Skip to content

Commit b73b2ab

Browse files
Merge pull request #234373 from markwahl-msft/mwahl-fun-gov
Azure AD: fundamentals: clarify relationship of Azure AD Premium P2 and Identity Governance
2 parents 22264a6 + 1b3f454 commit b73b2ab

9 files changed

+11
-17
lines changed

articles/active-directory/fundamentals/3-secure-access-plan.md

Lines changed: 5 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -139,16 +139,16 @@ Generally, organizations customize policy, however consider the following parame
139139

140140
## Access control methods
141141

142-
Some features, for example entitlement management, are available with an Azure AD Premium 2 (P2) license. Microsoft 365 E5 and Office 365 E5 licenses include Azure AD P2 licenses. Learn more in the following entitlement management section.
142+
Some features, for example entitlement management, are available with an Azure AD Premium 2 (P2) license. Microsoft 365 E5 and Office 365 E5 licenses include Azure AD Premium P2 licenses. Learn more in the following entitlement management section.
143143

144144
> [!NOTE]
145-
> Licenses are for one user. Therefore users, administrators, and business owners can have delegated access control. This scenario can occur with Azure AD P2 or Microsoft 365 E5, and you don't have to enable licenses for all users. The first 50,000 external users are free. If you don't enable P2 licenses for other internal users, they can't use entitlement management.
145+
> Licenses are for one user. Therefore users, administrators, and business owners can have delegated access control. This scenario can occur with Azure AD Premium P2 or Microsoft 365 E5, and you don't have to enable licenses for all users. The first 50,000 external users are free. If you don't enable P2 licenses for other internal users, they can't use entitlement management.
146146
147147
Other combinations of Microsoft 365, Office 365, and Azure AD have functionality to manage external users. See, [Microsoft 365 guidance for security & compliance](/office365/servicedescriptions/microsoft-365-service-descriptions/microsoft-365-tenantlevel-services-licensing-guidance/microsoft-365-security-compliance-licensing-guidance).
148148

149-
## Govern access with Azure AD P2 and Microsoft 365 or Office 365 E5
149+
## Govern access with Azure AD Premium P2 and Microsoft 365 or Office 365 E5
150150

151-
Azure AD P2 and Microsoft 365 E5 have all the security and governance tools.
151+
Azure AD Premium P2, included in Microsoft 365 E5, has additional security and governance capabilities.
152152

153153
### Provision, sign-in, review access, and deprovision access
154154

@@ -178,7 +178,7 @@ Use entitlement management to provision and deprovision access to groups and tea
178178

179179
Learn more: [Create a new access package in entitlement management](../governance/entitlement-management-access-package-create.md)
180180

181-
## Governance with Azure AD P1, Microsoft 365, Office 365 E3
181+
## Manage access with Azure AD P1, Microsoft 365, Office 365 E3
182182

183183
### Provision, sign-in, review access, and deprovision access
184184

articles/active-directory/fundamentals/9-secure-access-teams-sharepoint.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -55,7 +55,7 @@ Guest invite settings determine who invites guests and how guests are invited. T
5555

5656
* The IT team:
5757
* After training is complete, the IT team grants the Guest Inviter role
58-
* To enable access reviews, assigns Azure AD P2 license to the Microsoft 365 group owner
58+
* Ensures there are sufficient Azure AD Premium P2 licenses for the Microsoft 365 group owners who will review
5959
* Creates a Microsoft 365 group access review
6060
* Confirms access reviews occur
6161
* Removes users added to SharePoint

articles/active-directory/fundamentals/active-directory-deployment-plans.md

Lines changed: 2 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -96,9 +96,9 @@ The following list describes features and services for productivity gains in hyb
9696
* See, [B2B collaboration overview](../external-identities/what-is-b2b.md)
9797
* See, [Plan an Azure Active Directory B2B collaboration deployment](../fundamentals/secure-external-access-resources.md)
9898

99-
## Governance and reporting
99+
## Identity Governance and reporting
100100

101-
Use the following list to learn about governance and reporting. Items in the list refer to Microsoft Entra.
101+
Use the following list to learn about identity governance and reporting. Items in the list refer to Microsoft Entra.
102102

103103
Learn more: [Secure access for a connected world—meet Microsoft Entra](https://www.microsoft.com/en-us/security/blog/?p=114039)
104104

