Skip to content

Commit c980132

Browse files
authored
Merge branch 'MicrosoftDocs:main' into main
2 parents 6874333 + e9fa402 commit c980132

9 files changed

+97
-42
lines changed

articles/azure-monitor/app/availability-azure-functions.md

Lines changed: 23 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -13,12 +13,12 @@ This article explains how to review [TrackAvailability()](/dotnet/api/microsoft.
1313

1414
> [!div class="checklist"]
1515
> - [Workspace-based Application Insights resource](create-workspace-resource.md)
16-
> - Access to the source code of a [function app](../../azure-functions/functions-how-to-use-azure-function-app-settings.md) in Azure Functions.
17-
> - Developer expertise capable of authoring custom code for [TrackAvailability()](/dotnet/api/microsoft.applicationinsights.telemetryclient.trackavailability), tailored to your specific business needs
16+
> - Access to the source code of a [function app](../../azure-functions/functions-how-to-use-azure-function-app-settings.md) in Azure Functions
17+
> - Developer expertise capable of authoring [custom code](#basic-code-sample) for [TrackAvailability()](/dotnet/api/microsoft.applicationinsights.telemetryclient.trackavailability), tailored to your specific business needs
1818
1919
> [!NOTE]
20-
> - TrackAvailability() requires that you have made a developer investment in custom code.
21-
> - [Standard tests](availability-standard-tests.md) should always be used if possible as they require little investment and have few prerequisites.
20+
> - [TrackAvailability()](/dotnet/api/microsoft.applicationinsights.telemetryclient.trackavailability) requires that you make a developer investment in custom code.
21+
> - [Standard tests](availability-standard-tests.md) **should always be used if possible** as they require little investment, no maintenance, and have few prerequisites.
2222
2323
## Check availability
2424

@@ -43,6 +43,25 @@ You can use Log Analytics to view your availability results, dependencies, and m
4343

4444
:::image type="content" source="media/availability-azure-functions/dependencies.png" alt-text="Screenshot that shows the New Query tab with dependencies limited to 50." lightbox="media/availability-azure-functions/dependencies.png":::
4545

46+
## Basic code sample
47+
48+
The following example demonstrates a web availability test that requires a simple URL ping using the `getStringAsync()` method.
49+
50+
```csharp
51+
using System.Net.Http;
52+
53+
public async static Task RunAvailabilityTestAsync(ILogger log)
54+
{
55+
using (var httpClient = new HttpClient())
56+
{
57+
// TODO: Replace with your business logic
58+
await httpClient.GetStringAsync("https://www.bing.com/");
59+
}
60+
}
61+
```
62+
63+
For advanced scenarios where the business logic must be adjusted to access the URL, such as obtaining tokens, setting parameters, and other test cases, custom code is necessary.
64+
4665
## Next steps
4766

4867
* [Standard tests](availability-standard-tests.md)

articles/key-vault/general/best-practices.md

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -30,10 +30,10 @@ Encryption keys and secrets like certificates, connection strings, and passwords
3030

3131
Recommendations for controlling access to your vault are as follows:
3232
- Lock down access to your subscription, resource group, and key vaults using role-based access control (RBAC).
33-
- Assign RBAC roles at Key Vault scope for applications, services, and workloads requiring persistent access to Key Vault
34-
- Assign just-in-time eligible RBAC roles for operators, administrators and other user accounts requiring privileged access to Key Vault using [Privileged Identity Management (PIM)](../../active-directory/privileged-identity-management/pim-configure.md)
35-
- Require at least one approver
36-
- Enforce multi-factor authentication
33+
- Assign RBAC roles at Key Vault scope for applications, services, and workloads requiring persistent access to Key Vault
34+
- Assign just-in-time eligible RBAC roles for operators, administrators and other user accounts requiring privileged access to Key Vault using [Privileged Identity Management (PIM)](../../active-directory/privileged-identity-management/pim-configure.md)
35+
- Require at least one approver
36+
- Enforce multi-factor authentication
3737
- Restrict network access with [Private Link](private-link-service.md), [firewall and virtual networks](network-security.md)
3838

3939
## Turn on data protection for your vault

articles/logic-apps/logic-apps-using-sap-connector.md

Lines changed: 6 additions & 15 deletions
Original file line numberDiff line numberDiff line change
@@ -127,13 +127,6 @@ Along with simple string and number inputs, the SAP connector accepts the follow
127127
1. In the action named **\[BAPI] Call method in SAP**, disable the auto-commit feature.
128128
1. Call the action named **\[BAPI] Commit transaction** instead.
129129

