Skip to content

Commit b225552

Browse files
committed
Merge branch '133002-zone-pivot-logic-app' of https://github.com/laujan/azure-docs-pr into 133002-zone-pivot-logic-app
2 parents 1d87d7e + 406455a commit b225552

File tree

1,303 files changed

+23211
-17879
lines changed

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

1,303 files changed

+23211
-17879
lines changed

.openpublishing.redirection.active-directory.json

Lines changed: 35 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -255,6 +255,41 @@
255255
"redirect_url": "/azure/active-directory/workload-identities/workload-identity-federation-create-trust",
256256
"redirect_document_id": true
257257
},
258+
{
259+
"source_path_from_root": "/articles/active-directory/fundamentals/concept-fundamentals-security-defaults.md",
260+
"redirect_url": "/azure/active-directory/fundamentals/security-defaults",
261+
"redirect_document_id": true
262+
},
263+
{
264+
"source_path_from_root": "/articles/active-directory/devices/hybrid-azuread-join-control.md",
265+
"redirect_url": "/azure/active-directory/devices/hybrid-join-control",
266+
"redirect_document_id": true
267+
},
268+
{
269+
"source_path_from_root": "/articles/active-directory/devices/hybrid-azuread-join-manual.md",
270+
"redirect_url": "/azure/active-directory/devices/hybrid-join-manual",
271+
"redirect_document_id": true
272+
},
273+
{
274+
"source_path_from_root": "/articles/active-directory/devices/hybrid-azuread-join-plan.md",
275+
"redirect_url": "/azure/active-directory/devices/hybrid-join-plan",
276+
"redirect_document_id": true
277+
},
278+
{
279+
"source_path_from_root": "/articles/active-directory/devices/device-management-azure-portal.md",
280+
"redirect_url": "/azure/active-directory/devices/manage-device-identities",
281+
"redirect_document_id": true
282+
},
283+
{
284+
"source_path_from_root": "/articles/active-directory/devices/concept-azure-ad-register.md",
285+
"redirect_url": "/azure/active-directory/devices/concept-device-registration",
286+
"redirect_document_id": true
287+
},
288+
{
289+
"source_path_from_root": "/articles/active-directory/devices/concept-azure-ad-join.md",
290+
"redirect_url": "/azure/active-directory/devices/concept-directory-join",
291+
"redirect_document_id": true
292+
},
258293
{
259294
"source_path_from_root": "/articles/active-directory/fundamentals/10-secure-local-guest.md",
260295
"redirect_url": "/azure/active-directory/architecture/10-secure-local-guest",

.openpublishing.redirection.defender-for-cloud.json

Lines changed: 6 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -413,7 +413,7 @@
413413
{
414414
"source_path_from_root": "/articles/security-center/defender-for-dns-introduction.md",
415415
"redirect_url": "/azure/defender-for-cloud/defender-for-dns-introduction",
416-
"redirect_document_id": true
416+
"redirect_document_id": false
417417
},
418418
{
419419
"source_path_from_root": "/articles/security-center/defender-for-key-vault-introduction.md",
@@ -840,6 +840,11 @@
840840
"redirect_url": "/azure/defender-for-cloud/enable-agentless-scanning-vms",
841841
"redirect_document_id": true
842842
},
843+
{
844+
"source_path_from_root": "/articles/defender-for-cloud/tutorial-enable-dns-plan.md",
845+
"redirect_url": "/azure/defender-for-cloud/defender-for-dns-introduction",
846+
"redirect_document_id": true
847+
},
843848
{
844849
"source_path_from_root": "/articles/defender-for-cloud/defender-for-storage-exclude.md",
845850
"redirect_url": "/azure/defender-for-cloud/defender-for-storage-classic-enable#exclude-a-storage-account-from-a-protected-subscription-in-the-per-transaction-plan",

.openpublishing.redirection.json

Lines changed: 5 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -9093,6 +9093,11 @@
90939093
"redirect_url": "/azure/vpn-gateway/point-to-site-vpn-client-cert-windows",
90949094
"redirect_document_id": false
90959095
},
9096+
{
9097+
"source_path_from_root": "/articles/vpn-gateway/vpn-gateway-forced-tunneling-rm.md",
9098+
"redirect_url": "/azure/vpn-gateway/about-site-to-site-tunneling",
9099+
"redirect_document_id": false
9100+
},
90969101
{
90979102
"source_path_from_root": "/articles/azure-vmware/public-ip-usage.md",
90989103
"redirect_url": "/azure/azure-vmware/enable-public-ip-nsx-edge",
@@ -23853,11 +23858,6 @@
2385323858
"redirect_url": "/azure/sentinel/data-connectors-reference",
2385423859
"redirect_document_id": false
2385523860
},
23856-
{
23857-
"source_path_from_root": "/articles/sentinel/data-connectors/cisco-meraki.md",
23858-
"redirect_url": "/azure/sentinel/data-connectors-reference",
23859-
"redirect_document_id": false
23860-
},
2386123861
{
2386223862
"source_path_from_root": "/articles/networking/scripts/virtual-network-powershell-sample-peer-two-virtual-networks.md",
2386323863
"redirect_url": "/azure/virtual-network/tutorial-connect-virtual-networks-powershell",

