Skip to content

Commit e859cbb

Browse files
authored
Merge pull request #294732 from MicrosoftDocs/main
Publish to live, Sunday 4PM PST 2/16
2 parents b06ccb6 + 437d02b commit e859cbb

File tree

8 files changed

+164
-117
lines changed

8 files changed

+164
-117
lines changed

.openpublishing.redirection.json

Lines changed: 35 additions & 29 deletions
Original file line numberDiff line numberDiff line change
@@ -28,7 +28,7 @@
2828
{
2929
"source_path": "articles/partner-solutions/logzio/troubleshoot.md",
3030
"redirect_url": "/previous-versions/azure/partner-solutions/logzio/troubleshoot",
31-
"redirect_document_id": false
31+
"redirect_document_id": false
3232
},
3333
{
3434
"source_path_from_root": "/articles/hdinsight-aks/index.yml",
@@ -41,34 +41,34 @@
4141
"redirect_document_id": false
4242
},
4343
{
44-
"source_path_from_root": "/articles/hdinsight-aks/prerequisites-subscription.md",
45-
"redirect_url": "/previous-versions/azure/hdinsight-aks/quickstart-prerequisites-subscription",
46-
"redirect_document_id": false
44+
"source_path_from_root": "/articles/hdinsight-aks/prerequisites-subscription.md",
45+
"redirect_url": "/previous-versions/azure/hdinsight-aks/quickstart-prerequisites-subscription",
46+
"redirect_document_id": false
4747
},
4848
{
49-
"source_path_from_root": "/articles/hdinsight-aks/release-notes/index.md",
50-
"redirect_url": "/previous-versions/azure/hdinsight-aks/release-notes/hdinsight-aks-release-notes",
51-
"redirect_document_id": false
49+
"source_path_from_root": "/articles/hdinsight-aks/release-notes/index.md",
50+
"redirect_url": "/previous-versions/azure/hdinsight-aks/release-notes/hdinsight-aks-release-notes",
51+
"redirect_document_id": false
5252
},
5353
{
54-
"source_path_from_root": "/articles/hdinsight-aks/prerequisites-resources.md",
55-
"redirect_url": "/previous-versions/azure/hdinsight-aks/quickstart-prerequisites-resources",
56-
"redirect_document_id": false
57-
},
54+
"source_path_from_root": "/articles/hdinsight-aks/prerequisites-resources.md",
55+
"redirect_url": "/previous-versions/azure/hdinsight-aks/quickstart-prerequisites-resources",
56+
"redirect_document_id": false
57+
},
5858
{
59-
"source_path_from_root": "/articles/hdinsight-aks/spark/index.md",
60-
"redirect_url": "/previous-versions/azure/hdinsight-aks/spark/hdinsight-on-aks-spark-overview",
61-
"redirect_document_id": false
59+
"source_path_from_root": "/articles/hdinsight-aks/spark/index.md",
60+
"redirect_url": "/previous-versions/azure/hdinsight-aks/spark/hdinsight-on-aks-spark-overview",
61+
"redirect_document_id": false
6262
},
6363
{
64-
"source_path_from_root": "/articles/hdinsight-aks/get-started.md",
65-
"redirect_url": "/previous-versions/azure/hdinsight-aks/quickstart-get-started",
66-
"redirect_document_id": false
64+
"source_path_from_root": "/articles/hdinsight-aks/get-started.md",
65+
"redirect_url": "/previous-versions/azure/hdinsight-aks/quickstart-get-started",
66+
"redirect_document_id": false
6767
},
6868
{
69-
"source_path_from_root": "/articles/hdinsight-aks/trino/index.md",
70-
"redirect_url": "/previous-versions/azure/hdinsight-aks/trino/trino-overview ",
71-
"redirect_document_id": false
69+
"source_path_from_root": "/articles/hdinsight-aks/trino/index.md",
70+
"redirect_url": "/previous-versions/azure/hdinsight-aks/trino/trino-overview ",
71+
"redirect_document_id": false
7272
},
7373
{
7474
"source_path": "articles/hdinsight-aks/cluster-storage.md",
@@ -1038,7 +1038,7 @@
10381038
{
10391039
"source_path": "articles/defender-for-iot/organizations/legacy-central-management/how-to-troubleshoot-on-premises-management-console.md",
10401040
"redirect_url": "/previous-versions/azure/defender-for-iot/organizations/legacy-central-management/how-to-troubleshoot-on-premises-management-console",
