Skip to content

Commit ab62a4d

Browse files
authored
Merge branch 'master' into two-agriculture-articles
2 parents ce500f3 + c3f87c4 commit ab62a4d

File tree

1,413 files changed

+14494
-8567
lines changed

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

1,413 files changed

+14494
-8567
lines changed

.openpublishing.redirection.json

Lines changed: 63 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -567,6 +567,11 @@
567567
"redirect_url": "/azure/cognitive-services//QnAMaker/Quickstarts/get-answer-from-knowledge-base-using-url-tool",
568568
"redirect_document_id": false
569569
},
570+
{
571+
"source_path": "articles/cognitive-services/LUIS/luis-quickstart-intent-and-sentiment-analysis.md",
572+
"redirect_url": "/azure/cognitive-services/LUIS/tutorial-publish-settings",
573+
"redirect_document_id": false
574+
},
570575
{
571576
"source_path": "articles/cognitive-services/LUIS/luis-how-to-add-example-utterances.md",
572577
"redirect_url": "/azure/cognitive-services/LUIS/luis-how-to-add-entities",
@@ -11466,7 +11471,7 @@
1146611471
"source_path": "articles/event-hubs/event-hubs-create-kafka-enabled.md",
1146711472
"redirect_url": "/azure/event-hubs/event-hubs-create",
1146811473
"redirect_document_id": false
11469-
},
11474+
},
1147011475
{
1147111476
"source_path": "articles/event-hubs/event-hubs-csharp-ephcs-getstarted.md",
1147211477
"redirect_url": "/azure/event-hubs/event-hubs-dotnet-standard-getstarted-send",
@@ -15622,6 +15627,11 @@
1562215627
"redirect_url": "/azure/monitoring-and-diagnostics/insights-advanced-autoscale-virtual-machine-scale-sets",
1562315628
"redirect_document_id": false
1562415629
},
15630+
{
15631+
"source_path": "articles/virtual-machine-scale-sets/virtual-machine-scale-sets-use-low-priority.md",
15632+
"redirect_url": "/azure/virtual-machine-scale-sets/virtual-machine-scale-sets-use-spot",
15633+
"redirect_document_id": true
15634+
},
1562515635
{
1562615636
"source_path": "articles/virtual-machine-scale-sets/virtual-machine-scale-sets-cli-quick-create-cli-nodejs.md",
1562715637
"redirect_url": "/azure/virtual-machine-scale-sets/virtual-machine-scale-sets-create",
@@ -29511,9 +29521,54 @@
2951129521
"redirect_url": "/azure/cognitive-services/speech/concepts",
2951229522
"redirect_document_id": false
2951329523
},
29524+
{
29525+
"source_path": "articles/cognitive-services/Bing-Image-Search/index.yml",
29526+
"redirect_url": "/azure/cognitive-services/Bing-Web-Search",
29527+
"redirect_document_id": false
29528+
},
29529+
{
29530+
"source_path": "articles/cognitive-services/Bing-Autosuggest/index.yml",
29531+
"redirect_url": "/azure/cognitive-services/Bing-Web-Search",
29532+
"redirect_document_id": false
29533+
},
29534+
{
29535+
"source_path": "articles/cognitive-services/Bing-Custom-Search/index.yml",
29536+
"redirect_url": "/azure/cognitive-services/Bing-Web-Search",
29537+
"redirect_document_id": false
29538+
},
29539+
{
29540+
"source_path": "articles/cognitive-services/Bing-Entities-Search/index.yml",
29541+
"redirect_url": "/azure/cognitive-services/Bing-Web-Search",
29542+
"redirect_document_id": false
29543+
},
29544+
{
29545+
"source_path": "articles/cognitive-services/bing-local-business-search/index.yml",
29546+
"redirect_url": "/azure/cognitive-services/Bing-Web-Search",
29547+
"redirect_document_id": false
29548+
},
29549+
{
29550+
"source_path": "articles/cognitive-services/Bing-News-Search/index.yml",
29551+
"redirect_url": "/azure/cognitive-services/Bing-Web-Search",
29552+
"redirect_document_id": false
29553+
},
29554+
{
29555+
"source_path": "articles/cognitive-services/Bing-Spell-Check/index.yml",
29556+
"redirect_url": "/azure/cognitive-services/Bing-Web-Search",
29557+
"redirect_document_id": false
29558+
},
29559+
{
29560+
"source_path": "articles/cognitive-services/Bing-Video-Search/index.yml",
29561+
"redirect_url": "/azure/cognitive-services/Bing-Web-Search",
29562+
"redirect_document_id": false
29563+
},
29564+
{
29565+
"source_path": "articles/cognitive-services/bing-visual-search/index.yml",
29566+
"redirect_url": "/azure/cognitive-services/Bing-Web-Search",
29567+
"redirect_document_id": false
29568+
},
2951429569
{
2951529570
"source_path": "articles/cognitive-services/Bing-Image-Search/search-the-web.md",
29516-
"redirect_url": "/azure/cognitive-services/bing-image-search",
29571+
"redirect_url": "/azure/cognitive-services/Bing-Image-Search/overview",
2951729572
"redirect_document_id": false
2951829573
},
2951929574
{
@@ -29523,7 +29578,7 @@
2952329578
},
2952429579
{
2952529580
"source_path": "articles/cognitive-services/Bing-Web-Search/search-the-web.md",
29526-
"redirect_url": "/azure/cognitive-services/bing-web-search",
29581+
"redirect_url": "/azure/cognitive-services/bing-web-search/overview",
2952729582
"redirect_document_id": false
2952829583
},
2952929584
{
@@ -43851,6 +43906,11 @@
4385143906
"source_path": "articles/service-bus-messaging/migrate-java-apps-wild-fly.md",
4385243907
"redirect_url": "/azure/app-service/containers/configure-language-java#use-service-bus-as-a-message-broker",
4385343908
"redirect_document_id": false
43909+
},
43910+
{
43911+
"source_path": "articles/mysql/howto-redirection.md",
43912+
"redirect_url": "/azure/mysql/concepts-connectivity-architecture",
43913+
"redirect_document_id": false
4385443914
}
4385543915
]
4385643916
}