articles/active-directory-b2c/whats-new-docs.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
---
22
title: "What's new in Azure Active Directory business-to-customer (B2C)"
33
description: "New and updated documentation for the Azure Active Directory business-to-customer (B2C)."
4-
ms.date: 06/05/2023
4+
ms.date: 08/01/2023
55
ms.service: active-directory
66
ms.subservice: B2C
77
ms.topic: reference

articles/active-directory-domain-services/faqs.yml

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -11,7 +11,7 @@ metadata:
1111
ms.subservice: domain-services
1212
ms.workload: identity
1313
ms.topic: faq
14-
ms.date: 05/09/2023
14+
ms.date: 08/01/2023
1515
ms.author: justinha
1616
title: Frequently asked questions (FAQs) about Azure Active Directory (AD) Domain Services
1717
summary: This page answers frequently asked questions about Azure Active Directory Domain Services.
@@ -159,6 +159,10 @@ sections:
159159
Why do my domain controllers change names?
160160
answer: |
161161
It is possible that during the maintenance of domain controllers there is a change in their names. To avoid problems with this type of change, it is recommended to not use the names of the domain controllers hardcoded in applications and/or other domain resources, but the FQDN of the domain. This way, no matter what the names of the domain controllers are, you won't need to reconfigure anything after a name change.
162+
- question: |
163+
Is the password of the KRBTGT account in a managed domain rolled periodically? If so, what is the frequency?
164+
answer: |
165+
The password of the KRBTGT account in a managed domain is rolled over every seven (7) days.
162166
163167
- name: Billing and availability
164168
questions:

articles/active-directory-domain-services/join-windows-vm-template.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -11,7 +11,7 @@ ms.subservice: domain-services
1111
ms.workload: identity
1212
ms.custom: devx-track-arm-template
1313
ms.topic: how-to
14-
ms.date: 01/29/2023
14+
ms.date: 08/01/2023
1515
ms.author: justinha
1616
---
1717

@@ -31,7 +31,7 @@ To complete this tutorial, you need the following resources and privileges:
3131
* If needed, [create an Azure Active Directory tenant][create-azure-ad-tenant] or [associate an Azure subscription with your account][associate-azure-ad-tenant].
3232
* An Azure Active Directory Domain Services managed domain enabled and configured in your Azure AD tenant.
3333
* If needed, the first tutorial [creates and configures an Azure Active Directory Domain Services managed domain][create-azure-ad-ds-instance].
34-
* A user account that's a part of the managed domain.
34+
* A user account that's a part of the *AAD DC administrators* group.
3535

3636
## Azure Resource Manager template overview
3737

articles/active-directory-domain-services/network-considerations.md

Lines changed: 12 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -9,7 +9,7 @@ ms.service: active-directory
99
ms.subservice: domain-services
1010
ms.workload: identity
1111
ms.topic: conceptual
12-
ms.date: 03/14/2023
12+
ms.date: 08/01/2023
1313
ms.author: justinha
1414
ms.reviewer: xyuan
1515

@@ -49,6 +49,16 @@ A managed domain connects to a subnet in an Azure virtual network. Design this s
4949
* A managed domain requires 3-5 IP addresses. Make sure that your subnet IP address range can provide this number of addresses.
5050
* Restricting the available IP addresses can prevent the managed domain from maintaining two domain controllers.
5151

52+
>[!NOTE]
53+
>You shouldn't use public IP addresses for virtual networks and their subnets due to the following issues:
54+
>
55+
>- **Scarcity of the IP address**: IPv4 public IP addresses are limited, and their demand often exceeds the available supply. Also, there are potentially overlapping IPs with public endpoints.
56+
>- **Security risks**: Using public IPs for virtual networks exposes your devices directly to the internet, increasing the risk of unauthorized access and potential attacks. Without proper security measures, your devices may become vulnerable to various threats.
57+
>
58+
>- **Complexity**: Managing a virtual network with public IPs can be more complex than using private IPs, as it requires dealing with external IP ranges and ensuring proper network segmentation and security.
59+
>
60+
>It is strongly recommended to use private IP addresses. If you use a public IP, ensure you are the owner/dedicated user of the chosen IPs in the public range you chose.
61+
5262
The following example diagram outlines a valid design where the managed domain has its own subnet, there's a gateway subnet for external connectivity, and application workloads are in a connected subnet within the virtual network:
5363

5464
![Recommended subnet design](./media/active-directory-domain-services-design-guide/vnet-subnet-design.png)
@@ -139,7 +149,7 @@ If needed, you can [create the required network security group and rules using A
139149
140150
### Outbound connectivity
141151