1041-
"redirect_document_id": false
1041+
"redirect_document_id": false
10421042
},
10431043
{
10441044
"source_path": "articles/defender-for-iot/organizations/legacy-central-management/legacy-air-gapped-deploy.md",
@@ -1530,7 +1530,7 @@
15301530
"redirect_url": "/previous-versions/azure/partner-solutions/split-experimentation/troubleshoot",
15311531
"redirect_document_id": false
15321532
},
1533-
{
1533+
{
15341534
"source_path": "articles/virtual-desktop/virtual-desktop-fall-2019/classic-retirement.md",
15351535
"redirect_url": "/previous-versions/azure/virtual-desktop-classic/classic-retirement",
15361536
"redirect_document_id": false
@@ -3039,7 +3039,8 @@
30393039
"source_path_from_root": "/articles/ddos-protection/telemetry-monitoring-alerting.md",
30403040
"redirect_url": "/azure/ddos-protection/telemetry",
30413041
"redirect_document_id": false
3042-
}, {
3042+
},
3043+
{
30433044
"source_path_from_root": "/articles/ddos-protection/telemetry.md",
30443045
"redirect_url": "/azure/ddos-protection/monitor-ddos-protection",
30453046
"redirect_document_id": false
@@ -3333,7 +3334,7 @@
33333334
"source_path_from_root": "/articles/dns/dns-alerts-metrics.md",
33343335
"redirect_url": "/azure/dns/monitor-dns",
33353336
"redirect_document_id": false
3336-
},
3337+
},
33373338
{
33383339
"source_path_from_root": "/articles/docker/index.yml",
33393340
"redirect_url": "/dotnet/architecture/microservices/container-docker-introduction/docker-defined",
@@ -5708,8 +5709,8 @@
57085709
"source_path_from_root": "/articles/defender-for-iot/device-builders/defender-iot-firmware-analysis-rbac.md",
57095710
"redirect_url": "/azure/firmware-analysis/overview-firmware-analysis",
57105711
"redirect_document_id": false
5711-
},
5712-
{
5712+
},
5713+
{
57135714
"source_path_from_root": "/articles/virtual-network/ip-services/public-ip-upgrade-portal.md",
57145715
"redirect_url": "/azure/virtual-network/ip-services/public-ip-upgrade",
57155716
"redirect_document_id": false
@@ -5763,7 +5764,7 @@
57635764
"source_path_from_root": "/articles/load-balancer/move-across-regions-external-load-balancer-powershell.md",
57645765
"redirect_url": "/azure/load-balancer/move-across-regions-azure-load-balancer",
57655766
"redirect_document_id": false
5766-
},
5767+
},
57675768
{
57685769
"source_path_from_root": "/articles/load-balancer/move-across-regions-internal-load-balancer-portal.md",
57695770
"redirect_url": "/azure/load-balancer/move-across-regions-azure-load-balancer",
@@ -5872,7 +5873,7 @@
58725873
{
58735874
"source_path": "articles/virtual-desktop/troubleshoot-management-issues.md",
58745875
"redirect_url": "/troubleshoot/azure/virtual-desktop/troubleshoot-management-issues",
5875-
"redirect_document_id": false
5876+
"redirect_document_id": false
58765877
},
58775878
{
58785879
"source_path": "articles/virtual-desktop/troubleshoot-multimedia-redirection.md",
@@ -5943,6 +5944,11 @@
59435944
"source_path_from_root": "/articles/managed-grafana/how-to-share-grafana-workspace.md",
59445945
"redirect_url": "/azure/managed-grafana/how-to-manage-access-permissions-users-identities",
59455946
"redirect_document_id": false
5947+
},
5948+
{
5949+
"source_path": "articles/sentinel/resources.md",
5950+
"redirect_url": "/azure/sentinel/overview",
5951+
"redirect_document_id": false
59465952
}
59475953
]
5948-
}
5954+
}

articles/firewall/monitor-firewall.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -86,7 +86,7 @@ In **Resource specific** mode, individual tables in the selected workspace are c
8686
New resource specific tables are now available in Diagnostic setting that allows you to utilize the following categories:
8787

