Last 20 commits touching this section.
Spelling fixes (#2125) * spelling an auto space removal * Apply suggestion from @ShawnKupfer --------- Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>
release-preview-entra-provision-to-ad -> main -- 9/24 10AM PDT (#14417) * Reapply "Users and Groups Provision to AD docs (#14052)" (#14263) (#14268) This reverts commit 2b47765dfd4bb42ecbecdf3e717959d6f189731f. * Retire the duplicate Microsoft Entra ID to Active Directory attribute mapping article (#14206) * Retire the duplicate Microsoft Entra ID to Active Directory attribute mapping article The configure article covers scoping filters and attribute mapping for both users and groups in the Microsoft Entra ID to Active Directory direction, so this article duplicates it. Delete the article and the nine images only it used, remove its table of contents entry, add a redirect to the configure article, and repoint the three inbound links. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: f42d872e-d26f-4e7c-91bc-cdab386b3ed3 * Fix link to retired attribute mapping article Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: f42d872e-d26f-4e7c-91bc-cdab386b3ed3 * Correct Cloud Sync subservice metadata Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: f42d872e-d26f-4e7c-91bc-cdab386b3ed3 --------- Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: f42d872e-d26f-4e7c-91bc-cdab386b3ed3 * Update Source of Authority guidance for provisioning to Active Directory (#14205) * Update Source of Authority guidance for provisioning to Active Directory Cover the scenarios that provisioning Microsoft Entra ID users and groups to Active Directory enables: keeping an Active Directory account for Kerberos applications after converting a user's Source of Authority, and governing that user's lifecycle from the cloud. Correct the ms.reviewer alias across the Source of Authority set. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: f42d872e-d26f-4e7c-91bc-cdab386b3ed3 * Apply the pre-review guidance to the Source of Authority articles The same issues the review team blocked on the provisioning pull request apply here: Learn doesn't allow future product plans, and file names shouldn't use internal abbreviations. State the password writeback limitation without dates in five places, and remove the commented-out section describing it, along with the diagram only that section used. Rename the lifecycle diagram so the file name says what it shows instead of using the UPAD abbreviation. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: f42d872e-d26f-4e7c-91bc-cdab386b3ed3 * Use Markdown headings for bookmarks and correct on-premises terminology Remove the two leftover HTML anchors before the headings; nothing links to them, and the headings already generate their own bookmarks. Expand the remaining on-prem abbreviations to on-premises. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: f42d872e-d26f-4e7c-91bc-cdab386b3ed3 * Remove the future availability promise from the readiness diagram Learn publishing policy doesn't allow future product plans, so drop '(available Sep 2026)' from the LDAP bind node. The first two lines wrap unchanged without it, so only the third line is repainted. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: f42d872e-d26f-4e7c-91bc-cdab386b3ed3 * Correct the Active Directory object enforcement link target The article is how-to-active-directory-object-enforcement.md, so the two links to how-to-ad-object-enforcement.md were reported as file-not-found. All remaining cloud-sync links resolve against the articles PR 14052 adds. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: f42d872e-d26f-4e7c-91bc-cdab386b3ed3 * Spell out the abbreviations in the lifecycle management diagram Regenerated from the PowerPoint source rather than patching the export: AD Users becomes Active Directory Users, SOA: AD becomes SOA: Active Directory, MIM becomes Microsoft Identity Manager, and On-Prem HR source becomes On-premises HR source. Resized the title to a single line and repositioned the two left-hand labels so the longer text clears the connector line and its containing shape. pre-hire is left as is. It's the product name of the built-in Lifecycle Workflows template, Onboard pre-hire employee, shown in an embedded screenshot of that UI. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: f42d872e-d26f-4e7c-91bc-cdab386b3ed3 * Update Source of Authority subservice metadata Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: f42d872e-d26f-4e7c-91bc-cdab386b3ed3 --------- Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: f42d872e-d26f-4e7c-91bc-cdab386b3ed3 * Remove invalid hybrid landing page subservice Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: f42d872e-d26f-4e7c-91bc-cdab386b3ed3 * Retrigger documentation validation Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: f42d872e-d26f-4e7c-91bc-cdab386b3ed3 --------- Co-authored-by: Dhanyah Krishnamoorthy <dhanyahk@users.noreply.github.com> Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Co-authored-by: Alma Jenks <v-alje@microsoft.com> Co-authored-by: Dhanyah Krishnamoorthy (SHE/HER) <dhanyahk@microsoft.com> Co-authored-by: prmerger-automator[bot] <40007230+prmerger-automator[bot]@users.noreply.github.com> Copilot-Session: f42d872e-d26f-4e7c-91bc-cdab386b3ed3
[BULK cpcli] Rebrand Microsoft 365 Copilot to Microsoft Copilot MAXADO-12279337 Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 4829db76-3855-456d-a4c0-9931bdb6e163
Revert "Users and Groups Provision to AD docs (#14052)" (#14263) This reverts commit 10c83918fad008a4b10314fe2c4e3cb75d73eec7.
