Skip to content

Commit d041fbb

Browse files
author
JiayueHu
committed
sync the latest master
2 parents f43620d + cae7ae8 commit d041fbb

File tree

543 files changed

+3805
-2870
lines changed

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

543 files changed

+3805
-2870
lines changed

.openpublishing.redirection.json

+95
Original file line numberDiff line numberDiff line change
@@ -11605,6 +11605,11 @@
1160511605
"redirect_url": "/azure/storage/common/storage-quickstart-create-account?tabs=powershell",
1160611606
"redirect_document_id": false
1160711607
},
11608+
{
11609+
"source_path": "articles/storage/blobs/data-lake-storage-evaluation.md",
11610+
"redirect_url": "/azure/storage/blobs/data-lake-storage-upgrade",
11611+
"redirect_document_id": false
11612+
},
1160811613
{
1160911614
"source_path": "articles/sql-data-warehouse/sql-data-warehouse-get-started-load-with-azure-data-factory.md",
1161011615
"redirect_url": "/azure/sql-data-warehouse/sql-data-warehouse-load-with-data-factory",
@@ -31641,6 +31646,96 @@
3164131646
"redirect_url": "/azure/azure-monitor/platform/om-agents",
3164231647
"redirect_document_id": true
3164331648
},
31649+
{
31650+
"source_path": "articles/log-analytics/log-analytics-quick-collect-windows-computer.md",
31651+
"redirect_url": "/azure/azure-monitor/learn/quick-collect-windows-computer",
31652+
"redirect_document_id": true
31653+
},
31654+
{
31655+
"source_path": "articles/log-analytics/log-analytics-quick-create-workspace.md",
31656+
"redirect_url": "/azure/azure-monitor/learn/quick-create-workspace",
31657+
"redirect_document_id": true
31658+
},
31659+
{
31660+
"source_path": "articles/log-analytics/log-analytics-quick-create-workspace-cli.md",
31661+
"redirect_url": "/azure/azure-monitor/learn/quick-create-workspace-cli",
31662+
"redirect_document_id": true
31663+
},
31664+
{
31665+
"source_path": "articles/log-analytics/log-analytics-quick-create-workspace-posh.md",
31666+
"redirect_url": "/azure/azure-monitor/learn/quick-create-workspace-posh",
31667+
"redirect_document_id": true
31668+
},
31669+
{
31670+
"source_path": "articles/log-analytics/log-analytics-service-providers.md",
31671+
"redirect_url": "/azure/azure-monitor/platform/service-providers",
31672+
"redirect_document_id": true
31673+
},
31674+
{
31675+
"source_path": "articles/log-analytics/log-analytics-standard-properties.md",
31676+
"redirect_url": "/azure/azure-monitor/platform/log-standard-properties",
31677+
"redirect_document_id": true
31678+
},
31679+
{
31680+
"source_path": "articles/log-analytics/log-analytics-template-workspace-configuration.md",
31681+
"redirect_url": "/azure/azure-monitor/platform/template-workspace-configuration",
31682+
"redirect_document_id": true
31683+
},
31684+
{
31685+
"source_path": "articles/log-analytics/log-analytics-tutorial-dashboards.md",
31686+
"redirect_url": "/azure/azure-monitor/learn/tutorial-logs-dashboards",
31687+
"redirect_document_id": true
31688+
},
31689+
{
31690+
"source_path": "articles/log-analytics/log-analytics-tutorial-response.md",
31691+
"redirect_url": "/azure/azure-monitor/learn/tutorial-response",
31692+
"redirect_document_id": true
31693+
},
31694+
{
31695+
"source_path": "articles/log-analytics/log-analytics-tutorial-viewdata.md",
31696+
"redirect_url": "/azure/azure-monitor/learn/tutorial-viewdata",
31697+
"redirect_document_id": true
31698+
},
31699+
{
31700+
"source_path": "articles/log-analytics/log-analytics-manage-access.md",
31701+
"redirect_url": "/azure/azure-monitor/platform/manage-access",
31702+
"redirect_document_id": true
31703+
},
31704+
{
31705+
"source_path": "articles/log-analytics/log-analytics-manage-cost-storage.md",
31706+
"redirect_url": "/azure/azure-monitor/platform/manage-cost-storage",
31707+
"redirect_document_id": true
31708+
},
31709+
{
31710+
"source_path": "articles/log-analytics/log-analytics-manage-del-workspace.md",
31711+
"redirect_url": "/azure/azure-monitor/platform/delete-workspace",
31712+
"redirect_document_id": true
31713+
},
31714+
{
31715+
"source_path": "articles/log-analytics/log-analytics-network-performance-monitor-faq.md",
31716+
"redirect_url": "/azure/azure-monitor/insights/network-performance-monitor-faq",
31717+
"redirect_document_id": true
31718+
},
31719+
{
31720+
"source_path": "articles/log-analytics/log-analytics-oms-portal-faq.md",
31721+
"redirect_url": "/azure/azure-monitor/platform/oms-portal-faq",
31722+
"redirect_document_id": true
31723+
},
31724+
{
31725+
"source_path": "articles/log-analytics/log-analytics-oms-portal-transition.md",
31726+
"redirect_url": "/azure/azure-monitor/platform/oms-portal-transition",
31727+
"redirect_document_id": true
31728+
},
31729+
{
31730+
"source_path": "articles/log-analytics/log-analytics-personal-data-mgmt.md",
31731+
"redirect_url": "/azure/azure-monitor/platform/personal-data-mgmt",
31732+
"redirect_document_id": true
31733+
},
31734+
{
31735+
"source_path": "articles/log-analytics/log-analytics-powerbi.md",
31736+
"redirect_url": "/azure/azure-monitor/platform/powerbi",
31737+
"redirect_document_id": true
31738+
},
3164431739
{
3164531740
"source_path": "articles/storage/common/storage-lifecycle-managment-concepts.md",
3164631741
"redirect_url": "/azure/storage/common/storage-lifecycle-management-concepts",

