You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/active-directory/privileged-identity-management/pim-how-to-activate-role.md
+42-15Lines changed: 42 additions & 15 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -11,7 +11,7 @@ ms.service: active-directory
11
11
ms.topic: conceptual
12
12
ms.workload: identity
13
13
ms.component: pim
14
-
ms.date: 02/14/2017
14
+
ms.date: 08/21/2018
15
15
ms.author: rolyon
16
16
ms.custom: pim
17
17
---
@@ -26,25 +26,48 @@ This article is for admins who need to activate their role in Azure AD Privilege
26
26
Use the Azure AD Privileged Identity Management application in the [Azure portal](https://portal.azure.com/) to request a role activation, even if you're going to operate in another portal or PowerShell. If you don't have the Azure AD Privileged Identity Management application on your Azure portal, follow these steps to get started.
27
27
28
28
1. Sign in to the [Azure portal](https://portal.azure.com/).
29
-
2. Select your username in the upper right-hand corner of the Azure portal, and select the directory where you will you be operating.
30
-
3. Select **All services** and use the Filter textbox to search for **Azure AD Privileged Identity Management**.
31
-
4. Check **Pin to dashboard** and then click **Create**. The Privileged Identity Management application opens.
29
+
30
+
1. Select your username in the upper right-hand corner of the Azure portal, and select the directory where you will you be operating.
31
+
32
+
1. Select **All services** and use the Filter textbox to search for **Azure AD Privileged Identity Management**.
33
+
34
+
1. Check **Pin to dashboard** and then click **Create**. The Privileged Identity Management application opens.
32
35
33
36
## Activate a role
34
37
When you need to take on a role, you can request activation by selecting the **My Roles** navigation option in the Azure AD Privileged Identity Management application's left navigation column.
35
38
36
39
1. Sign in to the [Azure portal](https://portal.azure.com/) and select the Azure AD Privileged Identity Management tile.
37
-
2. Select **My Roles**. A list of your assigned eligible roles appear in the grouping at the top of the page.
38
-
3. Select a role to activate.
39
-
4. Select **Activate**. The **Request role activation** blade appears.
40
-
5. Some roles require Multi-Factor Authentication (MFA) before you can activate the role. You only have to authenticate once per session.
41
-
40
+
41
+
1. Select **My Roles**. A list of your assigned eligible roles appear in the grouping at the top of the page.
42
+
43
+
1. Select a role to activate.
44
+
45
+
1. Select **Activate**. The **Request role activation** blade appears.
46
+
47
+
1. Some roles require Multi-Factor Authentication (MFA) before you can activate the role. You only have to authenticate once per session.
48
+
42
49

43
-
6. Enter the reason for the activation request in the text field. Some roles require you to supply a trouble ticket number.
44
-
7. Select **OK**. If the role does not require approval, it is now activated, and the role appears in the list of active roles (directly below the list of eligible role assignments). If the [role requires approval](./azure-ad-pim-approval-workflow.md) to activate, a toast notification will briefly appear in the upper right-hand corner of your browser informing you the request is pending approval.
50
+
51
+
1. Enter the reason for the activation request in the text field. Some roles require you to supply a trouble ticket number.
52
+
53
+
1. Select **OK**. If the role does not require approval, it is now activated, and the role appears in the list of active roles (directly below the list of eligible role assignments). If the [role requires approval](./azure-ad-pim-approval-workflow.md) to activate, a toast notification will briefly appear in the upper right-hand corner of your browser informing you the request is pending approval.
Because of caching, activations do not occur immediately in the Azure portal without a refresh. If you need to reduce the possibility of delays after activating a role, you can use the **Application access** page in the portal. Applications accessed from this page check for new role assignments immediately.
1. Click **Azure Active Directory** to reopen the portal on the **All Users** page.
68
+
69
+
When you click this link, you force a refresh and there is a check for new Azure AD role assignments.
70
+
48
71
## Deactivate a role
49
72
Once a role has been activated, it automatically deactivates when its time limit (eligible duration) is reached.
50
73
@@ -54,10 +77,14 @@ If you complete your admin tasks early, you can also deactivate a role manually
54
77
In the event you do not require activation of a role that requires approval, you may cancel a pending request at any time. Simply select the **My Roles** navigation option in the Azure AD Privileged Identity Management application's left navigation column.
55
78
56
79
1. Sign in to the [Azure portal](https://portal.azure.com/) and select the Azure AD Privileged Identity Management tile.
57
-
2. Select **My Roles**. A list of your assigned eligible roles appear in the grouping at the top of the page.
58
-
3. Select a role.
59
-
4. Select the **Activation is pending approval** banner on the role activation details blade.
60
-
5. Select **Cancel** at the top of the **Pending approval** blade.
80
+
81
+
1. Select **My Roles**. A list of your assigned eligible roles appear in the grouping at the top of the page.
82
+
83
+
1. Select a role.
84
+
85
+
1. Select the **Activation is pending approval** banner on the role activation details blade.
86
+
87
+
1. Select **Cancel** at the top of the **Pending approval** blade.
Copy file name to clipboardExpand all lines: articles/active-directory/privileged-identity-management/pim-resource-roles-activate-your-roles.md
+15-2Lines changed: 15 additions & 2 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -11,15 +11,15 @@ ms.topic: conceptual
11
11
ms.tgt_pltfrm: na
12
12
ms.workload: identity
13
13
ms.component: pim
14
-
ms.date: 04/02/2018
14
+
ms.date: 08/21/2018
15
15
ms.author: rolyon
16
16
ms.custom: pim
17
17
---
18
18
19
19
# Activate roles for Azure resources by using Privileged Identity Management
20
20
Privileged Identity Management (PIM) introduces a new experience in activating roles for Azure resources. Eligible role members can schedule activation for a future date and time. They can also select a specific activation duration within the maximum (configured by administrators). For more information, see [How to activate or deactivate roles in Azure AD Privileged Identity Management](pim-how-to-activate-role.md).
21
21
22
-
## Activate roles
22
+
## Activate a role
23
23
Browse to the **My roles** section in the left pane. Select **Activate** for the role that you want to activate.
24
24
25
25