130-
### SAP built-in connector
131-
132-
The SAP built-in connector trigger named **Register SAP RFC server for trigger** is available in the Azure portal, but the trigger currently can't receive calls from SAP when deployed in Azure. To fire the trigger, you can run the workflow locally in Visual Studio Code. For Visual Studio Code setup requirements and more information, see [Create a Standard logic app workflow in single-tenant Azure Logic Apps using Visual Studio Code](create-single-tenant-workflows-visual-studio-code.md). You must also set up the following environment variables on the computer where you install Visual Studio Code:
133-
134-
- **WEBSITE_PRIVATE_IP**: Set this environment variable value to **127.0.0.1** as the localhost address.
135-
- **WEBSITE_PRIVATE_PORTS**: Set this environment variable value to two free and usable ports on your local computer, separating the values with a comma (**,**), for example, **8080,8088**.
136-
137130
## Prerequisites
138131

139132
* An Azure account and subscription. If you don't have an Azure subscription yet, [sign up for a free Azure account](https://azure.microsoft.com/free/?WT.mc_id=A261C142F).
@@ -206,6 +199,11 @@ The SAP built-in connector trigger named **Register SAP RFC server for trigger**
206199
> In Standard workflows, the SAP built-in trigger named **Register SAP RFC server for trigger** uses the Azure
207200
> Functions trigger instead, and shows only the actual callbacks from SAP.
208201
202+
* For the SAP built-in connector trigger named **Register SAP RFC server for trigger**, you have to enable virtual network integration and private ports by following the article at [Enabling Service Bus and SAP built-in connectors for stateful Logic Apps in Standard](https://techcommunity.microsoft.com/t5/integrations-on-azure-blog/enabling-service-bus-and-sap-built-in-connectors-for-stateful/ba-p/3820381). You can also run the workflow in Visual Studio Code to fire the trigger locally. For Visual Studio Code setup requirements and more information, see [Create a Standard logic app workflow in single-tenant Azure Logic Apps using Visual Studio Code](create-single-tenant-workflows-visual-studio-code.md). You must also set up the following environment variables on the computer where you install Visual Studio Code:
203+
204+
- **WEBSITE_PRIVATE_IP**: Set this environment variable value to **127.0.0.1** as the localhost address.
205+
- **WEBSITE_PRIVATE_PORTS**: Set this environment variable value to two free and usable ports on your local computer, separating the values with a comma (**,**), for example, **8080,8088**.
206+
209207
* The message content to send to your SAP server, such as a sample IDoc file. This content must be in XML format and include the namespace of the [SAP action](/connectors/sap/#actions) that you want to use. You can [send IDocs with a flat file schema by wrapping them in an XML envelope](sap-create-example-scenario-workflows.md#send-flat-file-idocs).
210208

211209
<a name="network-prerequisites"></a>
@@ -536,7 +534,7 @@ For a Consumption workflow in multi-tenant Azure Logic Apps, the SAP managed con
536534
537535
<a name="single-tenant-prerequisites"></a>
538536
539-
For a Standard workflow in single-tenant Azure Logic Apps, use the SAP *built-in* connector to directly access resources that are protected by an Azure virtual network. You can also use other built-in connectors that let workflows directly access on-premises resources without having to use the on-premises data gateway.
537+
For a Standard workflow in single-tenant Azure Logic Apps, use the SAP *built-in* connector to directly access resources that are protected by an Azure virtual network. You can also use other built-in connectors that let workflows directly access on-premises resources without having to use the on-premises data gateway. For additional requirements regarding the SAP built-in connector trigger named **Register SAP RFC server for trigger**, see [Prerequisites](#prerequisites).
540538
541539
1. To use the SAP connector, you need to download the following files and have them read to upload to your Standard logic app resource. For more information, see [SAP NCo client library prerequisites](#sap-client-library-prerequisites):
542540
@@ -590,13 +588,6 @@ For a Standard workflow in single-tenant Azure Logic Apps, use the SAP *built-in
590588
591589
1. In the **net472** folder, upload the assembly files larger than 4 MB.
592590
593-
#### SAP trigger requirements
594-
595-
The SAP built-in connector trigger named **Register SAP RFC server for trigger** is available in the Azure portal, but the trigger currently can't receive calls from SAP when deployed in Azure. To fire the trigger, you can run the workflow locally in Visual Studio Code. For Visual Studio Code setup requirements and more information, see [Create a Standard logic app workflow in single-tenant Azure Logic Apps using Visual Studio Code](create-single-tenant-workflows-visual-studio-code.md). You must also set up the following environment variables on the computer where you install Visual Studio Code:
596-
597-
- **WEBSITE_PRIVATE_IP**: Set this environment variable value to **127.0.0.1** as the localhost address.
598-
- **WEBSITE_PRIVATE_PORTS**: Set this environment variable value to two free and usable ports on your local computer, separating the values with a comma (**,**), for example, **8080,8088**.
599-
600591
### [ISE](#tab/ise)
601592
602593
<a name="ise-prerequisites"></a>