142-
For Outbound connectivity, you can either keep **AllowVnetOutbound** and **AllowInternetOutBound** or restrict Outbound traffic by using ServiceTags listed in the following table. The ServiceTag for AzureUpdateDelivery must be added via [PowerShell](powershell-create-instance.md).
152+
For Outbound connectivity, you can either keep **AllowVnetOutbound** and **AllowInternetOutBound** or restrict Outbound traffic by using ServiceTags listed in the following table. The ServiceTag for AzureUpdateDelivery must be added via [PowerShell](powershell-create-instance.md). Make sure no other NSG with higher priority denies the Outbound connectivity. If Outbound connectivity is denied, replication won't work between replica sets.
143153

144154

145155
| Outbound port number | Protocol | Source | Destination | Action | Required | Purpose |

articles/active-directory-domain-services/tutorial-create-instance.md

Lines changed: 12 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -8,7 +8,7 @@ ms.service: active-directory
88
ms.subservice: domain-services
99
ms.workload: identity
1010
ms.topic: tutorial
11-
ms.date: 01/29/2023
11+
ms.date: 08/01/2023
1212
ms.author: justinha
1313

1414
#Customer intent: As an identity administrator, I want to create an Azure Active Directory Domain Services managed domain so that I can synchronize identity information with my Azure Active Directory tenant and provide Domain Services connectivity to virtual machines and applications in Azure.
@@ -67,7 +67,7 @@ When you create a managed domain, you specify a DNS name. There are some conside
6767
* **Non-routable domain suffixes:** We generally recommend that you avoid a non-routable domain name suffix, such as *contoso.local*. The *.local* suffix isn't routable and can cause issues with DNS resolution.
6868

6969
> [!TIP]
70-
> If you create a custom domain name, take care with existing DNS namespaces. It's recommended to use a domain name separate from any existing Azure or on-premises DNS name space.
70+
> If you create a custom domain name, take care with existing DNS namespaces. Although it's supported, you may want to use a domain name separate from any existing Azure or on-premises DNS namespace.
7171
>
7272
> For example, if you have an existing DNS name space of *contoso.com*, create a managed domain with the custom domain name of *aaddscontoso.com*. If you need to use secure LDAP, you must register and own this custom domain name to generate the required certificates.
7373
>
@@ -106,6 +106,16 @@ To quickly create a managed domain, you can select **Review + create** to accept
106106
* Creates a subnet named *aadds-subnet* using the IP address range of *10.0.2.0/24*.
107107
* Synchronizes *All* users from Azure AD into the managed domain.
108108

109+
>[!NOTE]
110+
>You shouldn't use public IP addresses for virtual networks and their subnets due to the following issues:
111+
>
112+
>- **Scarcity of the IP address**: IPv4 public IP addresses are limited, and their demand often exceeds the available supply. Also, there are potentially overlapping IPs with public endpoints.
113+
>- **Security risks**: Using public IPs for virtual networks exposes your devices directly to the internet, increasing the risk of unauthorized access and potential attacks. Without proper security measures, your devices may become vulnerable to various threats.
114+
>
115+
>- **Complexity**: Managing a virtual network with public IPs can be more complex than using private IPs, as it requires dealing with external IP ranges and ensuring proper network segmentation and security.
116+
>
117+
>It is strongly recommended to use private IP addresses. If you use a public IP, ensure you are the owner/dedicated user of the chosen IPs in the public range you chose.
118+
109119
Select **Review + create** to accept these default configuration options.
110120

111121
## Deploy the managed domain

articles/active-directory/app-provisioning/application-provisioning-configuration-api.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -60,7 +60,7 @@ Content-type: application/json
6060
{
6161
"value": [
6262
{
63-
"id": "8b1025e4-1dd2-430b-a150-2ef79cd700f5",
63+
"id": "8b1025e4-1dd2-430b-a150-2ef79cd700f5",
6464
"displayName": "AWS Single-Account Access",
6565
"homePageUrl": "http://aws.amazon.com/",
6666
"supportedSingleSignOnModes": [

articles/active-directory/app-provisioning/application-provisioning-when-will-provisioning-finish-specific-user.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -85,7 +85,7 @@ Summary of factors that influence the time it takes to complete an **initial cyc
8585

8686
- Whether users in scope for provisioning are matched to existing users in the target application, or need to be created for the first time. Sync jobs for which all users are created for the first time take about *twice as long* as sync jobs for which all users are matched to existing users.
8787

88-
- Number of errors in the [provisioning logs](check-status-user-account-provisioning.md). Performance is slower if there are many errors and the provisioning service has gone into a quarantine state.
88+
- Number of errors in the [provisioning logs](check-status-user-account-provisioning.md). Performance is slower if there are many errors and the provisioning service has gone into a quarantine state.
8989

9090
- Request rate limits and throttling implemented by the target system. Some target systems implement request rate limits and throttling, which can impact performance during large sync operations. Under these conditions, an app that receives too many requests too fast might slow its response rate or close the connection. To improve performance, the connector needs to adjust by not sending the app requests faster than the app can process them. Provisioning connectors built by Microsoft make this adjustment.
9191

0 commit comments

Comments
 (0)