Skip to content

Commit dbe434f

Browse files
authored
Merge pull request #134308 from MicrosoftDocs/master
10/16 PM Publish
2 parents 33368ca + 155ac76 commit dbe434f

File tree

463 files changed

+2950
-1881
lines changed

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

463 files changed

+2950
-1881
lines changed

.openpublishing.redirection.json

Lines changed: 11 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -14657,6 +14657,11 @@
1465714657
"redirect_url": "/azure/azure-vmware/tutorial-deploy-vmware-hcx",
1465814658
"redirect_document_id": false
1465914659
},
14660+
{
14661+
"source_path": "articles/azure-vmware/pre-deployment-checklist.md",
14662+
"redirect_url": "/azure/azure-vmware/production-ready-deployment-steps",
14663+
"redirect_document_id": false
14664+
},
1466014665
{
1466114666
"source_path": "articles/azure-vmware/disaster-recovery.md",
1466214667
"redirect_url": "/azure/azure-vmware/disaster-recovery-for-virtual-machines",
@@ -24607,6 +24612,11 @@
2460724612
"redirect_url": "/azure/active-directory/authentication/howto-registration-mfa-sspr-combined-troubleshoot",
2460824613
"redirect_document_id": true
2460924614
},
24615+
{
24616+
"source_path": "articles/active-directory/conditional-access/best-practices.md",
24617+
"redirect_url": "/azure/active-directory/conditional-access/overview",
24618+
"redirect_document_id": true
24619+
},
2461024620
{
2461124621
"source_path": "articles/active-directory/conditional-access/app-sign-in-risk.md",
2461224622
"redirect_url": "/azure/active-directory/conditional-access/howto-conditional-access-policy-risk",
@@ -39730,7 +39740,7 @@
3973039740
{
3973139741
"source_path": "articles/active-directory/active-directory-conditional-access-azure-portal.md",
3973239742
"redirect_url": "/azure/active-directory/conditional-access/overview",
39733-
"redirect_document_id": true
39743+
"redirect_document_id": false
3973439744
},
3973539745
{
3973639746
"source_path": "articles/active-directory/active-directory-conditional-access-azure-portal-get-started.md",

articles/active-directory/app-provisioning/application-provisioning-log-analytics.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -21,7 +21,7 @@ Provisioning integrates with Azure Monitor logs and Log Analytics. With Azure mo
2121

2222
You should already be familiar with Azure monitoring and Log Analytics. If not, jump over to learn about them and then come back to learn about application provisioning logs. To learn more about Azure monitoring, see [Azure Monitor overview](../../azure-monitor/overview.md). To learn more about Azure Monitor logs and Log Analytics, see [Overview of log queries in Azure Monitor](../../azure-monitor/log-query/log-query-overview.md).
2323

24-
Once you've configured on Azure monitoring, you can enable logs for application provisioning. The option is located on the **Diagnostics settings** page.
24+
Once you've configured Azure monitoring, you can enable logs for application provisioning. The option is located on the **Diagnostics settings** page.
2525

2626
:::image type="content" source="media/application-provisioning-log-analytics/diagnostic-settings.png" alt-text="Access diagnostic settings" lightbox="media/application-provisioning-log-analytics/diagnostic-settings.png":::
2727

articles/active-directory/conditional-access/TOC.yml

Lines changed: 0 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -92,8 +92,6 @@
9292
href: terms-of-use.md
9393
- name: Sign-in frequency and browser persistence controls
9494
href: howto-conditional-access-session-lifetime.md
95-
- name: Best practices
96-
href: best-practices.md
9795
- name: Troubleshooting
9896
items:
9997
- name: Troubleshoot sign-in problems

articles/active-directory/conditional-access/best-practices.md

Lines changed: 0 additions & 155 deletions
This file was deleted.

articles/active-directory/conditional-access/block-legacy-authentication.md

Lines changed: 2 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -6,7 +6,7 @@ services: active-directory
66
ms.service: active-directory
77
ms.subservice: conditional-access
88
ms.topic: how-to
9-
ms.date: 08/07/2020
9+
ms.date: 10/16/2020
1010

1111
ms.author: joflore
1212
author: MicrosoftGuyJFlo
@@ -34,10 +34,7 @@ If your environment is ready to block legacy authentication to improve your tena
3434

3535
## Prerequisites
3636

37-
This article assumes that you are familiar with:
38-
39-
- The [basic concepts](overview.md) of Azure AD Conditional Access
40-
- The [best practices](best-practices.md) for configuring Conditional Access policies in the Azure portal
37+
This article assumes that you are familiar with the [basic concepts](overview.md) of Azure AD Conditional Access.
4138

4239
## Scenario description
4340

articles/active-directory/conditional-access/concept-conditional-access-cloud-apps.md

Lines changed: 2 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -6,7 +6,7 @@ services: active-directory
66
ms.service: active-directory
77
ms.subservice: conditional-access
88
ms.topic: conceptual
9-
ms.date: 02/11/2020
9+
ms.date: 10/16/2020
1010

1111
ms.author: joflore
1212
author: MicrosoftGuyJFlo
@@ -118,8 +118,7 @@ In addition to the Microsoft apps, administrators can add any Azure AD registere
118118
- Applications that use [password based single sign-on](../manage-apps/configure-password-single-sign-on-non-gallery-applications.md)
119119