8888
- [Network rule log](/azure/azure-monitor/reference/tables/azfwnetworkrule) - Contains all Network Rule log data. Each match between data plane and network rule creates a log entry with the data plane packet and the matched rule's attributes.
89-
- [NAT rule log](/azure/azure-monitor/reference/tables/azfwnatrule) - Contains all DNAT (Destination Network Address Translation) events log data. Each match between data plane and DNAT rule creates a log entry with the data plane packet and the matched rule's attributes.
89+
- [NAT rule log](/azure/azure-monitor/reference/tables/azfwnatrule) - Contains all DNAT (Destination Network Address Translation) events log data. Each match between data plane and DNAT rule creates a log entry with the data plane packet and the matched rule's attributes. Asa note, the AZFWNATRule table logs only when a DNAT rule match occurs. If there is no match, no log is generated.
9090
- [Application rule log](/azure/azure-monitor/reference/tables/azfwapplicationrule) - Contains all Application rule log data. Each match between data plane and Application rule creates a log entry with the data plane packet and the matched rule's attributes.
9191
- [Threat Intelligence log](/azure/azure-monitor/reference/tables/azfwthreatintel) - Contains all Threat Intelligence events.
9292
- [IDPS log](/azure/azure-monitor/reference/tables/azfwidpssignature) - Contains all data plane packets that were matched with one or more IDPS signatures.

articles/role-based-access-control/TOC.yml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -9,6 +9,8 @@
99
href: conditions-overview.md
1010
- name: Understand the different roles
1111
href: rbac-and-directory-admin-roles.md
12+
- name: What's new in docs
13+
href: whats-new.md
1214
- name: Quickstarts
1315
items:
1416
- name: Check access for a user

articles/role-based-access-control/index.yml

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -11,7 +11,7 @@ metadata:
1111
author: rolyon
1212
manager: amycolannino
1313
ms.author: rolyon
14-
ms.date: 03/24/2024
14+
ms.date: 02/18/2025
1515

1616
# linkListType: architecture | concept | deploy | download | get-started | how-to-guide | learn | overview | quickstart | reference | tutorial | video | whats-new
1717