articles/active-directory-b2c/active-directory-b2c-app-registration.md

+2-5
Original file line numberDiff line numberDiff line change
@@ -8,7 +8,7 @@ manager: mtillman
88
ms.service: active-directory
99
ms.workload: identity
1010
ms.topic: conceptual
11-
ms.date: 11/01/2018
11+
ms.date: 12/05/2018
1212
ms.author: davidmu
1313
ms.component: B2C
1414
---
@@ -78,7 +78,4 @@ If your application calls a web API secured by Azure AD B2C, you need to create
7878

7979
## Next steps
8080

81-
Now that you have an application registered with Azure AD B2C, you can complete one of [the quickstart tutorials](active-directory-b2c-overview.md) to get up and running.
82-
83-
> [!div class="nextstepaction"]
84-
> [Create an ASP.NET web app with sign-up, sign-in, and password reset](active-directory-b2c-devquickstarts-web-dotnet-susi.md)
81+
Learn more about how access tokens are used by applications grant permissions to APIs in [Requesting access tokens](active-directory-b2c-access-tokens.md)
Loading
Loading
Binary file not shown.
Loading
Loading
Loading
Loading

articles/active-directory/b2b/user-properties.md

+23-11
Original file line numberDiff line numberDiff line change
@@ -6,7 +6,7 @@ services: active-directory
66
ms.service: active-directory
77
ms.component: B2B
88
ms.topic: conceptual
9-
ms.date: 05/25/2017
9+
ms.date: 12/5/2018
1010

1111
ms.author: mimart
1212
author: msmimart
@@ -23,31 +23,43 @@ Depending on the inviting organization's needs, an Azure AD B2B collaboration us
2323