120120
> [!NOTE]
121-
> Since Conditional access policy sets the requirements for accessing a service you are not able to apply it to a client (public/native) application. Other words the policy is not set directly on a client (public/native) application, but is applied when a client calls a service. For example, a policy set on SharePoint service applies to the clients calling SharePoint. A policy set on Exchange applies to the attempt to access the email using Outlook client. That is why client (public/native) applications are not available for selection in the Cloud Apps picker and Conditional Access option is not available in the application settings for the client (public/native) application registered in your tenant.
122-
121+
> Since Conditional Access policy sets the requirements for accessing a service you are not able to apply it to a client (public/native) application. Other words the policy is not set directly on a client (public/native) application, but is applied when a client calls a service. For example, a policy set on SharePoint service applies to the clients calling SharePoint. A policy set on Exchange applies to the attempt to access the email using Outlook client. That is why client (public/native) applications are not available for selection in the Cloud Apps picker and Conditional Access option is not available in the application settings for the client (public/native) application registered in your tenant.
123122
124123
## User actions
125124

articles/active-directory/conditional-access/concept-conditional-access-policies.md

Lines changed: 21 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -6,7 +6,7 @@ services: active-directory
66
ms.service: active-directory
77
ms.subservice: conditional-access
88
ms.topic: conceptual
9-
ms.date: 03/25/2020
9+
ms.date: 10/16/2020
1010

1111
ms.author: joflore
1212
author: MicrosoftGuyJFlo
@@ -19,10 +19,29 @@ ms.collection: M365-identity-device-management
1919

2020
As explained in the article [What is Conditional Access](overview.md), a Conditional Access policy is an if-then statement, of **Assignments** and **Access controls**. A Conditional Access policy brings signals together, to make decisions, and enforce organizational policies.
2121

22-
How does an organization create these policies? What is required?
22+
How does an organization create these policies? What is required? How are they applied?
2323

2424
![Conditional Access (Signals + Decisions + Enforcement = Policies)](./media/concept-conditional-access-policies/conditional-access-signal-decision-enforcement.png)
2525

26+
Multiple Conditional Access policies may apply to an individual user at any time. In this case, all policies that apply must be satisfied. For example, if one policy requires multi-factor authentication (MFA) and another requires a compliant device, you must complete MFA, and use a compliant device. All assignments are logically **ANDed**. If you have more than one assignment configured, all assignments must be satisfied to trigger a policy.
27+
28+
All policies are enforced in two phases:
29+
30+
- Phase 1: Collect session details
31+
- Gather session details, like network location and device identity that will be necessary for policy evaluation.
32+
- Phase 1 of policy evaluation occurs for enabled policies and policies in [report-only mode](concept-conditional-access-report-only.md).
33+
- Phase 2: Enforcement
34+
- Use the session details gathered in phase 1 to identify any requirements that have not been met.
35+
- If there is a policy that is configured to block access, with the block grant control, enforcement will stop here and the user will be blocked.
36+
- The user will be prompted to complete additional grant control requirements that were not satisfied during phase 1 in the following order, until policy is satisfied:
37+
- Multi-factor authentication​
38+
- Approved client app/app protection policy​
39+
- Managed device (compliant or hybrid Azure AD join)​
40+
- Terms of use
41+
- Custom controls
42+
- Once all grant controls have been satisfied, apply session controls (App Enforced, Microsoft Cloud App Security, and token Lifetime)
43+
- Phase 2 of policy evaluation occurs for all enabled policies.
44+
2645
## Assignments
2746

2847
The assignments portion controls the who, what, and where of the Conditional Access policy.

articles/active-directory/conditional-access/concept-conditional-access-users-groups.md

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -17,7 +17,7 @@ ms.collection: M365-identity-device-management
1717
---
1818
# Conditional Access: Users and groups
1919

20-
A Conditional Access policy must include a user assignment as one of the signals in the decision process. Users can be included or excluded from Conditional Access policies.
20+
A Conditional Access policy must include a user assignment as one of the signals in the decision process. Users can be included or excluded from Conditional Access policies. Azure Active Directory evaluates all policies and ensures that all requirements are met before granting access to the user.
2121

2222
![User as a signal in the decisions made by Conditional Access](./media/concept-conditional-access-users-groups/conditional-access-users-and-groups.png)
2323

@@ -71,6 +71,8 @@ By default the policy will provide an option to exclude the current user from th
7171

7272
![Warning, don't lock yourself out!](./media/concept-conditional-access-users-groups/conditional-access-users-and-groups-lockout-warning.png)
7373

74+
[What to do if you are locked out of the Azure portal?](troubleshoot-conditional-access.md#what-to-do-if-you-are-locked-out-of-the-azure-portal)
75+
7476
## Next steps
7577

7678
- [Conditional Access: Cloud apps or actions](concept-conditional-access-cloud-apps.md)

articles/active-directory/conditional-access/faqs.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -6,7 +6,7 @@ services: active-directory
66
ms.service: active-directory
77
ms.subservice: conditional-access
88
ms.topic: troubleshooting
9-
ms.date: 06/22/2020
9+
ms.date: 10/16/2020
1010

1111
ms.author: joflore
1212
author: MicrosoftGuyJFlo
@@ -60,4 +60,4 @@ To see the affected tabs you must use the Teams web client in Edge, Internet Exp
6060

6161
## Next steps
6262

63-
- To configure Conditional Access policies for your environment, see the [Best practices for Conditional Access in Azure Active Directory](best-practices.md).
63+
- To configure Conditional Access policies for your environment, see the article [Plan a Conditional Access deployment](plan-conditional-access.md).

0 commit comments

Comments
 (0)