You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/active-directory/fundamentals/identity-secure-score.md
+12-28Lines changed: 12 additions & 28 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -23,7 +23,7 @@ ms.reviewer: nigu
23
23
24
24
How secure is your Azure AD tenant? If you don't know how to answer this question, read this article to learn how the identity secure score helps you to monitor and improve your identity security posture.
25
25
26
-
## What is a secure score?
26
+
## What is an identity secure score?
27
27
28
28
The identity secure score is number between 1 and 248 that functions as indicator for how aligned you are with Microsoft's best practices recommendations for security.
29
29
@@ -66,17 +66,6 @@ By following the improvement actions, you can:
66
66
67
67
- Take advantage of Microsoft’s Identity features.
68
68
69
-
The improvement actions take into consideration:
70
-
71
-
- Privileged accounts
72
-
73
-
- App management
74
-
75
-
- Conditional access policies
76
-
77
-
- Authentication methods
78
-
79
-
- Auditing and reporting.
80
69
81
70
82
71
## How do I get my secure score?
@@ -104,19 +93,25 @@ Additionally, you also have the option to set recommendations to be ignored if t
104
93
105
94
## How does it help me?
106
95
107
-
Using the secure score helps increase your organization's security by encouraging you to use the built-in security features such as:
96
+
The secure score helps you to:
97
+
98
+
- Objectively measure your identity security posture
108
99
100
+
- Plan identity security improvements
109
101
110
-
Learning more about these features as you use the tool will help give you piece of mind that you're taking the right steps to protect your organization from threats.
102
+
- Review the success of your improvements
111
103
112
-
Customers who are using Secure Score have seen their score increase five times more than customers who aren't using it. (The increase in score corresponds with the security features being used in their organizations.)
113
104
114
105
115
106
## What you should know
116
107
117
-
### Who can use Secure Score?
108
+
### Who can use the identity secure score?
109
+
110
+
The identity secure score can be used by the following roles:
118
111
119
-
Anyone who has admin permissions (global admin or a custom admin role) for your Azure AD tenant. Users who aren't assigned an admin role can't access the score. However, admins can use the tool to share their results with other people in their organization.
112
+
- Global admin
113
+
- Security admin
114
+
- Security readers
120
115
121
116
### What does [Not Scored] mean?
122
117
@@ -126,9 +121,6 @@ Actions labeled as [Not Scored] are ones you can perform in your organization bu
126
121
127
122
The score is calculated once per day (around 1:00 AM PST). If you make a change to a measured action, the score will automatically update the next day. It takes up to 48 hours for a change to be reflected in your score.
128
123
129
-
### Who can see my results?
130
-
131
-
Results are filtered to show scores only to people in your organization who are assigned an admin role (global admin or a custom admin role).
132
124
133
125
### My score changed. How do I figure out why?
134
126
@@ -162,14 +154,6 @@ The [Office 365 secure score](https://docs.microsoft.com/office365/securitycompl
162
154
The identity secure score represents the identity part of of the Office 365 secure score. This means that your recommendations for the identity secure score and the identity score in Office 365 are the same.
163
155
164
156
165
-
### I have an idea for another control. How do I let you know what it is?
166
-
We'd love to hear from you. Post your ideas on the Office Security, Privacy & Compliance community. We're listening and want the Secure Score to include all options that are important to you.
167
-
168
-
Something isn't working right. Who should I contact?
169
-
If you have any issues, let us know by posting on the Office Security, Privacy & Compliance community. We're monitoring the community and will provide help.
170
-
171
-
### My organization only has certain security features. Does this affect my score?
172
-
The Secure Score calculates your score based on the services you purchased. For example, if you only purchased an Exchange Online plan, you won't be scored for SharePoint Online security features. The denominator of the score is the sum of all the baselines for the controls that apply to the products you purchased. The numerator is the sum of all the controls for which you completed, or partially completed, the actions to fulfill that control.
173
157
## Next steps
174
158
175
159
If you would like to see a video about the Office 365 secure score, click [here](https://www.youtube.com/watch?v=jzfpDJ9Kg-A).