articles/active-directory/authentication/active-directory-certificate-based-authentication-get-started.md

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -33,14 +33,17 @@ This topic:
3333

3434
To configure certificate-based authentication, the following statements must be true:
3535

36-
- Certificate-based authentication (CBA) is only supported for Federated environments for browser applications or native clients using modern authentication (ADAL). The one exception is Exchange Active Sync (EAS) for Exchange Online (EXO), which can be used for federated and managed accounts.
36+
- Certificate-based authentication (CBA) is only supported for Federated environments for browser applications, native clients using modern authentication (ADAL), or MSAL libraries. The one exception is Exchange Active Sync (EAS) for Exchange Online (EXO), which can be used for federated and managed accounts.
3737
- The root certificate authority and any intermediate certificate authorities must be configured in Azure Active Directory.
3838
- Each certificate authority must have a certificate revocation list (CRL) that can be referenced via an internet-facing URL.
3939
- You must have at least one certificate authority configured in Azure Active Directory. You can find related steps in the [Configure the certificate authorities](#step-2-configure-the-certificate-authorities) section.
4040
- For Exchange ActiveSync clients, the client certificate must have the user’s routable email address in Exchange online in either the Principal Name or the RFC822 Name value of the Subject Alternative Name field. Azure Active Directory maps the RFC822 value to the Proxy Address attribute in the directory.
4141
- Your client device must have access to at least one certificate authority that issues client certificates.
4242
- A client certificate for client authentication must have been issued to your client.
4343

44+
>[!IMPORTANT]
45+
>The maximum size of a CRL for Azure Active Directory to successfully download and cache is 20MB, and the time required to download the CRL must not exceed 10 seconds. If Azure Active Directory can't download a CRL, certificate based authentications using certificates issued by the corresponding CA will fail. Best practices to ensure CRL files are within size constraints are to keep certificate lifetimes to within reasonable limits and to clean up expired certificates.
46+
4447
## Step 1: Select your device platform
4548

4649
As a first step, for the device platform you care about, you need to review the following:

articles/active-directory/authentication/howto-authentication-passwordless-security-key-windows.md

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -6,7 +6,7 @@ services: active-directory
66
ms.service: active-directory
77
ms.subservice: authentication
88
ms.topic: conceptual
9-
ms.date: 11/21/2019
9+
ms.date: 12/02/2019
1010

1111
ms.author: joflore
1212
author: MicrosoftGuyJFlo
@@ -53,7 +53,7 @@ Azure AD joined devices that you will be piloting with must be running Windows 1
5353
Organizations may choose to use one or more of the following methods to enable the use of security keys for Windows sign-in based on their organization's requirements.
5454

