Skip to content

Commit d29e7d0

Browse files
authored
Merge pull request #101502 from MicrosoftDocs/master
Merge Master to Live, 3 AM
2 parents 276c1c7 + 01addb4 commit d29e7d0

File tree

192 files changed

+2225
-1718
lines changed

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

192 files changed

+2225
-1718
lines changed

.openpublishing.redirection.json

Lines changed: 26 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -39782,9 +39782,29 @@
3978239782
},
3978339783
{
3978439784
"source_path": "articles/application-insights/app-insights-troubleshoot-faq.md",
39785-
"redirect_url": "/azure/azure-monitor/app/troubleshoot-faq",
39785+
"redirect_url": "/azure/azure-monitor/faq",
3978639786
"redirect_document_id": true
3978739787
},
39788+
{
39789+
"source_path": "articles/azure-monitor/app/troubleshoot-faq.md",
39790+
"redirect_url": "/azure/azure-monitor/faq",
39791+
"redirect_document_id": false
39792+
},
39793+
{
39794+
"source_path": "articles/azure-monitor/platform/log-faq.md",
39795+
"redirect_url": "/azure/azure-monitor/faq",
39796+
"redirect_document_id": false
39797+
},
39798+
{
39799+
"source_path": "articles/azure-monitor/insights/container-insights-faq.md",
39800+
"redirect_url": "/azure/azure-monitor/faq",
39801+
"redirect_document_id": false
39802+
},
39803+
{
39804+
"source_path": "articles/azure-monitor/insights/vminsights-faq.md",
39805+
"redirect_url": "/azure/azure-monitor/faq",
39806+
"redirect_document_id": false
39807+
},
3978839808
{
3978939809
"source_path": "articles/application-insights/app-insights-usage-cohorts.md",
3979039810
"redirect_url": "/azure/azure-monitor/app/usage-cohorts",
@@ -41085,6 +41105,11 @@
4108541105
"redirect_url": "/azure/hdinsight/hadoop/apache-hadoop-use-pig-ssh",
4108641106
"redirect_document_id": false
4108741107
},
41108+
{
41109+
"source_path": "articles/cognitive-services/LUIS/sdk-csharp-3x.md",
41110+
"redirect_url": "/azure/cognitive-services/LUIS/sdk-authoring.md",
41111+
"redirect_document_id": true
41112+
},
4108841113
{
4108941114
"source_path": "articles/cognitive-services/LUIS/luis-reference-faq.md",
4109041115
"redirect_url": "/azure/cognitive-services/LUIS/troubleshooting",

articles/active-directory/cloud-provisioning/what-is-provisioning.md

Lines changed: 2 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -45,9 +45,7 @@ The most common scenario would be, when a new employee joins your company, they
4545

4646
![cloud provisioning](media/what-is-provisioning/cloud3.png)
4747

48-
App provisioning involves the provisioning of users and roles in the applications the user needs access to.
49-
50-
The most common scenario would be, when a user in Azure AD is provisioned into O365 or Salesforce.
48+
In Azure Active Directory (Azure AD), the term **[app provisioning](https://docs.microsoft.com/azure/active-directory/manage-apps/user-provisioning)** refers to automatically creating user identities and roles in the cloud applications that users need access to. In addition to creating user identities, automatic provisioning includes the maintenance and removal of user identities as status or roles change. Common scenarios include provisioning an Azure AD user into applications like [Dropbox](https://docs.microsoft.com/azure/active-directory/saas-apps/dropboxforbusiness-provisioning-tutorial), [Salesforce](https://docs.microsoft.com/azure/active-directory/saas-apps/salesforce-provisioning-tutorial), [ServiceNow](https://docs.microsoft.com/azure/active-directory/saas-apps/servicenow-provisioning-tutorial), and more.
5149

5250
## Directory provisioning
5351

@@ -62,4 +60,4 @@ This has been accomplished by Azure AD Connect sync, Azure AD Connect cloud prov
6260
## Next steps
6361