Copy file name to clipboardExpand all lines: articles/active-directory/user-help/microsoft-authenticator-app-faq.md
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -40,7 +40,7 @@ The Microsoft Authenticator app replaced the Azure Authenticator app, and is the
40
40
|Why does the Microsoft Authenticator app allow you to approve a request without unlocking the device?|You don't have to unlock your device to approve verification requests because all you need to prove is that you have your phone with you. Two-step verification requires proving two things – a thing you know, and a thing you have. The thing you know is your password. The thing you have is your phone (set up with the Microsoft Authenticator app and registered as an MFA proof.) Therefore, having the phone and approving the request meets the criteria for the second factor of authentication.|
41
41
|Why aren’t all my accounts showing up when I open the Microsoft Authenticator app on my Apple Watch?|The Microsoft Authenticator app only supports using Microsoft personal or school or work accounts with push notifications on the Apple Watch companion app. For your other accounts, like Google or Facebook, you’ll have to open the authenticator app on your phone to view your verification codes.|
42
42
|Why can’t I approve or deny notifications on my Apple Watch?|First, make sure you’ve upgraded to the Microsoft Authenticator app, version 6.0.0 or higher on your iPhone. After that, open the Microsoft Authenticator companion app on your Apple Watch and look for any accounts with a **Set Up** button beneath them. You must complete that set up process to approve notifications for those accounts.|
43
-
|Why am I getting the error, **Unable to communicate with the phone while using the Microsoft Authenticator companion app on the Apple Watch**?|If your phone and watch aren’t communicating, you can try the following:<ol><li>Force quit the Microsoft Authenticator phone app and open it again on your iPhone.</li><li>Force quit the companion app on your Apple Watch.<ol><li> Open the Microsoft Authenticator companion app on your Watch</li><li>Hold down the side button until the **Shutdown** screen appears.</li><li>Release the side button and hold down the Digital Crown to force quit the active app.</li></ol></li><li>Turn off both Bluetooth and Wi-Fi for both your phone and your Watch, and then turn them back on.</li><li>Restart your iPhone and your Watch.</li></ol>|
43
+
|I’m getting a communication error between the Apple Watch and my phone. What can I do to troubleshoot?|This error happens when your Watch screen goes to sleep before it finishes communicating with your phone.<br><br><b>If this happens during setup:</b><br>Try to run setup again, making sure to keep your Watch awake until the process is done. At the same time, open the app on your phone and respond to any prompts that appear.<br><br>If your phone and Watch still aren’t communicating, you can try the following:<ol><li>Force quit the Microsoft Authenticator phone app and open it again on your iPhone.</li><li>Force quit the companion app on your Apple Watch.<ol><li> Open the Microsoft Authenticator companion app on your Watch</li><li>Hold down the side button until the **Shutdown** screen appears.</li><li>Release the side button and hold down the Digital Crown to force quit the active app.</li></ol></li><li>Turn off both Bluetooth and Wi-Fi for both your phone and your Watch, and then turn them back on.</li><li>Restart your iPhone and your Watch.</li></ol><b>If this happens when you’re trying to approve a notification:</b><br>The next time you try to approve a notification on your Apple Watch, keep the screen awake until the request is complete and you hear the sound that indicates it was successful.|
44
44
|Why isn’t the Microsoft Authenticator companion app for Apple Watch syncing or showing up on my watch?|If the app isn’t showing up on your Watch, try the following: <ol><li>Make sure your Watch is running watchOS 4.0 or higher.</li><li>Sync your Watch again.</li></ol>|
45
45
|My Apple Watch companion app crashed. Can I send you my crash logs so you can investigate? |You first have to make sure you’ve chosen to share your analytics with us. If you’re a TestFlight user, you’re already signed up. Otherwise, you can go to **Settings > Privacy > Analytics** and select both the **Share iPhone & Watch analytics** and the **Share with App Developers** options.<br><br>After you sign up, you can try to reproduce your crash so your crash logs are automatically sent to us for investigation. However, if you can’t reproduce your crash, you can manually copy your log files and send them to us.<ol><li>Open the Watch app on your phone, go to **Settings > General**, and then click **Copy Watch Analytics**.</li><li>Find the corresponding crash under **Settings > Privacy > Analytics > Analytics Data**, and then manually copy the entire text.</li><li>Open the Microsoft Authenticator app on your phone and paste that copied text into the **Share with App Developers** text box on the **Send logs** page.</li></ol>|
Copy file name to clipboardExpand all lines: articles/application-insights/app-insights-profiler.md
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -18,7 +18,7 @@ ms.author: mbullwin
18
18
---
19
19
# Profile live Azure web apps with Application Insights
20
20
21
-
This feature of Azure Application Insights is generally available for the Web Apps feature of Azure App Service and is in preview for Azure compute resources. For information regarding [on premises use of profiler](https://docs.microsoft.com/azure/application-insights/enable-profiler-compute#enable-profiler-on-on-premises-servers).
