MicrosoftDocs/architecture-center/docs/security

Last 20 commits touching this section.

978a720

Reassign articles after org changes (#16843) * switch to clayton * Switch priyanka

0dfe987

PNP Edit: [AAC] Maintenance - Hybrid-ARB | Update Azure Hybrid Options + Getting Started articles (#16585) * Azure hybrid options - Complete article rewrite * Address hybrid options review feedback * Address hybrid architecture review comments * add spacing for clarity when reading * Reduce bullet spacing * updated spacing * Clarify disconnected operations eligibility * Refresh hybrid getting started guide Convert the hybrid Getting Started article to the YAML-plus-content pattern, move conceptual guidance and its diagram from Azure hybrid options, add browse metadata and a thumbnail, update navigation and inbound references, and keep detailed selection criteria in the options article. * Improve hybrid options workload flow Frame specialized service evaluation as the next step after selecting workload placement, infrastructure, and connectivity, and broaden the heading to reflect the services covered. * Fix hybrid getting started title Use singular architecture consistently in the YAML metadata and remove the duplicate H1 from the included Markdown body. * Address hybrid options review comments Add Azure Local operating limits and preview status, include Azure Arc-enabled Kubernetes in the decision-tree description, and preserve the intentional contributor attribution. * Update hybrid technology choices overview * Update technology choices review date * Clarify hybrid control plane options * Restore technology choices review date * Restore hybrid guide Markdown format Keep the Getting Started Architecture Guide as a standalone Markdown article, remove the YAML wrapper and its browse thumbnail, and update inbound links. * Clarify Azure IoT Operations offline limit Update the hybrid services diagram and accessible description to distinguish Azure Local disconnected operations from Azure IoT Operations' 72-hour offline window. Remove the redundant diagram footer. * Refine hybrid services diagram Replace the hybrid services diagram to keep Azure IoT Operations in the Edge and IoT category, clarify the Azure Local service list, and synchronize the accessible description. * Correct hybrid decision tree label Change the connected Azure Local path from "control plan" to "control plane" in the SVG and matching browse thumbnail. * Clarify Azure Local outage impact Document immediate cloud-dependent feature limitations, the 30-day reduced-functionality threshold, and AKS certificate-expiration risk during Azure connectivity loss. * Scope Azure Local sync guidance Qualify the documented 30-day synchronization and reduced-functionality behavior as applying to hyperconverged Azure Local deployments. * Apply suggestions from code review Co-authored-by: Chad Kittel <chad.kittel@gmail.com> * Update images * Address hybrid architecture review feedback Incorporate reviewer guidance on portability, edge AI, workload placement, recovery objectives, service wording, preview usage, and contributors. * Refine Azure Local reliability link text * Update hybrid options article date * improvements for Resiliency and recovery * Clarify hybrid deployment and connectivity guidance Correct Azure Local deployment taxonomy, distinguish ExpressRoute from VPN Gateway connectivity, and restore the overview article freshness date. * Update hybrid connectivity diagram label Rename the decision-tree branch to “Connectivity to Azure services” and refresh the matching browse thumbnail. * Clarify failover testing cadence Base Azure Local test-failover frequency on workload criticality, recovery objectives, business and compliance requirements, and material changes instead of a universal monthly interval. * Apply suggestion from @ckittel * Reference Sovereign Private Cloud in hybrid guidance * update ms.date * Reorder hybrid candidate approaches * Restore technology choices review date * Add private access selection guidance * Clarify Azure Arc machine support * Clarify VPN wording from review 5083098602 Addresses feedback from https://github.com/MicrosoftDocs/architecture-center-pr/pull/16383#pullrequestreview-5083098602 by distinguishing ExpressRoute from an encrypted site-to-site VPN in the article diagram and synchronized browse thumbnail. * get started article * options * edits * edits * edits * copilot * edits * not a tree * rearrange to fit template * Revert last 2 commits * revert toc * peer review cx * make png 3-2 * Apply batched suggestions from code review Co-authored-by: Chad Kittel <chad.kittel@gmail.com> * Fix link Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> * . * . * . * fix --------- Co-authored-by: Neil Bird <nebird@microsoft.com> Co-authored-by: Chad Kittel <chad.kittel@gmail.com> Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>