6462
- [What is Azure AD Connect cloud provisioning?](what-is-cloud-provisioning.md)
65-
- [Install cloud provisioning](how-to-install.md)
63+
- [Install cloud provisioning](how-to-install.md)

articles/active-directory/conditional-access/TOC.yml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -19,6 +19,8 @@
1919
href: concept-conditional-access-policy-common.md
2020
- name: Conditional Access policy components
2121
href: concept-conditional-access-policies.md
22+
- name: Cloud apps and actions
23+
href: concept-conditional-access-cloud-apps.md
2224
- name: Conditions
2325
href: conditions.md
2426
- name: Location conditions
Lines changed: 126 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,126 @@
1+
---
2+
title: Client apps in Conditional Access policy - Azure Active Directory
3+
description:
4+
5+
services: active-directory
6+
ms.service: active-directory
7+
ms.subservice: conditional-access
8+
ms.topic: conceptual
9+
ms.date: 01/10/2020
10+
11+
ms.author: joflore
12+
author: MicrosoftGuyJFlo
13+
manager: daveba
14+
ms.reviewer: calebb
15+
16+
ms.collection: M365-identity-device-management
17+
---
18+
# Conditional Access: Cloud apps and actions
19+
20+
Cloud apps or actions is a key part of a Conditional Access policy. Conditional Access policies allow administrators to assign controls to specific applications or actions.
21+
22+
- Administrators can choose from the list of applications that include built-in Microsoft applications and any [Azure AD integrated applications](../manage-apps/what-is-application-management.md) including gallery, non-gallery, and applications published through [Application Proxy](../manage-apps/what-is-application-proxy.md).
23+
- Administrators may choose to define policy not based on a cloud application but on a user action. The only supported action is Register security information (preview), allowing Conditional Access to enforce controls around the [combined security information registration experience](../authentication/howto-registration-mfa-sspr-combined.md).
24+
25+
![Define a Conditional Access policy and specify cloud apps](./media/concept-conditional-access-cloud-apps/conditional-access-define-policy-specify-cloud-apps.png)
26+
27+
## Microsoft cloud applications
28+
29+
Many of the existing Microsoft cloud applications are included in the list of applications you can select from.
30+
31+
Administrators can assign a Conditional Access policy to the following cloud apps from Microsoft. Some apps like the Office 365 (preview) and Microsoft Azure Management include multiple related child apps or services. The following list is not exhaustive and is subject to change.
32+
33+
- [Office 365 (preview)](#office-365-preview)
34+
- Azure Analysis Services
35+
- Azure DevOps
36+
- [Azure SQL Database and Data Warehouse](../../sql-database/sql-database-conditional-access.md)
37+
- Dynamics CRM Online
38+
- Microsoft Application Insights Analytics
39+
- [Microsoft Azure Information Protection](https://docs.microsoft.com/azure/information-protection/faqs#i-see-azure-information-protection-is-listed-as-an-available-cloud-app-for-conditional-accesshow-does-this-work)
40+
- [Microsoft Azure Management](#microsoft-azure-management)
41+
- Microsoft Azure Subscription Management
42+
- Microsoft Cloud App Security
43+
- Microsoft Commerce Tools Access Control Portal
44+
- Microsoft Commerce Tools Authentication Service
45+
- Microsoft Flow
46+
- Microsoft Forms
47+
- Microsoft Intune
48+
- [Microsoft Intune Enrollment](https://docs.microsoft.com/intune/enrollment/multi-factor-authentication)
49+
- Microsoft Planner
50+
- Microsoft PowerApps
51+
- Microsoft Search in Bing
52+
- Microsoft StaffHub
53+
- Microsoft Stream
54+
- Microsoft Teams
55+
- Office 365 Exchange Online
56+
- Office 365 SharePoint Online
57+
- Office 365 Yammer
58+
- Office Delve
59+
- Office Sway
60+
- Outlook Groups
61+
- Power BI Service
62+
- Project Online
63+
- Skype for Business Online
64+
- Virtual Private Network (VPN)
65+
- Windows Defender ATP
66+
67+
### Office 365 (preview)
68+
69+
Office 365 provides cloud-based productivity and collaboration services like Exchange, SharePoint, and Microsoft Teams. Office 365 cloud services are deeply integrated to ensure smooth and collaborative experiences. This integration can cause confusion when creating policies as some apps such as Microsoft Teams have dependencies on others such as SharePoint or Exchange.
70+
71+
The Office 365 (preview) app makes it possible to target these services all at once. We recommend using the new Office 365 (preview) app, instead of targeting individual cloud apps. Targeting this group of applications helps to avoid issues that may arise due to inconsistent policies and dependencies.
72+
73+
Administrators can choose to exclude specific apps from policy if they wish by including the Office 365 (preview) app and excluding the specific apps of their choice in policy.
74+
75+
Key applications that are included in the Office 365 (preview) client app:
76+
77+
- Microsoft Flow
78+
- Microsoft Forms
79+
- Microsoft Office 365 Portal
80+
- Microsoft Stream
81+
- Microsoft To-Do
82+
- Microsoft Teams
83+
- Office 365 Exchange Online
84+
- Office 365 SharePoint Online
85+
- Office 365 Search Service
86+
- Office 365 Yammer
87+
- Office Delve
88+
- Office Online
89+
- OneDrive
90+
- PowerApps
91+
- Skype for Business Online
92+
- Sway
93+
94+
### Microsoft Azure Management
95+
96+
The Microsoft Azure Management application includes multiple underlying services.
97+
98+
- Azure portal
99+
- Azure Resource Manager provider
100+
- Classic deployment model APIs
101+
- Azure PowerShell
102+
- Visual Studio subscriptions administrator portal
103+
- Azure DevOps
104+
- Azure Data Factory portal
105+
106+
> [!NOTE]
107+
> The Microsoft Azure Management application applies to Azure PowerShell, which calls the Azure Resource Manager API. It does not apply to Azure AD PowerShell, which calls Microsoft Graph.
108+
109+
## Other applications
110+
111+
In addition to the Microsoft apps, administrators can add any Azure AD registered application to Conditional Access policies. These applications may include:
112+
113+
- Applications published through [Azure AD Application Proxy](../manage-apps/what-is-application-proxy.md)
114+
- [Applications added from the gallery](../manage-apps/add-application-portal.md)
115+
- [Custom applications not in the gallery](../manage-apps/add-non-gallery-app.md)
116+
- [Legacy applications published through app delivery controllers and networks](../manage-apps/secure-hybrid-access.md)
117+
118+
## User actions
119+
120+
User actions are tasks that can be performed by a user. The only currently supported action is **Register security information (preview)**, which allows Conditional Access policy to enforce when users who are enabled for combined registration attempt to register their security information. More information can be found in the article, [Combined security information registration (preview)](../authentication/concept-registration-mfa-sspr-combined.md).
121+
122+
## Next steps
123+
124+
- [Conditional Access policy components](concept-conditional-access-policies.md)
125+
- [Client application dependencies](service-dependencies.md)
126+
- [Microsoft Intune: Require MFA for device enrollment](https://docs.microsoft.com/intune/enrollment/multi-factor-authentication)
Loading