21
+
This feature of Azure Application Insights is generally available for the Web Apps feature of Azure App Service and Azure compute resources. For information regarding [on premises use of profiler](https://docs.microsoft.com/azure/application-insights/enable-profiler-compute#enable-profiler-on-on-premises-servers).
22
22
23
23
This article discusses the amount of time that's spent in each method of your live web application when you use [Application Insights](app-insights-overview.md). The Application Insights Profiler tool displays detailed profiles of live requests that were served by your app. Profiler highlights the *hot path* that uses the most time. Requests with various response times are profiled on a sampling basis. By using a variety of techniques, you can minimize the overhead that's associated with the application.
Copy file name to clipboardExpand all lines: articles/automation/automation-update-azure-modules.md
+4-2Lines changed: 4 additions & 2 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -6,7 +6,7 @@ ms.service: automation
6
6
ms.component: process-automation
7
7
author: georgewallace
8
8
ms.author: gwallace
9
-
ms.date: 03/16/2018
9
+
ms.date: 09/19/2018
10
10
ms.topic: conceptual
11
11
manager: carmonm
12
12
---
@@ -39,8 +39,10 @@ Because modules are updated regularly by the product group, changes can occur wi
39
39
40
40
If the modules are already up-to-date, then the process completes in a few seconds. When the update process completes, you are notified.<br><br> 
41
41
42
+
The .NET core AzureRm modules (AzureRm.*.Core) are not supported in Azure Automation and can not be imported.
43
+
42
44
> [!NOTE]
43
-
> Azure Automation uses the latest modules in your Automation account when a new scheduled job is run.
45
+
> Azure Automation uses the latest modules in your Automation account when a new scheduled job is run.
44
46
45
47
If you use cmdlets from these Azure PowerShell modules in your runbooks, you want to run this update process every month or so to make sure that you have the latest modules. Azure Automation uses the AzureRunAsConnection connection to authenticate when updating the modules, if the service principal is expired or no longer exists on the subscription level, the module update will fail.
Copy file name to clipboardExpand all lines: articles/automation/automation-update-management.md
+19-13Lines changed: 19 additions & 13 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -29,7 +29,7 @@ The following diagram shows a conceptual view of the behavior and data flow with
29
29
30
30

31
31
32
-
Update Management can be used to natively onboard machines in multiple subscriptions in the same tenant. To manage machines in a different tenant you must onboard them as [Non-Azure machines](automation-onboard-solutions-from-automation-account.md#onboard-a-non-azure-machine).
32
+
Update Management can be used to natively onboard machines in multiple subscriptions in the same tenant. To manage machines in a different tenant you must onboard them as [Non-Azure machines](automation-onboard-solutions-from-automation-account.md#onboard-a-non-azure-machine).
33
33
34
34
After a computer performs a scan for update compliance, the agent forwards the information in bulk to Azure Log Analytics. On a Windows computer, the compliance scan is performed every 12 hours by default.
35
35
@@ -50,6 +50,8 @@ Updates are installed by runbooks in Azure Automation. You can't view these runb
50
50
51
51
At the date and time specified in the update deployment, the target computers execute the deployment in parallel. Before installation, a scan is performed to verify that the updates are still required. For WSUS client computers, if the updates aren't approved in WSUS, the update deployment fails.
52
52
53
+
Having a machine registered for Update Management in multiple Log Analytics Workspaces (multi-homing) is not supported.
54
+
53
55
## Clients
54
56
55
57
### Supported client types
@@ -193,18 +195,6 @@ To avoid updates being applied outside of a maintenance window on Ubuntu, reconf
193
195
194
196
Virtual machines that were created from the on-demand Red Hat Enterprise Linux (RHEL) images that are available in the Azure Marketplace are registered to access the [Red Hat Update Infrastructure (RHUI)](../virtual-machines/virtual-machines-linux-update-infrastructure-redhat.md) that's deployed in Azure. Any other Linux distribution must be updated from the distribution's online file repository by following the distribution's supported methods.
195
197
196
-
## View missing updates
197
-
198
-
Select **Missing updates** to view the list of updates that are missing from your machines. Each update is listed and can be selected. Information about the number of machines that require the update, the operating system, and a link for more information is shown. The **Log search** pane shows more details about the updates.
199
-
200
-
## View update deployments
201
-
202
-
Select the **Update Deployments** tab to view the list of existing update deployments. Select any of the update deployments in the table to open the **Update Deployment Run** pane for that update deployment.