@@ -25,6 +25,8 @@ landingContent:
2525
url: overview.md
2626
- text: Understand the different roles
2727
url: rbac-and-directory-admin-roles.md
28+
- text: "What's new in docs"
29+
url: whats-new.md
2830
- linkListType: video
2931
links:
3032
- text: "Microsoft Ignite: Lock down access to Azure"
Lines changed: 59 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,59 @@
1+
---
2+
title: What's new in Azure RBAC
3+
description: Learn about the new features and documentation improvements in Azure role-based access control (RBAC).
4+
author: rolyon
5+
manager: amycolannino
6+
ms.service: role-based-access-control
7+
ms.topic: whats-new
8+
ms.date: 02/18/2025
9+
ms.author: rolyon
10+
11+
---
12+
13+
# What's new in Azure RBAC
14+
15+
This article provides information about new features and documentation improvements in Azure role-based access control (RBAC).
16+
17+
## 2025
18+
19+
| Date | Area | Description |
20+
| --- | --- | --- |
21+
| February 2025 | Security | Added instructions for how to detect elevate access events using Microsoft Sentinel. See [Detect elevate access events using Microsoft Sentinel](elevate-access-global-admin.md#detect-elevate-access-events-using-microsoft-sentinel). |
22+
| February 2025 | Permissions | Updated list of permissions for the Azure Container Registry. See [Microsoft.ContainerRegistry](permissions/containers.md#microsoftcontainerregistry). |
23+
| February 2025 | Roles | Added [Locks Contributor](built-in-roles/security.md#locks-contributor) role. |
24+
| February 2025 | Subscriptions | Updated list of known impact when transferring a subscription. See [Understand the impact of transferring a subscription](transfer-subscription.md#understand-the-impact-of-transferring-a-subscription). |
25+
| January 2025 | Security | Preview of elevate access log entries in the Microsoft Entra directory audit logs. See [View elevate access log entries](elevate-access-global-admin.md#view-elevate-access-log-entries). |
26+
| January 2025 | Roles | Updated descriptions for roles with `*/read` permissions.<br/>[App Compliance Automation Administrator](built-in-roles/security.md#app-compliance-automation-administrator)<br/>[App Compliance Automation Reader](built-in-roles/security.md#app-compliance-automation-reader)<br/>[Log Analytics Contributor](built-in-roles/analytics.md#log-analytics-contributor)<br/>[Log Analytics Reader](built-in-roles/analytics.md#log-analytics-reader)<br/>[Managed Application Contributor Role](built-in-roles/management-and-governance.md#managed-application-contributor-role)<br/>[Managed Application Operator Role](built-in-roles/management-and-governance.md#managed-application-operator-role)<br/>[Managed Applications Reader](built-in-roles/management-and-governance.md#managed-applications-reader)<br/>[Monitoring Contributor](built-in-roles/monitor.md#monitoring-contributor)<br/>[Monitoring Reader](built-in-roles/monitor.md#monitoring-reader)<br/>[Reader](built-in-roles/general.md#reader)<br/>[Resource Policy Contributor](built-in-roles/management-and-governance.md#resource-policy-contributor)<br/>[Role Based Access Control Administrator](built-in-roles/privileged.md#role-based-access-control-administrator)<br/>[User Access Administrator](built-in-roles/privileged.md#user-access-administrator) |
27+
| January 2025 | Roles | Added Azure Chaos Studio roles. See [Chaos Studio Experiment Contributor](built-in-roles/devops.md#chaos-studio-experiment-contributor), [Chaos Studio Operator](built-in-roles/devops.md#chaos-studio-operator), and [Chaos Studio Reader](built-in-roles/devops.md#chaos-studio-reader). |
28+
| January 2025 | Roles | Added Azure Container Registry roles.<br/>[Container Registry Configuration Reader and Data Access Configuration Reader](built-in-roles/containers.md#container-registry-configuration-reader-and-data-access-configuration-reader)<br/>[Container Registry Contributor and Data Access Configuration Administrator](built-in-roles/containers.md#container-registry-contributor-and-data-access-configuration-administrator)<br/>[Container Registry Data Importer and Data Reader](built-in-roles/containers.md#container-registry-data-importer-and-data-reader)<br/>[Container Registry Repository Catalog Lister](built-in-roles/containers.md#container-registry-repository-catalog-lister)<br/>[Container Registry Repository Contributor](built-in-roles/containers.md#container-registry-repository-contributor)<br/>[Container Registry Repository Reader](built-in-roles/containers.md#container-registry-repository-reader)<br/>[Container Registry Repository Writer](built-in-roles/containers.md#container-registry-repository-writer)<br/>[Container Registry Tasks Contributor](built-in-roles/containers.md#container-registry-tasks-contributor)<br/>[Container Registry Transfer Pipeline Contributor](built-in-roles/containers.md#container-registry-transfer-pipeline-contributor) |
29+
| January 2025 | Roles and permissions | Updated permissions for several roles and resource providers. See [Azure built-in roles](built-in-roles.md) and [Azure permissions](resource-provider-operations.md). |
30+
| January 2025 | REST API | Updated how to list a role definition with a specified role name. See [List role definitions](role-definitions-list.yml#rest-api). |