08d1398

Potential fix for pull request finding Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>

cd06f1f

Update AKS Bastion tunneling section to reflect GA status Co-authored-by: ckittel <671075+ckittel@users.noreply.github.com>

7c653f4

Pipeline: [New] ransomware resilient backup architecture article (#16117) * pull in Stephanie's changes * edits * Apply suggestion from @ckittel * Apply suggestion from @ckittel * Apply suggestion from @ckittel * Apply suggestions from PR review Spell out "vs." to align with established Microsoft style. --------- Co-authored-by: Chad Kittel <chad.kittel@gmail.com> Co-authored-by: Anna Huff <v-annahuff@microsoft.com>

8f07141

Update ms.author to pnp

d41c780

Pipeline: [Freshness] Get Started Guide: Identity (#16013) * identity * Update identity-start-here-content.md @claytonsiemens77 * Update identity-start-here-content.md * merge conflict * LAA * link * link * laa * move to md * links * links * redirect * links * edits * template * long desc * link * edit * edits * diagram * link * Apply suggestions from code review Co-authored-by: Jodi Martis <v-jodimartis@microsoft.com> * Apply suggestions from code review Co-authored-by: Jodi Martis <v-jodimartis@microsoft.com> * Update docs/identity/identity-get-started.md Co-authored-by: learn-build-service-prod-10[bot] <274431553+learn-build-service-prod-10[bot]@users.noreply.github.com> * Apply suggestions from code review removing Learn about... section Co-authored-by: Mick Alberts <v-albemi@microsoft.com> * Apply suggestions from code review remove extra spaces Co-authored-by: Mick Alberts <v-albemi@microsoft.com> * Update .openpublishing.redirection.json --------- Co-authored-by: Anastasia Harris <61602255+anaharris-ms@users.noreply.github.com> Co-authored-by: Jodi Martis <v-jodimartis@microsoft.com> Co-authored-by: learn-build-service-prod-10[bot] <274431553+learn-build-service-prod-10[bot]@users.noreply.github.com>

c840646

Delete Create an AD DS resource forest in Azure reference architecture (#15943) Retire the self-managed AD DS resource-forest-on-Azure-VM reference architecture (adds-forest) as part of the on-premises AD/AD FS topic cleanup. Running self-managed AD DS forests on IaaS VMs is not a cloud-first pattern; redirect readers to Microsoft Entra Domain Services (managed AD DS). - Delete adds-forest.yml, adds-forest-content.md, the diagram SVG, and the browse thumbnail. - Add redirect: adds-forest.yml -> /entra/identity/domain-services/overview. - Remove the retired entry from toc.yml, the index.yml featured card, and the curated reference-architecture lists in identity-start-here and security-get-started. - Repoint the Related-resources cross-link in the retained adds-extend-domain article to the Microsoft Entra Domain Services overview. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

9d68775

Delete Extend on-premises AD FS to Azure reference architecture Retire the AD FS-on-Azure-VM reference architecture (adfs) as part of the on-premises AD/AD FS topic cleanup. Running AD FS on IaaS VMs is not a cloud-first pattern; redirect readers to Microsoft Entra federation-to-cloud authentication migration guidance. - Delete adfs.yml, adfs-content.md, the diagram SVG, and the browse thumbnail. - Add redirect: adfs.yml -> /entra/identity/hybrid/connect/migrate-from-federation-to-cloud-authentication. - Remove the retired entry from toc.yml and the curated reference-architecture lists in identity-start-here and security-get-started. - Repoint Related-resources cross-links in azure-ad, adds-forest, and adds-extend-domain to the migration guidance. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

01c5081

Delete azure-ad reference architecture and redirect to Microsoft Entra Cloud Sync Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

cbacf90

fix links

09fc335

implement changes from other pr

0acaaa0

move

eaa79e2

Merge branch 'edit-get-started-security' of https://github.com/jmart1428/architecture-center-pr into edit-get-started-security

401f45b

fix merge conflicts

f36d338

Apply suggestions from code review Co-authored-by: Jodi Martis <v-jodimartis@microsoft.com>

727d453

Clarify Microsoft Entra ID description in documentation

eddc0df

Apply suggestions from code review Co-authored-by: Courtney Wales <62625502+Court72@users.noreply.github.com>

ff14eba

fixes

71fb0e0

edits