2424
- State 1: Homed in an external instance of Azure AD and represented as a guest user in the inviting organization. In this case, the B2B user signs in by using an Azure AD account that belongs to the invited tenant. If the partner organization doesn't use Azure AD, the guest user in Azure AD is still created. The requirements are that they redeem their invitation and Azure AD verifies their email address. This arrangement is also called a just-in-time (JIT) tenancy or a "viral" tenancy.
2525

26-
- State 2: Homed in a Microsoft account and represented as a guest user in the host organization. In this case, the guest user signs in with a Microsoft account. The invited user's social identity (google.com or similar), which is not a Microsoft account, is created as a Microsoft account during offer redemption.
26+
- State 2: Homed in a Microsoft or other account and represented as a guest user in the host organization. In this case, the guest user signs in with a Microsoft account or a social account (google.com or similar). The invited user's identity is created as a Microsoft account in the inviting organization’s directory during offer redemption.
2727

28-
- State 3: Homed in the host organization's on-premises Active Directory and synced with the host organization's Azure AD. During this release, you must use PowerShell to manually change the UserType of such users in the cloud.
28+
- State 3: Homed in the host organization's on-premises Active Directory and synced with the host organization's Azure AD. You can use Azure AD Connect to sync the partner accounts to the cloud as Azure AD B2B users with UserType = Guest. See [Grant locally-managed partner accounts access to cloud resources](hybrid-on-premises-to-cloud.md).
2929

30-
- State 4: Homed in host organization's Azure AD with UserType = Guest and credentials that the host organization manages.
30+
- State 4: Homed in the host organization's Azure AD with UserType = Guest and credentials that the host organization manages.
3131

3232
![Displaying the inviter's initials](media/user-properties/redemption-diagram.png)
3333

3434

35-
Now, let's see what an Azure AD B2B collaboration user in State 1 looks like in Azure AD.
35+
Now, let's see what an Azure AD B2B collaboration user looks like in Azure AD.
3636

3737
### Before invitation redemption
3838

39+
State 1 and State 2 accounts are the result of inviting guest users to collaborate by using the guest users' own credentials. When the invitation is initially sent to the guest user, an account is created in your directory. This account doesn’t have any credentials associated with it because authentication is performed by the guest user's identity provider. The **Source** property for the guest user account in your directory is set to **Invited user**.
40+
3941
![Before offer redemption](media/user-properties/before-redemption.png)
4042

4143
### After invitation redemption
4244

43-
![After offer redemption](media/user-properties/after-redemption.png)
45+
After the guest user accepts the invitation, the **Source** property is updated based on the guest user’s identity provider.
46+
47+
For guest users in State 1, the **Source** is **External Azure Active Directory**.
48+
49+
![State 1 guest user after offer redemption](media/user-properties/after-redemption-state1.png)
50+
51+
For guest users in State 2, the **Source** is **Microsoft Account**.
52+
53+
![State 2 guest user after offer redemption](media/user-properties/after-redemption-state2.png)
54+
55+
For guest users in State 3 and State 4, the **Source** property is set to **Azure Active Directory** or **Windows Server Active Directory**, as described in the next section.
4456

4557
## Key properties of the Azure AD B2B collaboration user
4658
### UserType
4759
This property indicates the relationship of the user to the host tenancy. This property can have two values:
48-
- Member: This value indicates an employee of the host organization and a user in the organization's payroll. For example, this user expects to have access to internal-only sites. This user would not be considered an external collaborator.
60+
- Member: This value indicates an employee of the host organization and a user in the organization's payroll. For example, this user expects to have access to internal-only sites. This user is not considered an external collaborator.
4961

50-
- Guest: This value indicates a user who isn't considered internal to the company, such as an external collaborator, partner, customer, or similar user. Such a user wouldn't be expected to receive a CEO's internal memo, or receive company benefits, for example.
62+
- Guest: This value indicates a user who isn't considered internal to the company, such as an external collaborator, partner, or customer. Such a user isn't expected to receive a CEO's internal memo or receive company benefits, for example.
5163