31+
32+
## 2024
33+
34+
| Date | Area | Description |
35+
| --- | --- | --- |
36+
| December 2024 | Role assignments | Documented check access improvements on the **Access control (IAM) page**. See [Quickstart: Check access for a user to a single Azure resource](check-access.md). |
37+
| December 2024 | Security | Documented improvements for how to view users with elevated access and how to remove this elevated access. See [View users with elevated access](elevate-access-global-admin.md#view-users-with-elevated-access). |
38+
| December 2024 | Roles | Added [Compute Gallery Image Reader](built-in-roles/compute.md#compute-gallery-image-reader) role. |
39+
| December 2024 | Roles | Added [Azure Stack HCI Connected InfraVMs](built-in-roles/hybrid-multicloud.md#azure-stack-hci-connected-infravms) role. |
40+
| December 2024 | Roles and permissions | Updated permissions for several roles and resource providers. See [Azure built-in roles](built-in-roles.md) and [Azure permissions](resource-provider-operations.md). |
41+
| November 2024 | Role assignments | General availability of the integration of Azure RBAC and Microsoft Entra Privileged Identity Management (PIM) to create eligible and time-bound role assignments. See [Eligible and time-bound role assignments in Azure RBAC](pim-integration.md), [Assign Azure roles using the Azure portal](role-assignments-portal.yml#step-6-select-assignment-type), and [Activate eligible Azure role assignments](role-assignments-eligible-activate.md). |
42+
| November 2024 | Roles | Added [Azure Managed Grafana Workspace Contributor](built-in-roles/monitor.md#azure-managed-grafana-workspace-contributor) role. |
43+
| October 2024 | Roles | Added Azure Service Fabric roles. See [Service Fabric Cluster Contributor](built-in-roles/containers.md#service-fabric-cluster-contributor) and [Service Fabric Managed Cluster Contributor](built-in-roles/containers.md#service-fabric-managed-cluster-contributor). |
44+
| October 2024 | Roles | Updated [Cognitive Services Data Reader](built-in-roles/ai-machine-learning.md#cognitive-services-data-reader) role. |
45+
| September 2024 | Roles | Added Azure Kubernetes roles. See [Azure Kubernetes Service Arc Cluster Admin Role](built-in-roles/containers.md#azure-kubernetes-service-arc-cluster-admin-role), [Azure Kubernetes Service Arc Cluster User Role](built-in-roles/containers.md#azure-kubernetes-service-arc-cluster-user-role), and [Azure Kubernetes Service Arc Contributor Role](built-in-roles/containers.md#azure-kubernetes-service-arc-contributor-role). |
46+
| September 2024 | Roles and permissions | Added de-identification service roles in Azure Health Data Services. See [DeID Batch Data Owner](built-in-roles/integration.md#deid-batch-data-owner), [DeID Batch Data Reader](built-in-roles/integration.md#deid-batch-data-reader), [DeID Data Owner](built-in-roles/integration.md#deid-data-owner), [DeID Realtime Data User](built-in-roles/integration.md#deid-realtime-data-user), and [Microsoft.HealthDataAIServices](permissions/integration.md#microsofthealthdataaiservices). |
47+
| September 2024 | Roles | Added app configuration roles. See [App Configuration Contributor](built-in-roles/integration.md#app-configuration-contributor) and [App Configuration Reader](built-in-roles/integration.md#app-configuration-reader). |
48+
| September 2024 | Roles | Added Privileged category. See [Azure built-in roles for Privileged](built-in-roles/privileged.md). |
49+
| August 2024 | Security | Updates about classic administrators retirement. See [Azure classic subscription administrators](classic-administrators.md). |
50+
| August 2024 | Role assignments | Updates to scope for the integration of Azure RBAC and Microsoft Entra Privileged Identity Management (PIM). See [Eligible and time-bound role assignments in Azure RBAC](pim-integration.md). |
51+
| July 2024 | Roles | Added Azure Compute Gallery roles. See [Compute Gallery Artifacts Publisher](built-in-roles/compute.md#compute-gallery-artifacts-publisher) and [Compute Gallery Sharing Admin](built-in-roles/compute.md#compute-gallery-sharing-admin). |
52+
| June 2024 | Roles | Added Azure AI roles. See [Azure AI Developer](built-in-roles/ai-machine-learning.md#azure-ai-developer), [Azure AI Enterprise Network Connection Approver](built-in-roles/ai-machine-learning.md#azure-ai-enterprise-network-connection-approver), and [Azure AI Inference Deployment Operator](built-in-roles/ai-machine-learning.md#azure-ai-inference-deployment-operator). |
53+
| June 2024 | Role assignments | Preview of the integration of Azure RBAC and Microsoft Entra Privileged Identity Management (PIM) to create eligible and time-bound role assignments. See [Eligible and time-bound role assignments in Azure RBAC](pim-integration.md), [Assign Azure roles using the Azure portal](role-assignments-portal.yml#step-6-select-assignment-type), and [Activate eligible Azure role assignments](role-assignments-eligible-activate.md). |
54+
55+
## Related content
56+
57+
- [Azure documentation](/azure/)
58+
- [Azure Updates](https://azure.microsoft.com/updates/)
59+
- [Microsoft Azure Blog - Announcements](https://azure.microsoft.com/blog/content-type/announcements/)

0 commit comments

Comments
 (0)