785
|operation_Name|string|OperationName|string|
785-
|operation_ParentId|string|OperationParentId|string|
786+
|operation_ParentId|string|ParentId|string|
786787
|operation_SyntheticSource|string|OperationSyntheticSource|string|
787788
|sdkVersion|string|SDKVersion|string|
788789
|session_Id|string|SessionId|string|
@@ -796,3 +797,4 @@ Legacy table: traces
796797

797798
* [Explore metrics](../essentials/metrics-charts.md)
798799
* [Write Log Analytics queries](../logs/log-query-overview.md)
800+

articles/azure-resource-manager/bicep/decompile.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -13,7 +13,7 @@ This article describes how to decompile Azure Resource Manager templates (ARM te
1313
> [!NOTE]
1414
> From Visual Studio Code, you can directly create resource declarations by importing from existing resources. For more information, see [Bicep commands](./visual-studio-code.md#bicep-commands).
1515
>
16-
> Visual Studio Code enables you to paste JSON as Bicep. It automatically runs the decompile command. For more information, see [Paste JSON as Bicep](./visual-studio-code.md#paste-as-bicep-preview).
16+
> Visual Studio Code enables you to paste JSON as Bicep. It automatically runs the decompile command. For more information, see [Paste JSON as Bicep](./visual-studio-code.md#paste-as-bicep).
1717
1818
Decompiling an ARM template helps you get started with Bicep development. If you have a library of ARM templates and want to use Bicep for future development, you can decompile them to Bicep. However, the Bicep file might need revisions to implement best practices for Bicep.
1919

articles/azure-resource-manager/bicep/migrate.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -33,7 +33,7 @@ The convert phase consists of two steps, which you complete in sequence:
3333
> [!NOTE]
3434
> You can import a resource by opening the Visual Studio Code command palette. Use <kbd>Ctrl+Shift+P</kbd> on Windows and Linux and <kbd>⌘+Shift+P</kbd> on macOS.
3535
>
36-
> Visual Studio Code enables you to paste JSON as Bicep. For more information, see [Paste JSON as Bicep](./visual-studio-code.md#paste-as-bicep-preview).
36+
> Visual Studio Code enables you to paste JSON as Bicep. For more information, see [Paste JSON as Bicep](./visual-studio-code.md#paste-as-bicep).
3737
3838
## Phase 2: Migrate
3939

articles/azure-resource-manager/bicep/visual-studio-code.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -124,7 +124,7 @@ From Visual Studio Code, you can easily open the template reference for the reso
124124

125125
:::image type="content" source="./media/visual-studio-code/visual-studio-code-bicep-view-type-document.png" alt-text="Screenshot of Visual Studio Code Bicep view type document.":::
126126

127-
## Paste as Bicep (Preview)
127+
## Paste as Bicep
128128

129129
You can paste a JSON snippet from an ARM template to Bicep file. Visual Studio Code automatically decompiles the JSON to Bicep. This feature is only available with the Bicep extension version 0.14.0 or newer.
130130

0 commit comments

Comments
 (0)