203
-
204
-

205
-
206
-
## Create or edit an update deployment
207
-
208
198
To create a new update deployment, select **Schedule update deployment**. The **New Update Deployment** pane opens. Enter values for the properties described in the following table and then click **Create**:
209
199
210
200
| Property | Description |
@@ -220,6 +210,20 @@ To create a new update deployment, select **Schedule update deployment**. The **
220
210
| Maintenance window |Number of minutes set for updates. The value can be not be less than 30 minutes and no more than 6 hours |
221
211
| Reboot control| Determines how reboots should be handled. Available options are:</br>Reboot if required (Default)</br>Always reboot</br>Never reboot</br>Only reboot - will not install updates|
222
212
213
+
Update Deployments can also be created programmatically. To learn how to create an Update Deployment with the REST API, see [Software Update Configurations - Create](/rest/api/automation/softwareupdateconfigurations/create). There is also a sample runbook that can be used to create a weekly Update Deployment. To learn more about this runbook, see [Create a weekly update deployment for one or more VMs in a resource group](https://gallery.technet.microsoft.com/scriptcenter/Create-a-weekly-update-2ad359a1).
214
+
215
+
## View missing updates
216
+
217
+
Select **Missing updates** to view the list of updates that are missing from your machines. Each update is listed and can be selected. Information about the number of machines that require the update, the operating system, and a link for more information is shown. The **Log search** pane shows more details about the updates.
218
+
219
+
## View update deployments
220
+
221
+
Select the **Update Deployments** tab to view the list of existing update deployments. Select any of the update deployments in the table to open the **Update Deployment Run** pane for that update deployment.
222
+
223
+

224
+
225
+
To view an update deployment from the REST API, see [Software Update Configuration Runs](/rest/api/automation/softwareupdateconfigurationruns).
226
+
223
227
## Update classifications
224
228
225
229
The following tables list the update classifications in Update Management, with a definition for each classification.
@@ -544,3 +548,5 @@ Continue to the tutorial to learn how to manage updates for your Windows virtual
544
548
545
549
* Use log searches in [Log Analytics](../log-analytics/log-analytics-log-searches.md) to view detailed update data.
546
550
*[Create alerts](../log-analytics/log-analytics-alerts.md) when critical updates are detected as missing from computers or if a computer has automatic updates disabled.
551
+
552
+
* To learn how to interact with Update Management through the REST API, see [Software Update Configurations](/rest/api/automation/softwareupdateconfigurations)
Copy file name to clipboardExpand all lines: articles/azure-stack/azure-stack-csp-howto-register-tenants.md
+4-4Lines changed: 4 additions & 4 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -12,7 +12,7 @@ ms.workload: na
12
12
pms.tgt_pltfrm: na
13
13
ms.devlang: na
14
14
ms.topic: article
15
-
ms.date: 07/12/2018
15
+
ms.date: 09/19/2018
16
16
ms.author: sethm
17
17
ms.reviewer: alfredo
18
18
@@ -66,9 +66,9 @@ Update your registration with the new customer’s subscription. Azure reports t
66
66
### New-AzureRmResource PowerShell parameters
67
67
| Parameter | Description |
68
68
| --- | --- |
69
-
|registrationSubscriptionID | The Azure subscription that was used for the initial registration of the Azure Stack.|
70
-
| customerSubscriptionID | The Azure subscription (not Azure Stack) belonging to the customer to be registered. Must be created in the CSP offer; in practice, this means through Partner Center. If a customer has more than one Azure Active Directory tenant, this subscription must be created in the tenant that will be used to log into Azure Stack.
71
-
| resourceGroup | The resource group in Azure in which your registration is stored.
69
+
|registrationSubscriptionID | The Azure subscription that was used for the initial registration of the Azure Stack.|
70
+
| customerSubscriptionID | The Azure subscription (not Azure Stack) belonging to the customer to be registered. Must be created in the CSP offer; in practice, this means through Partner Center. If a customer has more than one Azure Active Directory tenant, this subscription must be created in the tenant that will be used to log into Azure Stack. The customer subscription ID must use lowercase letters. |
71
+
| resourceGroup | The resource group in Azure in which your registration is stored. |
72
72
| registrationName | The name of the registration of your Azure Stack. It is an object stored in Azure. |
73
73
| Properties | Specifies properties for the resource. Use this parameter to specify the values of properties that are specific to the resource type.
0 commit comments