@@ -34,6 +34,19 @@ If the activation is scheduled for a future date and time, the pending request a
34
34
35
35

36
36
37
+
## Use a role immediately after activation
38
+
39
+
Because of caching, activations do not occur immediately in the Azure portal without a refresh. If you need to reduce the possibility of delays after activating a role, you can use the **Application access** page in the portal. Applications accessed from this page check for new role assignments immediately.
Copy file name to clipboardExpand all lines: articles/active-directory/privileged-identity-management/pim-resource-roles-discover-resources.md
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -22,7 +22,7 @@ Learn how to discover and manage Azure resources when you use Privileged Identit
22
22
When you first set up PIM for Azure resources, you need to discover and select resources to protect with PIM. There's no limit to the number of resources that you can manage with PIM. However, we recommend starting with your most critical (production) resources.
23
23
24
24
> [!NOTE]
25
-
> You can only search for and select subscription resources to manage by using PIM. When you manage a subscription in PIM, you can also manage child resources in the subscription.
25
+
> You can only search for and select management group or subscription resources to manage using PIM. When you manage a management group or a subscription in PIM, you can also manage its child resources.
Copy file name to clipboardExpand all lines: articles/api-management/api-management-howto-disaster-recovery-backup-restore.md
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -174,7 +174,7 @@ POST https://management.azure.com/subscriptions/{subscriptionId}/resourceGroups/
174
174
where:
175
175
176
176
*`subscriptionId` - id of the subscription containing the API Management service you are restoring a backup into
177
-
*`resourceGroupName` - a string in the form of 'Api-Default-{service-region}' where `service-region` identifies the Azure region where the API Management service you are restoring a backup into is hosted, for example, `North-Central-US`
177
+
*`resourceGroupName` - name of the resource group containing the Azure API Management service you are restoring a backup into
178
178
*`serviceName` - the name of the API Management service being restored into specified at the time of its creation
179
179
*`api-version` - replace with `2018-06-01-preview`
Copy file name to clipboardExpand all lines: articles/app-service/app-service-deploy-complex-application-predictably.md
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -36,7 +36,7 @@ In the tutorial, you will deploy an application that includes:
36
36
In this tutorial, you will use the following tools. Since it’s not comprehensive discussion on tools, I’m going to stick to the end-to-end scenario and just give you a brief intro to each, and where you can find more information on it.
37
37
38
38
### Azure Resource Manager templates (JSON)
39
-
Every time you create a web app in Azure App Service, for example, Azure Resource Manager uses a JSON template to create the entire resource group with the component resources. A complex template from the [Azure Marketplace](/marketplace) like the [Scalable WordPress](/marketplace/partners/wordpress/scalablewordpress/) app can include the MySQL database, storage accounts, the App Service plan, the web app itself, alert rules, app settings, autoscale settings, and more, and all these templates are available to you through PowerShell. For information on how to download and use these templates, see [Using Azure PowerShell with Azure Resource Manager](../powershell-azure-resource-manager.md).
39
+
Every time you create a web app in Azure App Service, for example, Azure Resource Manager uses a JSON template to create the entire resource group with the component resources. A complex template from the [Azure Marketplace](/azure/marketplace)can include the database, storage accounts, the App Service plan, the web app itself, alert rules, app settings, autoscale settings, and more, and all these templates are available to you through PowerShell. For information on how to download and use these templates, see [Using Azure PowerShell with Azure Resource Manager](../powershell-azure-resource-manager.md).
40
40
41
41
For more information on the Azure Resource Manager templates, see [Authoring Azure Resource Manager Templates](../azure-resource-manager/resource-group-authoring-templates.md)
Copy file name to clipboardExpand all lines: articles/app-service/app-service-patch-os-runtime.md
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -90,7 +90,7 @@ The following table shows how to the versions of Windows and of the language run
90
90
| Python version | At `https://<appname>.scm.azurewebsites.net/DebugConsole`, run the following command in the command prompt: <br> `python --version`|
91
91
92
92
> [!NOTE]
93
-
> Access to registry location `HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\Packages`, where information on ["KB" patches]((https://docs.microsoft.com/security-updates/SecurityBulletins/securitybulletins)) is stored, is locked down.
93
+
> Access to registry location `HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\Packages`, where information on ["KB" patches](https://docs.microsoft.com/security-updates/SecurityBulletins/securitybulletins) is stored, is locked down.
0 commit comments