articles/role-based-access-control/built-in-roles.md

Lines changed: 45 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -29,6 +29,7 @@ The following table provides a brief description of each built-in role. Click th
2929
> | [Contributor](#contributor) | Grants full access to manage all resources, but does not allow you to assign roles in Azure RBAC, manage assignments in Azure Blueprints, or share image galleries. | b24988ac-6180-42a0-ab88-20f7382dd24c |
3030
> | [Owner](#owner) | Grants full access to manage all resources, including the ability to assign roles in Azure RBAC. | 8e3af657-a8ff-443c-a75c-2fe8c4bcb635 |
3131
> | [Reader](#reader) | View all resources, but does not allow you to make any changes. | acdd72a7-3385-48ef-bd42-f606fba81ae7 |
32+
> | [Role Based Access Control Administrator (Preview)](#role-based-access-control-administrator-preview) | Manage access to Azure resources by assigning roles using Azure RBAC. This role does not allow you to manage access using other ways, such as Azure Policy. | f58310d9-a9f6-439a-9e8d-f62e7b41a168 |
3233
> | [User Access Administrator](#user-access-administrator) | Lets you manage user access to Azure resources. | 18d7d88d-d35e-4fb5-a5c3-7773c20a72d9 |
3334
> | **Compute** | | |
3435
> | [Classic Virtual Machine Contributor](#classic-virtual-machine-contributor) | Lets you manage classic virtual machines, but not access to them, and not the virtual network or storage account they're connected to. | d73bb868-a0df-4d4d-bd69-98a00b01fccb |
@@ -461,6 +462,50 @@ View all resources, but does not allow you to make any changes. [Learn more](rba
461462
"type": "Microsoft.Authorization/roleDefinitions"
462463
}
463464
```
465+
### Role Based Access Control Administrator (Preview)
466+
467+
Manage access to Azure resources by assigning roles using Azure RBAC. This role does not allow you to manage access using other ways, such as Azure Policy.
468+
469+
> [!div class="mx-tableFixed"]
470+
> | Actions | Description |
471+
> | --- | --- |
472+
> | [Microsoft.Authorization](resource-provider-operations.md#microsoftauthorization)/roleAssignments/write | Create a role assignment at the specified scope. |
473+
> | [Microsoft.Authorization](resource-provider-operations.md#microsoftauthorization)/roleAssignments/delete | Delete a role assignment at the specified scope. |
474+
> | */read | Read resources of all types, except secrets. |
475+
> | [Microsoft.Support](resource-provider-operations.md#microsoftsupport)/* | Create and update a support ticket |
476+
> | **NotActions** | |
477+
> | *none* | |
478+
> | **DataActions** | |
479+
> | *none* | |
480+
> | **NotDataActions** | |
481+
> | *none* | |
482+
483+
```json
484+
{
485+
"assignableScopes": [
486+
"/"
487+
],
488+
"description": "Manage access to Azure resources by assigning roles using Azure RBAC. This role does not allow you to manage access using other ways, such as Azure Policy.",
489+
"id": "/providers/Microsoft.Authorization/roleDefinitions/f58310d9-a9f6-439a-9e8d-f62e7b41a168",
490+
"name": "f58310d9-a9f6-439a-9e8d-f62e7b41a168",
491+
"permissions": [
492+
{
493+
"actions": [
494+
"Microsoft.Authorization/roleAssignments/write",
495+
"Microsoft.Authorization/roleAssignments/delete",
496+
"*/read",
497+
"Microsoft.Support/*"
498+
],
499+
"notActions": [],
500+
"dataActions": [],
501+
"notDataActions": []
502+
}
503+
],
504+
"roleName": "Role Based Access Control Administrator (Preview)",
505+
"roleType": "BuiltInRole",
506+
"type": "Microsoft.Authorization/roleDefinitions"
507+
}
508+
```
464509

465510
### User Access Administrator
466511

articles/spring-apps/quickstart-configure-single-sign-on-enterprise.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -182,7 +182,7 @@ To complete the single sign-on experience, use the following steps to deploy the
182182
--name identity-routes \
183183
--service <Azure-Spring-Apps-service-instance-name> \
184184
--app-name identity-service \
185-
--routes-file azure/routes/identity-service.json
185+
--routes-file azure-spring-apps-enterprise/resources/json/routes/identity-service.json
186186
```
187187