5555
- [Enable with Intune](#enable-with-intune)
56-
- [Targeted Intune deployment](#targeted-intune-deployment)
56+
- [Targeted Intune deployment](#targeted-intune-deployment)
5757
- [Enable with a provisioning package](#enable-with-a-provisioning-package)
5858

5959
### Enable with Intune
@@ -64,7 +64,7 @@ Organizations may choose to use one or more of the following methods to enable t
6464

6565
Configuration of security keys for sign-in, is not dependent on configuring Windows Hello for Business.
6666

67-
#### Targeted Intune deployment
67+
### Targeted Intune deployment
6868

6969
To target specific device groups to enable the credential provider, use the following custom settings via Intune.
7070

articles/active-directory/authentication/howto-mfa-nps-extension-rdg.md

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -230,7 +230,7 @@ To ensure there is time to validate users’ credentials, perform two-step verif
230230

231231
### Verify Connection Request Policies
232232

233-
By default, when you configure the RD Gateway to use a central policy store for connection authorization policies, the RD Gateway is configured to forward CAP requests to the NPS server. The NPS server with the Azure MFA extension installed, processes the RADIUS access request. The following steps show you how to verify the default connection request policy.
233+
By default, when you configure the RD Gateway to use a central policy store for connection authorization policies, the RD Gateway is configured to forward CAP requests to the NPS server. The NPS server with the Azure MFA extension installed, processes the RADIUS access request. The following steps show you how to verify the default connection request policy.
234234

235235
1. On the RD Gateway, in the NPS (Local) console, expand **Policies**, and select **Connection Request Policies**.
236236
1. Double-click **TS GATEWAY AUTHORIZATION POLICY**.
@@ -241,6 +241,9 @@ By default, when you configure the RD Gateway to use a central policy store for
241241

242242
1. Click **Cancel**.
243243

244+
>[!NOTE]
245+
> For more information about creating a connection request policy see the article, [Configure connection request policies](https://docs.microsoft.com/windows-server/networking/technologies/nps/nps-crp-configure#add-a-connection-request-policy) documentation for the same.
246+
244247
## Configure NPS on the server where the NPS extension is installed
245248

246249
The NPS server where the NPS extension is installed needs to be able to exchange RADIUS messages with the NPS server on the Remote Desktop Gateway. To enable this message exchange, you need to configure the NPS components on the server where the NPS extension service is installed.

articles/active-directory/authentication/howto-mfa-userstates.md

Lines changed: 7 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -38,11 +38,14 @@ Enabled by Azure AD Identity Protection - This method uses the Azure AD Identity
3838

3939
User accounts in Azure Multi-Factor Authentication have the following three distinct states:
4040

41+
> [!IMPORTANT]
42+
> Enabling Azure MFA through a Conditional Access policy will not change the state of the user. Do not be alarmed users appear disabled. Conditional Access does not change the state. **Organizations should not enable or enforce users if they are utilizing Conditional Access policies.**
43+
4144
| Status | Description | Non-browser apps affected | Browser apps affected | Modern authentication affected |
42-
|:---:|:---:|:---:|:--:|:--:|
43-
| Disabled |The default state for a new user not enrolled in Azure MFA. |No |No |No |
44-
| Enabled |The user has been enrolled in Azure MFA, but has not registered. They receive a prompt to register the next time they sign in. |No. They continue to work until the registration process is completed. | Yes. After the session expires, Azure MFA registration is required.| Yes. After the access token expires, Azure MFA registration is required. |
45-
| Enforced |The user has been enrolled and has completed the registration process for Azure MFA. |Yes. Apps require app passwords. |Yes. Azure MFA is required at login. | Yes. Azure MFA is required at login. |
45+
|:---:| --- |:---:|:--:|:--:|
46+
| Disabled | The default state for a new user not enrolled in Azure MFA. | No | No | No |
47+
| Enabled | The user has been enrolled in Azure MFA, but has not registered. They receive a prompt to register the next time they sign in. | No. They continue to work until the registration process is completed. | Yes. After the session expires, Azure MFA registration is required.| Yes. After the access token expires, Azure MFA registration is required. |
48+
| Enforced | The user has been enrolled and has completed the registration process for Azure MFA. | Yes. Apps require app passwords. | Yes. Azure MFA is required at login. | Yes. Azure MFA is required at login. |
4649