5264
> [!NOTE]
5365
> The UserType has no relation to how the user signs in, the directory role of the user, and so on. This property simply indicates the user's relationship to the host organization and allows the organization to enforce policies that depend on this property.
@@ -75,17 +87,17 @@ Typically, an Azure AD B2B user and guest user are synonymous. Therefore, an Azu
7587
![Filter guest users](media/user-properties/filter-guest-users.png)
7688

7789
## Convert UserType
78-
Currently, it is possible for users to convert UserType from Member to Guest and vice-versa by using PowerShell. However, the UserType property is supposed to represent the user's relationship to the organization. Therefore, the value of this property should change only if the relationship of the user to the organization changes. If the relationship of the user changes, should issues, like whether the user principal name (UPN) should change, be addressed? Should the user continue to have access to the same resources? Should a mailbox be assigned? Therefore, we do not recommend changing the UserType by using PowerShell as an atomic activity. In addition, in case this property becomes immutable by using PowerShell, we do not recommend taking a dependency on this value.
90+
It's possible to convert UserType from Member to Guest and vice-versa by using PowerShell. However, the UserType property represents the user's relationship to the organization. Therefore, you should change this property only if the relationship of the user to the organization changes. If the relationship of the user changes, should the user principal name (UPN) change? Should the user continue to have access to the same resources? Should a mailbox be assigned? We don't recommend changing the UserType by using PowerShell as an atomic activity. Also, in case this property becomes immutable by using PowerShell, we don't recommend taking a dependency on this value.
7991

8092
## Remove guest user limitations
8193
There may be cases where you want to give your guest users higher privileges. You can add a guest user to any role and even remove the default guest user restrictions in the directory to give a user the same privileges as members.
8294

83-
It is possible to turn off the default guest user limitations so that a guest user in the company directory is given the same permissions as a member user.
95+
It's possible to turn off the default limitations so that a guest user in the company directory has the same permissions as a member user.
8496

8597
![Remove guest user limitations](media/user-properties/remove-guest-limitations.png)
8698

8799
## Can I make guest users visible in the Exchange Global Address List?
88-
Yes. By default, guest objects are not visible in your organization's global address list, but you can use Azure Active Directory PowerShell to make them visible. For details, see **Can I make guest objects visible in the global address list?** in [Guest access in Office 365 Groups](https://support.office.com/article/guest-access-in-office-365-groups-bfc7a840-868f-4fd6-a390-f347bf51aff6#PickTab=FAQ).
100+
Yes. By default, guest objects aren't visible in your organization's global address list, but you can use Azure Active Directory PowerShell to make them visible. For details, see **Can I make guest objects visible in the global address list?** in [Guest access in Office 365 Groups](https://support.office.com/article/guest-access-in-office-365-groups-bfc7a840-868f-4fd6-a390-f347bf51aff6#PickTab=FAQ).
89101

90102
## Next steps
91103

articles/active-directory/develop/quickstart-v2-aspnet-core-webapp.md

+4-4
Original file line numberDiff line numberDiff line change
@@ -3,7 +3,7 @@ title: Azure AD v2.0 ASP.NET Core web app quickstart | Microsoft Docs
33
description: Learn how to implement Microsoft Sign-In on an ASP.NET Core Web App using OpenID Connect
44
services: active-directory
55
documentationcenter: dev-center-name
6-
author: andretms
6+
author: jmprieur
77
manager: mtillman
88
editor: ''
99

@@ -14,13 +14,13 @@ ms.devlang: na
1414
ms.topic: quickstart
1515
ms.tgt_pltfrm: na
1616
ms.workload: identity
17-
ms.date: 11/09/2018
18-
ms.author: andret
17+
ms.date: 12/05/2018
18+
ms.author: jmprieur
1919
ms.custom: aaddev
2020
#Customer intent: As an application developer, I want to know how to write an ASP.NET Core web app that can sign in personal accounts, as well as work and school accounts from any Azure Active Directory instance.
2121
---
2222

