Skip to content

Commit d4a9769

Browse files
Merge pull request #253695 from rwike77/workload2
Adding App health recommendations to FAQ
2 parents b99fea3 + c085326 commit d4a9769

File tree

1 file changed

+9
-6
lines changed

1 file changed

+9
-6
lines changed

articles/active-directory/workload-identities/workload-identities-faqs.md

Lines changed: 9 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -8,7 +8,7 @@ ms.service: active-directory
88
ms.subservice: workload-identities
99
ms.workload: identity
1010
ms.topic: conceptual
11-
ms.date: 9/15/2023
11+
ms.date: 10/03/2023
1212
ms.author: gasinh
1313
ms.reviewer:
1414
ms.custom: aaddev
@@ -45,6 +45,7 @@ pricing](https://www.microsoft.com/security/business/identity-access/microsoft-e
4545
|**Lifecycle Management**| | | |
4646
|Access reviews for service provider-assigned privileged roles | Closely monitor workload identities with impactful permissions | | Yes |
4747
| Application authentication methods API | Allows IT admins to enforce best practices for how apps in their organizations use application authentication methods. | | Yes |
48+
| App Health Recommendations | Identify unused or inactive workload identities and their risk levels. Get remediation guidelines. | | Yes |
4849
|**Identity Protection** | | |
4950
|Identity Protection for workload identities | Detect and remediate compromised workload identities | | Yes |
5051

@@ -68,7 +69,7 @@ You can purchase the plan through Enterprise Agreement (EA)/Enterprise Subscript
6869

6970
## Where can I find more feature details to determine if I need a license(s)?
7071

71-
Microsoft Entra Workload ID has three premium features that require a license.
72+
Microsoft Entra Workload ID has four premium features that require a license.
7273

7374
- [Conditional Access](../conditional-access/workload-identity.md):
7475
Supports location or risk-based policies for workload identities.
@@ -81,11 +82,13 @@ suspicious changes to accounts.
8182
Enables delegation of reviews to the right people, focused on the most
8283
important privileged roles.
8384

85+
- [App health recommendations](/azure/active-directory/reports-monitoring/howto-use-recommendations): Provides you with personalized insights with actionable guidance so you can implement best practices, improve the state of your Microsoft Entra tenant, and optimize the configurations for your scenarios.
86+
8487
## What do the numbers in each category on the [Workload identities - Microsoft Entra admin center](https://entra.microsoft.com/#view/Microsoft_Azure_ManagedServiceIdentity/WorkloadIdentitiesBlade) mean?
8588

8689
Category definitions:
8790

88-
- **Enterprise apps/Service Principals**: This category includes multi-tenant apps, gallery apps, non-gallery apps and service principals.
91+
- **Enterprise apps/Service Principals**: This category includes multitenant apps, gallery apps, non-gallery apps and service principals.
8992

9093
- **Microsoft apps**: Apps such as Outlook and Microsoft Teams.
9194

@@ -96,9 +99,9 @@ applications for connecting resources that support Microsoft Entra authenticatio
9699

97100
All workload identities - service principles, apps and managed identities, configured in your directory for a Microsoft Entra Workload ID Premium feature require a license. Customers don’t need to license all the workload identities. You can find the right number of Workload ID licenses with the following guidance:
98101

99-
1. Customer will need to license enterprise applications or service principals ONLY if they set up Conditional Access policies or use Identity Protection for them.
100-
2. Customers don't need to license applications at all, even if they are using Conditional Access policies.
101-
3. Customers will need to license managed identities, only when they set up access reviews for managed identities.
102+
1. Customer needs to license enterprise applications or service principals ONLY if they set up Conditional Access policies or use Identity Protection for them.
103+
2. Customers don't need to license applications at all, even if they're using Conditional Access policies.
104+
3. Customers need to license managed identities, only when they set up access reviews for managed identities.
102105
You can find the number of each workload identity type (enterprise apps/service principals, apps, managed identities) on the product landing page at the [Microsoft Entra admin center](https://entra.microsoft.com).
103106

104107
## Do these licenses require individual workload identities assignment?

0 commit comments

Comments
 (0)