Skip to content

Commit d2cd670

Browse files
committed
Merge branch 'master' of https://github.com/MicrosoftDocs/azure-docs-pr into migration
2 parents 840bde5 + 14eab46 commit d2cd670

File tree

68 files changed

+430
-154
lines changed

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

68 files changed

+430
-154
lines changed

articles/active-directory/develop/msal-net-use-brokers-with-xamarin-apps.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -180,7 +180,7 @@ The portal has a new experience app registration portal to help you compute the
180180

181181
MSAL.NET only support the Xamarin.iOS platform at the moment. It doesn't yet support brokers for the Xamarin.Android platform.
182182

183-
The MSAL Android native library already supports it. For details see [Brokered auth in Android](https://docs.microsoft.com/azure/active-directory/develop/brokered-auth.md)
183+
The MSAL Android native library already supports it. For details see [Brokered auth in Android](brokered-auth.md)
184184

185185
## Next steps
186186

articles/active-directory/governance/entitlement-management-access-package-assignments.md

Lines changed: 18 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -75,6 +75,24 @@ In some cases, you might want to directly assign specific users to an access pac
7575

7676
After a few moments, click **Refresh** to see the users in the Assignments list.
7777

78+
## Remove an assignment
79+
80+
**Prerequisite role:** Global administrator, User administrator, Catalog owner, or Access package manager
81+
82+
1. In the Azure portal, click **Azure Active Directory** and then click **Identity Governance**.
83+
84+
1. In the left menu, click **Access packages** and then open the access package.
85+
86+
1. In the left menu, click **Assignments**.
87+
88+
1. Click the check box next to the user whose assignment you want to remove from the access package.
89+
90+
1. Click the **Remove** button near the top of the left pane.
91+
92+
![Assignments - Remove user from access package](./media/entitlement-management-access-package-assignments/remove-assignment-select-remove-assignment.png)
93+
94+
A notification will appear informing you that the assignment has been removed.
95+
7896
## Next steps
7997

8098
- [Change request and settings for an access package](entitlement-management-access-package-request-policy.md)

articles/active-directory/governance/entitlement-management-request-access.md

Lines changed: 24 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -79,6 +79,30 @@ If you request access to an access package that has multiple policies that apply
7979

8080
![My Access portal - Request access - multiple policies](./media/entitlement-management-request-access/my-access-multiple-policies.png)
8181

82+
## Resubmit a request
83+
84+
When you request access to an access package, your request might be denied or your request might expire if approvers don't respond in time. If you need access, you can try again and resubmit your request. The following procedure explains how to resubmit an access request:
85+
86+
**Prerequisite role:** Requestor
87+
88+
1. Sign in to the **My Access** portal.
89+
90+
1. Click **Request history** from the navigation menu to the left.
91+
92+
1. Find the access package for which you are resubmitting a request.
93+
94+
1. Click the check mark to select the access package.
95+
96+
1. Click the blue **View** link to the right of the selected access package.
97+
98+
![Select access package and view link](./media/entitlement-management-request-access/resubmit-request-select-request-and-view.png)
99+
100+
A pane will open to the right with the request history for the access package.
101+
102+
![Select resubmit button](./media/entitlement-management-request-access/resubmit-request-select-resubmit.png)
103+
104+
1. Click the **Resubmit** button at the bottom of the pane.
105+
82106
## Cancel a request
83107

84108
If you submit an access request and the request is still in the **pending approval** state, you can cancel the request.
Loading
Loading
Loading

articles/active-directory/manage-apps/configure-automatic-user-provisioning-portal.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -81,4 +81,4 @@ If provisioning is being enabled for the first time for an application, turn on
8181

8282
Change the **Provisioning Status** to **Off** to pause the provisioning service. In this state, Azure doesn't create, update, or remove any user or group objects in the app. Change the state back to **On** and the service picks up where it left off.
8383