188188
## Configure single sign-on for Spring Cloud Gateway

articles/spring-apps/quickstart-deploy-apps-enterprise.md

Lines changed: 5 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -240,7 +240,7 @@ Use the following steps to deploy and build applications. For these steps, make
240240
--resource-group <resource-group-name> \
241241
--name quickstart-builder \
242242
--service <Azure-Spring-Apps-service-instance-name> \
243-
--builder-file azure/builder.json
243+
--builder-file azure-spring-apps-enterprise/resources/json/tbs/builder.json
244244
```
245245

246246
1. Use the following command to build and deploy the payment service:
@@ -343,7 +343,7 @@ Use the following steps to configure Spring Cloud Gateway and configure routes t
343343
--name cart-routes \
344344
--service <Azure-Spring-Apps-service-instance-name> \
345345
--app-name cart-service \
346-
--routes-file azure/routes/cart-service.json
346+
--routes-file azure-spring-apps-enterprise/resources/json/routes/cart-service.json
347347
```
348348

349349
1. Use the following command to create routes for the order service:
@@ -354,7 +354,7 @@ Use the following steps to configure Spring Cloud Gateway and configure routes t
354354
--name order-routes \
355355
--service <Azure-Spring-Apps-service-instance-name> \
356356
--app-name order-service \
357-
--routes-file azure/routes/order-service.json
357+
--routes-file azure-spring-apps-enterprise/resources/json/routes/order-service.json
358358
```
359359

360360
1. Use the following command to create routes for the catalog service:
@@ -365,7 +365,7 @@ Use the following steps to configure Spring Cloud Gateway and configure routes t
365365
--name catalog-routes \
366366
--service <Azure-Spring-Apps-service-instance-name> \
367367
--app-name catalog-service \
368-
--routes-file azure/routes/catalog-service.json
368+
--routes-file azure-spring-apps-enterprise/resources/json/routes/catalog-service.json
369369
```
370370

371371
1. Use the following command to create routes for the frontend:
@@ -376,7 +376,7 @@ Use the following steps to configure Spring Cloud Gateway and configure routes t
376376
--name frontend-routes \
377377
--service <Azure-Spring-Apps-service-instance-name> \
378378
--app-name frontend \
379-
--routes-file azure/routes/frontend.json
379+
--routes-file azure-spring-apps-enterprise/resources/json/routes/frontend.json
380380
```
381381

382382
1. Use the following commands to retrieve the URL for Spring Cloud Gateway:

articles/spring-apps/quickstart-integrate-azure-database-and-redis-enterprise.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -110,13 +110,13 @@ The following instructions describe how to provision an Azure Cache for Redis an
110110

111111
[!INCLUDE [About Azure Resource Manager](../../includes/resource-manager-quickstart-introduction.md)]
112112

113-
You can find the template used in this quickstart in the [fitness store sample GitHub repository](https://github.com/Azure-Samples/acme-fitness-store/blob/Azure/azure/templates/azuredeploy.json).
113+
You can find the template used in this quickstart in the [fitness store sample GitHub repository](https://github.com/Azure-Samples/acme-fitness-store/blob/Azure/azure-spring-apps-enterprise/resources/json/deploy/azuredeploy.json).
114114

115115
To deploy this template, follow these steps:
116116

117117
1. Select the following image to sign in to Azure and open a template. The template creates an Azure Cache for Redis and an Azure Database for PostgreSQL Flexible Server.
118118

119-
:::image type="content" source="../media/template-deployments/deploy-to-azure.svg" alt-text="Button to deploy the ARM template to Azure." border="false" link="https://portal.azure.com/#create/Microsoft.Template/uri/https%3A%2F%2Fraw.githubusercontent.com%2FAzure-Samples%2Facme-fitness-store%2FAzure%2Fazure%2Ftemplates%2Fazuredeploy.json":::
119+
:::image type="content" source="../media/template-deployments/deploy-to-azure.svg" alt-text="Button to deploy the ARM template to Azure." border="false" link="https://portal.azure.com/#create/Microsoft.Template/uri/https%3A%2F%2Fraw.githubusercontent.com%2FAzure-Samples%2Facme-fitness-store%2FAzure%2Fazure-spring-apps-enterprise%2Fresources%2Fjson%2Fdeploy%2Fazuredeploy.json":::
120120

121121
1. Enter values for the following fields:
122122

articles/spring-apps/quickstart-set-request-rate-limits-enterprise.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -82,7 +82,7 @@ az spring gateway route-config update \
8282
--service <Azure-Spring-Apps-service-instance-name> \
8383
--name catalog-routes \
8484
--app-name catalog-service \
85-
--routes-file azure/routes/catalog-service_rate-limit.json
85+
--routes-file azure-spring-apps-enterprise/resources/json/routes/catalog-service_rate-limit.json
8686
```
8787

8888
Use the following commands to retrieve the URL for the `/products` route in Spring Cloud Gateway:

0 commit comments

Comments
 (0)