@@ -112,8 +112,6 @@ Learn more: [Secure access for a connected world—meet Microsoft Entra](https:/
112112
* See, [Plan a Microsoft Entra access reviews deployment](../governance/deploy-access-reviews.md)
113113
* **Identity governance** - Meet your compliance and risk management objectives for access to critical applications. Learn how to enforce accurate access.
114114
* See, [Govern access for applications in your environment](../governance/identity-governance-applications-prepare.md)
115-
116-
Learn more: [Azure governance documentation](../../governance/index.yml)
117115

118116
## Best practices for a pilot
119117

articles/active-directory/fundamentals/active-directory-ops-guide-auth.md

Lines changed: 1 addition & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -44,7 +44,6 @@ As you review your list, you may find you need to either assign an owner for tas
4444
#### Owner recommended reading
4545

4646
- [Assigning administrator roles in Azure Active Directory](../roles/permissions-reference.md)
47-
- [Governance in Azure](../../governance/index.yml)
4847

4948
## Credentials management
5049

@@ -246,7 +245,7 @@ Conditional Access is an essential tool for improving the security posture of yo
246245
- Plan for [break glass](../roles/security-planning.md#break-glass-what-to-do-in-an-emergency) accounts without MFA controls
247246
- Ensure a consistent experience across Microsoft 365 client applications, for example, Teams, OneDrive, Outlook, etc.) by implementing the same set of controls for services such as Exchange Online and SharePoint Online
248247
- Assignment to policies should be implemented through groups, not individuals
249-
- Do regular reviews of the exception groups used in policies to limit the time users are out of the security posture. If you own Azure AD P2, then you can use access reviews to automate the process
248+
- Do regular reviews of the exception groups used in policies to limit the time users are out of the security posture. If you own Azure AD Premium P2, then you can use access reviews to automate the process
250249

251250
#### Conditional Access recommended reading
252251

articles/active-directory/fundamentals/active-directory-ops-guide-govern.md

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -45,7 +45,6 @@ As you review your list, you may find you need to either assign an owner for tas
4545
#### Owner recommended reading
4646

4747
- [Assigning administrator roles in Azure Active Directory](../roles/permissions-reference.md)
48-
- [Governance in Azure](../../governance/index.yml)
4948

5049
### Configuration changes testing
5150

articles/active-directory/fundamentals/active-directory-ops-guide-iam.md

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -41,7 +41,6 @@ As you review your list, you may find you need to either assign an owner for tas
4141
#### Assigning owners recommended reading
4242

4343
- [Assigning administrator roles in Azure Active Directory](../roles/permissions-reference.md)
44-
- [Governance in Azure](../../governance/index.yml)
4544

4645
## On-premises identity synchronization
4746

articles/active-directory/fundamentals/active-directory-ops-guide-intro.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -25,7 +25,7 @@ This operations reference guide describes the checks and actions you should take
2525
Some recommendations here might not be applicable to all customers’ environment, for example, AD FS best practices might not apply if your organization uses password hash sync.
2626

2727
> [!NOTE]
28-
> These recommendations are current as of the date of publishing but can change over time. Organizations should continuously evaluate their identity practices as Microsoft products and services evolve over time. Recommendations can change when organizations subscribe to a different Azure AD Premium license. For example, Azure AD Premium P2 will include more governance recommendations.
28+
> These recommendations are current as of the date of publishing but can change over time. Organizations should continuously evaluate their identity practices as Microsoft products and services evolve over time. Recommendations can change when organizations subscribe to a different Azure AD Premium license.
2929
3030
## Stakeholders
3131

articles/active-directory/fundamentals/active-directory-ops-guide-ops.md

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -45,7 +45,6 @@ As you review your list, you may find you need to either assign an owner for tas
4545
#### Owners recommended reading
4646

4747
- [Assigning administrator roles in Azure Active Directory](../roles/permissions-reference.md)
48-
- [Governance in Azure](../../governance/index.yml)
4948

5049
## Hybrid management
5150

articles/active-directory/fundamentals/concept-secure-remote-workers.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -94,7 +94,7 @@ The following table is intended to highlight the key actions for the following l
9494

9595
The following table is intended to highlight the key actions for the following license subscriptions:
9696

97-
- Azure Active Directory Premium P2 (Azure AD P2)
97+
- Azure Active Directory Premium P2
9898
- Enterprise Mobility + Security (EMS E5)
9999
- Microsoft 365 (E5, A5)
100100

0 commit comments

Comments
 (0)