84-
**Clear current state and restart synchronization** triggers an initial cycle. The service will then evaluate all the users in the source system again and determine if they are in scope for provisioning. This can be useful when your application is currently in quarantine or you need to make a change to your attribute mappings. This should not be used to trigger a delete or disable request as these events can be dropped when triggering a clear state and restart. The initial cycle also takes longer to complete than the typical incremental cycle due to the number of objects that need to be evaluated. You can learn more about the performance of initial and incremental cycles [here.](https://docs.microsoft.com/azure/active-directory/manage-apps/application-provisioning-when-will-provisioning-finish-specific-user).
84+
**Clear current state and restart synchronization** triggers an initial cycle. The service will then evaluate all the users in the source system again and determine if they are in scope for provisioning. This can be useful when your application is currently in quarantine or you need to make a change to your attribute mappings. Note that the initial cycle takes longer to complete than the typical incremental cycle due to the number of objects that need to be evaluated. You can learn more about the performance of initial and incremental cycles [here.](https://docs.microsoft.com/azure/active-directory/manage-apps/application-provisioning-when-will-provisioning-finish-specific-user).

articles/active-directory/users-groups-roles/directory-assign-admin-roles.md

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -181,7 +181,7 @@ This role is available for assignment only as an additional local administrator
181181

182182
Users in this role can read basic directory information. This role should be used for:
183183
* Granting a specific set of guest users read access instead of granting it to all guest users.
184-
* Granting a specific set of non-admin users access to Azure Portal when “Restrict access to Azure AD portal to admins only” is set to “Yes”.
184+
* Granting a specific set of non-admin users access to Azure portal when “Restrict access to Azure AD portal to admins only” is set to “Yes”.
185185
* Granting service principals access to directory where Directory.Read.All is not an option.
186186

187187
### [Directory Synchronization Accounts](#directory-synchronization-accounts-permissions)
@@ -234,7 +234,7 @@ Users in this role can read settings and administrative information across Micro
234234
>- [Azure AD portal](https://portal.azure.com/#blade/Microsoft_AAD_IAM/StartboardApplicationsMenuBlade/AllApps/menuId/) - Global reader can't read the provisioning mode of an enterprise app.
235235
>- [M365 admin center](https://admin.microsoft.com/Adminportal/Home#/homepage) - Global reader can't read customer lockbox requests. You won't find the **Customer lockbox requests** tab under **Support** in the left pane of M365 Admin Center.
236236
>- [M365 Security center](https://security.microsoft.com/homepage) - Global reader can't read sensitivity and retention labels. You won't find **Sensitivity labels**, **Retention labels**, and **Label analytics** tabs in the left pane of the M365 Security center.
237-
>- [Office Security & Compliance Center](https://protection.microsoft.com) - Global reader can't read SCC audit logs or do content search.
237+
>- [Office Security & Compliance Center](https://sip.protection.office.com/homepage) - Global reader can't read SCC audit logs or do content search.
238238
>- [Teams admin center](https://admin.teams.microsoft.com) - Global reader cannot read **Teams lifecycle**, **Analytics & reports**, **IP phone device management** and **App catalog**.
239239
>- [Privileged Access Management (PAM)](https://docs.microsoft.com/office365/securitycompliance/privileged-access-management-overview) doesn't support the Global reader role.
240240
>- [Azure Information Protection](https://docs.microsoft.com/azure/information-protection/what-is-information-protection) - Global reader is supported [for central reporting](https://docs.microsoft.com/azure/information-protection/reports-aip) only, and when your Azure AD organization isn't on the [unified labeling platform](https://docs.microsoft.com/azure/information-protection/faqs#how-can-i-determine-if-my-tenant-is-on-the-unified-labeling-platform).
@@ -244,7 +244,7 @@ Users in this role can read settings and administrative information across Micro
244244
245245
### [Group Administrator](#group-administrator)
246246

247-
Users in this role can create/manage groups and its settings like naming and expiration policies. It is important to understand that assigning a user to this role gives them the ability to manage all groups in the tenant across various workloads like Teams, SharePoint, Yammer in addition to Outlook. Also the user will be able to manage the various groups settings across various admin portals like Microsoft Admin Center, Azure Portal, as well as workload specific ones like Teams and SharePoint Admin Centers.
247+
Users in this role can create/manage groups and its settings like naming and expiration policies. It is important to understand that assigning a user to this role gives them the ability to manage all groups in the tenant across various workloads like Teams, SharePoint, Yammer in addition to Outlook. Also the user will be able to manage the various groups settings across various admin portals like Microsoft Admin Center, Azure portal, as well as workload specific ones like Teams and SharePoint Admin Centers.
248248

249249
### [Guest Inviter](#guest-inviter-permissions)
250250

0 commit comments

Comments
 (0)