4750
A user's state reflects whether an admin has enrolled them in Azure MFA, and whether they completed the registration process.
4851

Lines changed: 79 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,79 @@
1+
- name: Cloud provisioning
2+
href: index.yml
3+
- name: Overview
4+
items:
5+
- name: What is identity provisioning?
6+
href: what-is-provisioning.md
7+
- name: What is Azure AD Connect cloud provisioning?
8+
href: what-is-cloud-provisioning.md
9+
maintainContext: true
10+
- name: Tutorials
11+
expanded: true
12+
items:
13+
- name: Integrate a single AD forest with a single Azure AD tenant
14+
href: tutorial-single-forest.md
15+
- name: Integrate an existing forest and a new forest with a single Azure AD tenant
16+
href: tutorial-existing-forest.md
17+
- name: Pilot cloud provisioning for an existing synced AD forest
18+
href: tutorial-pilot-aadc-aadccp.md
19+
20+
21+
22+
23+
24+
- name: Concepts
25+
items:
26+
- name: What is password hash sync?
27+
href: /azure/active-directory/hybrid/whatis-phs?context=azure/active-directory/cloud-provisioning/context/cloud-provisioning-context
28+
- name: Understanding the Azure AD schema, attributes, and expressions
29+
href: concept-attributes.md
30+
- name: Writing Expressions for Attribute Mappings in Azure Active Directory
31+
href: reference-expressions.md
32+
33+
34+
35+
- name: How-to guides
36+
items:
37+
- name: Installation and upgrade
38+
items:
39+
- name: Installation Prerequisites
40+
href: how-to-prerequisites.md
41+
- name: Install the Azure AD Connect cloud provisioning agent
42+
href: how-to-install.md
43+
- name: Cloud provisioning configuration
44+
href: how-to-configure.md
45+
- name: Plan and design
46+
items:
47+
- name: Topologies and scenarios for Azure AD Connect cloud provisioning
48+
href: plan-cloud-provisioning-topologies.md
49+
50+
51+
- name: Manage
52+
items:
53+
- name: Agent automatic upgrade
54+
href: how-to-automatic-upgrade.md
55+
- name: Develop
56+
items:
57+
- name: Transformations
58+
href: how-to-transformation.md
59+
- name: Azure AD synchronization API
60+
href: https://docs.microsoft.com/graph/api/resources/synchronization-overview
61+
62+
- name: Troubleshoot
63+
items:
64+
- name: Troubleshoot cloud provisioning
65+
href: how-to-troubleshoot.md
66+
- name: Duplicate attributes
67+
href: https://docs.microsoft.com/office365/troubleshoot/administration/duplicate-attributes-prevent-dirsync
68+
69+
- name: Reference
70+
items:
71+
- name: Azure AD Connect cloud provisioning agent version history
72+
href: /azure/active-directory/manage-apps/provisioning-agent-release-version-history?context=azure/active-directory/cloud-provisioning/context/cp-context
73+
- name: Azure AD Connect cloud provisioning FAQ
74+
href: reference-cloud-provisioning-faq.md
75+
- name: Attributes that are synchronized
76+
href: /azure/active-directory/hybrid/reference-connect-sync-attributes-synchronized?context=azure/active-directory/cloud-provisioning/context/cp-context
77+
- name: Basic Active Directory and Azure AD environment
78+
href: tutorial-basic-ad-azure.md
79+
Lines changed: 24 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,24 @@
1+
- name: Azure
2+
tocHref: /azure/
3+
topicHref: /azure/index
4+
items:
5+
- name: Active Directory
6+
tocHref: /azure/active-directory/manage-apps/
7+
topicHref: /azure/active-directory/index
8+
items:
9+
- name: Cloud provisioning
10+
tocHref: /azure/active-directory/manage-apps/
11+
topicHref: /azure/active-directory/cloud-provisioning/index
12+
13+
- name: Azure
14+
tocHref: /azure/
15+
topicHref: /azure/index
16+
items:
17+
- name: Active Directory
18+
tocHref: /azure/active-directory/hybrid/
19+
topicHref: /azure/active-directory/index
20+
items:
21+
- name: Cloud provisioning
22+
tocHref: /azure/active-directory/hybrid/
23+
topicHref: /azure/active-directory/cloud-provisioning/index
24+

0 commit comments

Comments
 (0)