articles/active-directory/develop/id-tokens.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -9,7 +9,7 @@ ms.service: active-directory
99
ms.subservice: develop
1010
ms.workload: identity
1111
ms.topic: conceptual
12-
ms.date: 08/27/2019
12+
ms.date: 01/16/2020
1313
ms.author: ryanwi
1414
ms.reviewer: hirsin
1515
ms.custom: aaddev, identityplatformtop40
@@ -78,7 +78,7 @@ This list shows the claims that are in most id_tokens by default (except where n
7878
|`rh` | Opaque String |An internal claim used by Azure to revalidate tokens. Should be ignored. |
7979
|`sub` | String, a GUID | The principal about which the token asserts information, such as the user of an app. This value is immutable and cannot be reassigned or reused. The subject is a pairwise identifier - it is unique to a particular application ID. If a single user signs into two different apps using two different client IDs, those apps will receive two different values for the subject claim. This may or may not be wanted depending on your architecture and privacy requirements. |
8080
|`tid` | String, a GUID | A GUID that represents the Azure AD tenant that the user is from. For work and school accounts, the GUID is the immutable tenant ID of the organization that the user belongs to. For personal accounts, the value is `9188040d-6c67-4c5b-b112-36a304b66dad`. The `profile` scope is required to receive this claim. |
81-
|`unique_name` | String | Provides a human readable value that identifies the subject of the token. This value isn't guaranteed to be unique within a tenant and should be used only for display purposes. Only issued in v1.0 `id_tokens`. |
81+
|`unique_name` | String | Provides a human readable value that identifies the subject of the token. This value is unique at any given point in time, but as emails and other identifiers can be reused, this value can reappear on other accounts, and should therefore be used only for display purposes. Only issued in v1.0 `id_tokens`. |
8282
|`uti` | Opaque String | An internal claim used by Azure to revalidate tokens. Should be ignored. |
8383
|`ver` | String, either 1.0 or 2.0 | Indicates the version of the id_token. |
8484