23-
# Quickstart: Add sign-in with Microsoft to an ASP.NET web app
23+
# Quickstart: Add sign-in with Microsoft to an ASP.NET Core web app
2424

2525
[!INCLUDE [active-directory-develop-applies-v2](../../../includes/active-directory-develop-applies-v2.md)]
2626

articles/active-directory/fundamentals/active-directory-groups-membership-azure-portal.md

+1-1
Original file line numberDiff line numberDiff line change
@@ -25,7 +25,7 @@ This article helps you to add and remove a group from another group using Azure
2525
You can add an existing Security group to another existing Security group (also known as nested groups), creating a member group (subgroup) and a parent group. The member group inherits the attributes and properties of the parent group, saving you configuration time.
2626

2727
>[!Important]
28-
>We don't currently support:<ul><li>Adding Security groups to Office 365 groups</li><li>Adding Office 365 groups to Security groups or other Office 365 groups</li><li>Assigning apps to nested groups</li><li>Applying licenses to nested groups</li></ul>
28+
>We don't currently support:<ul><li>Adding groups to a group synced with on-premises Active Directory</li><li>Adding Security groups to Office 365 groups</li><li>Adding Office 365 groups to Security groups or other Office 365 groups</li><li>Assigning apps to nested groups</li><li>Applying licenses to nested groups</li></ul>
2929
3030
### To add a group as a member of another group
3131

articles/active-directory/hybrid/how-to-connect-fed-hybrid-azure-ad-join-post-config-tasks.md

+1-1
Original file line numberDiff line numberDiff line change
@@ -74,7 +74,7 @@ To register Windows down-level devices, you need to make sure that the Azure AD
7474
Add the Azure AD device authentication endpoint to the local Intranet zones on your Windows down-level devices to avoid certificate prompts when authenticating the devices:
7575
https://device.login.microsoftonline.com
7676

77-
If you are using [Seamless SSO](https://aka.ms/hybrid/sso), also enable “Allow status bar updates via script” on that zone and add the following endpoint:
77+
If you are using [Seamless SSO](how-to-connect-sso.md), also enable “Allow status bar updates via script” on that zone and add the following endpoint:
7878
https://autologon.microsoftazuread-sso.com
7979

8080
## 9. Install Microsoft Workplace Join on Windows down-level devices

articles/active-directory/hybrid/how-to-connect-health-diagnose-sync-errors.md

+1-1
Original file line numberDiff line numberDiff line change
@@ -23,7 +23,7 @@ The diagnosis feature has these benefits:
2323
- It provides a diagnostic procedure that narrows down duplicated attribute sync errors. And it gives specific fixes.
2424
- It applies a fix for dedicated scenarios from Azure AD to resolve the error in a single step.
2525
- No upgrade or configuration is required to enable this feature.
26-
For more information about Azure AD, see [Identity synchronization and duplicate attribute resiliency](https://aka.ms/dupattributeresdocs).
26+
For more information about Azure AD, see [Identity synchronization and duplicate attribute resiliency](how-to-connect-syncservice-duplicate-attribute-resiliency.md).
2727

2828
## Problems
2929
### A common scenario

articles/active-directory/hybrid/plan-hybrid-identity-design-considerations-identity-adoption-strategy.md

+1-1
Original file line numberDiff line numberDiff line change
@@ -86,7 +86,7 @@ You must also be aware of what capabilities will not be available:
8686
* Transition of Office to passive authentication allows them to support pure SAML 2.0 IdPs, but support will still be on a client-by-client basis
8787

8888
> [!NOTE]
89-
> For the most updated list read the article https://aka.ms/ssoproviders.
89+
> For the most updated list read the article [Azure AD federation compatibility list](how-to-connect-fed-compatibility.md).
9090
>
9191
>
9292

0 commit comments

Comments
 (0)