articles/active-directory/devices/hybrid-azuread-join-federated-domains.md

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -155,6 +155,9 @@ If some of your domain-joined devices are Windows downlevel devices, you must:
155155
- Configure the local intranet settings for device registration
156156
- Install Microsoft Workplace Join for Windows downlevel computers
157157

158+
> [!NOTE]
159+
> Windows 7 support ended on January 14, 2020. For more information, [Support for Windows 7 has ended](https://support.microsoft.com/en-us/help/4057281/windows-7-support-ended-on-january-14-2020).
160+
158161
### Configure the local intranet settings for device registration
159162

160163
To successfully complete hybrid Azure AD join of your Windows downlevel devices and to avoid certificate prompts when devices authenticate to Azure AD, you can push a policy to your domain-joined devices to add the following URLs to the local intranet zone in Internet Explorer:

articles/active-directory/devices/hybrid-azuread-join-managed-domains.md

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -133,6 +133,9 @@ If some of your domain-joined devices are Windows downlevel devices, you must:
133133
- Configure seamless SSO
134134
- Install Microsoft Workplace Join for Windows downlevel computers
135135

136+
> [!NOTE]
137+
> Windows 7 support ended on January 14, 2020. For more information, [Support for Windows 7 has ended](https://support.microsoft.com/en-us/help/4057281/windows-7-support-ended-on-january-14-2020).
138+
136139
### Configure the local intranet settings for device registration
137140

138141
To successfully complete hybrid Azure AD join of your Windows downlevel devices and to avoid certificate prompts when devices authenticate to Azure AD, you can push a policy to your domain-joined devices to add the following URLs to the local intranet zone in Internet Explorer:

articles/active-directory/devices/hybrid-azuread-join-plan.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -61,7 +61,7 @@ For devices running the Windows desktop operating system, supported version are
6161
### Windows down-level devices
6262

6363
- Windows 8.1
64-
- Windows 7. For support information on Windows 7, see [Support for Windows 7 is ending](https://www.microsoft.com/microsoft-365/windows/end-of-windows-7-support).
64+
- Windows 7 support ended on January 14, 2020. For more information, see [Support for Windows 7 has ended](https://support.microsoft.com/en-us/help/4057281/windows-7-support-ended-on-january-14-2020).
6565
- Windows Server 2012 R2
6666
- Windows Server 2012
6767
- Windows Server 2008 R2. For support information on Windows Server 2008 and 2008 R2, see [Prepare for Windows Server 2008 end of support](https://www.microsoft.com/cloud-platform/windows-server-2008).

0 commit comments

Comments
 (0)