Users and Groups Provision to AD docs (#14052) * Update provisioning guidance for users and groups Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: c4c9f8b7-6dbe-4b35-add8-014778a06938 * Add updated provisioning screenshots Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: c4c9f8b7-6dbe-4b35-add8-014778a06938 * Correct provisioning screenshot sequence Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: c4c9f8b7-6dbe-4b35-add8-014778a06938 * Rename provisioning configuration article Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: c4c9f8b7-6dbe-4b35-add8-014778a06938 * Render provisioning screenshots in Markdown previews Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: c4c9f8b7-6dbe-4b35-add8-014778a06938 * Add Entra to Active Directory documentation set Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: c4c9f8b7-6dbe-4b35-add8-014778a06938 * Expand Entra ID to AD provisioning documentation Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: c4c9f8b7-6dbe-4b35-add8-014778a06938 * Share Entra to AD prerequisites across guides Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: c4c9f8b7-6dbe-4b35-add8-014778a06938 * Apply documentation copy-edit recommendations Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: c4c9f8b7-6dbe-4b35-add8-014778a06938 * Clarify provisioning licensing and release timing Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: c4c9f8b7-6dbe-4b35-add8-014778a06938 * Expand Entra to AD provisioning guidance Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: c4c9f8b7-6dbe-4b35-add8-014778a06938 * Correct Entra to AD technical guidance Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 636f04f7-246d-4c40-ac81-6e0ddd9b2a8f * Restore provisioning licensing requirements Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 636f04f7-246d-4c40-ac81-6e0ddd9b2a8f * Copy edit Entra to AD provisioning docs Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: acef19f5-c154-4e27-936a-d80cb58f71b6 * Mark Entra to AD guidance as preview Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: acef19f5-c154-4e27-936a-d80cb58f71b6 * Merge AD user and group enforcement guidance Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: acef19f5-c154-4e27-936a-d80cb58f71b6 * Move app governance article under Group SOA Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: acef19f5-c154-4e27-936a-d80cb58f71b6 * Update cloud-first architect guidance Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: acef19f5-c154-4e27-936a-d80cb58f71b6 * Update SOA readiness decision tree Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: acef19f5-c154-4e27-936a-d80cb58f71b6 * Add missing UPAD scenarios and directory extension guidance Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: acef19f5-c154-4e27-936a-d80cb58f71b6 * Revise User SOA lifecycle and password guidance Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: acef19f5-c154-4e27-936a-d80cb58f71b6 * Address AD enforcement review feedback Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: acef19f5-c154-4e27-936a-d80cb58f71b6 * Address review feedback on scoping filter and test/enable docs - Replace duplicated prerequisites include in the configure and test/enable articles with a single funnel link, so prerequisites contain no calls to action, steps, or commands. - Drop the redundant Prerequisites H2 from the prerequisites article and promote the include headings to H2. - Trim redundancy in the Preserve the OU path section. - Remove the group target container screenshot from the Preserve a group's original organizational unit section; it shows a Switch() expression. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Document moving a provisioned user to a different OU Adds guidance for the reported scenario where changing the target container doesn't move an already-provisioned user, because the default parentDistinguishedName expression derives the OU from onPremisesDistinguishedName when that attribute is populated. - Add "Move a provisioned user to a different organizational unit" to the configure how-to, covering the cause, the three ways to move a user, and how to verify the move in provisioning logs. - Add a "Common tasks" table to the concept article so the task-level sections in the how-to are discoverable, plus a line explaining the target container precedence rule. - Add a "Provisioning users to Active Directory" FAQ entry. - Apply the funnel-of-success prerequisites pattern to the test and enable how-to. - Copy edits: restore the deployment options enumeration, expand SOA on first use, remove a stray comma, and drop a duplicate link. Screenshots are redacted to remove object IDs, SIDs, and account names. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: f42d872e-d26f-4e7c-91bc-cdab386b3ed3 * Note the role required to edit onPremisesDistinguishedName The attribute is read-only for non-privileged users, so calling out the Hybrid Identity Administrator requirement prevents readers from hitting an authorization failure when following the single-user move steps. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: f42d872e-d26f-4e7c-91bc-cdab386b3ed3 * Fix heading contradiction, stale link text, and reviewer alias in SOA articles - Rename 'Recommended Solution: Microsoft Entra Domain Services' to 'Another option' so the heading matches the body text this PR changed to 'Another option'. - Update link text in concept-source-of-authority-overview.md to the IT architects article's new title, matching the sibling reference already updated in user-source-of-authority-overview.md. - Correct ms.reviewer to dhanyahk in four articles (was dhanyak / dahnyahk). Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: f42d872e-d26f-4e7c-91bc-cdab386b3ed3 * Correct ms.reviewer alias to dhanyahk in remaining SOA articles Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: f42d872e-d26f-4e7c-91bc-cdab386b3ed3 * Resequence the configure article to match the setup order The article presented three setup H2s for the portal's two configuration sections, and mixed post-deployment tasks into the middle of setup. - Move 'Scope using directory extensions' under 'Configure scoping filters'; it was filed under 'Configure the target container' despite being a scoping topic. - Group post-deployment tasks (verify, AD-skip behavior, move a user's OU, roll back) under a new 'Verify and manage provisioned objects' section after attribute mapping, instead of nesting them under 'Preserve the OU path'. - Promote the OU-preservation and post-deployment task headings from H4 to H3 so they appear in the on-page navigation, which renders only H2 and H3. Maximum heading depth drops from H5 to H4. Anchors are generated from heading text, so no links break. - Move the orphaned 'select Save' step out of the rollback section to the end of the target container section, and reword the duplicated closing sentence so each configuration section ends with its own step. No prose was rewritten; the diff is heading levels, section order, and the two closing steps. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: f42d872e-d26f-4e7c-91bc-cdab386b3ed3 * Document user SOA provisioning scenarios and on-premises attribute writeback The 'Group and user SOA scenarios' table covered only group and membership provisioning, so there was no reference for how a user is provisioned based on the user's own source of authority. - Add a 'User SOA scenarios' table under 'How users are provisioned' covering cloud-native, SOA-converted, and B2B guest users in both directions. Users follow the same rule as groups: an on-premises source of authority blocks provisioning to AD, and a cloud source of authority blocks sync back to Microsoft Entra ID. - Add 'On-premises attributes written back to Microsoft Entra ID' listing the five attributes stamped on the cloud object after provisioning. This explains how a cloud-native user acquires an onPremisesDistinguishedName, which the OU-move procedure depends on, and cross-link the two. - Rename the existing table to 'Group membership SOA scenarios' to match what it documents. Copy-edit and security review fixes: - Spell out Source of Authority and business-to-business on first use. - Use 'Microsoft Entra ID' instead of bare 'Entra' in 18 sync-direction table cells. - Remove a duplicated explanation and a repeated SID expansion. - Remove the stale sfi-image-nochange tag from the configure article. It attested that the article's images needed no review, but three screenshots were added after that attestation, so the new images would have been skipped by image scanning. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: f42d872e-d26f-4e7c-91bc-cdab386b3ed3 * Correct group membership behavior for user provisioning to AD Three articles stated that groups provisioned to AD DS can contain only on-premises synchronized users or cloud-created security groups. That was true when only group provisioning existed, but user provisioning gives cloud-managed users an AD account, so those users can be written as members. Membership depends on whether the member has an AD account, not on the member's source of authority. A member can have one because it's synchronized from AD or because user provisioning created it. - Correct the claim in the deployment options article, the shared prerequisites include, and the multi-forest section of the topologies article. - Rewrite the group membership scenarios table. Split it by source direction, replace the sync direction column with the member's AD account, and add the two cases that user provisioning changes: cloud members of a cloud group are now written as member references when those members are provisioned to AD. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: f42d872e-d26f-4e7c-91bc-cdab386b3ed3 * Correct membership behavior, apply review feedback, and extract group OU setup Review feedback (SahaAditi): - Only users retain their original organizational unit automatically. Groups need a directory extension, so the overview no longer claims both. - Rewrite the deployment options table. What's generally available is memberships to on-premises owned users, which the previous wording overstated. - Replace the combined-versus-standalone section. Separate user and group configurations aren't possible for one domain, because there's one configuration per AD domain. - Generalize scale limits from groups to objects, and add limits for users. Users, groups, and membership links count toward the same total. - Reword the licensing row so it states what existing configurations need rather than inviting comparison with new ones. Technical corrections: - Group membership now depends on whether the member has an AD account, not on the member's source of authority alone. Rebuild the scenarios table around the configuration, and note that the on-premises membership setting must be enabled. - Add the out-of-scope row to the deletes table, correct the agent build to 1.1.2334.0, remove the password hash sync option, and add the Mooncake app role ID. - One provisioning job now handles users and groups, so drop 'group' from the job references and remove the suggestion to split a domain across multiple jobs. Structure and formatting: - Extract the GroupDN setup procedure into its own how-to. It's a one-time task performed before Source of Authority conversion, it carried a nested tab group, and it made the target container section 37 percent of the configure article. That article drops from 549 to 433 lines. - Convert 28 images to the Learn :::image::: syntax used elsewhere in this docset, which also adds borders and completes the alt text. - Render prerequisites as a checklist, and fix three alt-text values that lacked a media type and a period. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: f42d872e-d26f-4e7c-91bc-cdab386b3ed3 * Note the built-in isWritebackEnabled property in the directory extension tutorial The tutorial teaches a custom WritebackEnabled extension attribute so that scoping filters can select which groups are written back. Microsoft Entra ID now exposes a built-in isWritebackEnabled property through Microsoft Graph that attribute value filtering can use directly, so readers should know the workaround is optional before they follow the steps. - Add a note at the start of the group scoping scenario pointing to the built-in property and to attribute value filtering. - Repoint the tip that referenced the writeback flag. Its link resolved to docs/identity/users/groups-write-back-portal.md, which doesn't exist in this repo, so the tip now refers to the built-in property described earlier in the article. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: f42d872e-d26f-4e7c-91bc-cdab386b3ed3 * Retitle the group organizational unit article and align its link text The H1 read 'Set up organizational unit preservation for a group', which named the mechanism rather than the outcome and didn't match the article's own metadata title or its TOC label. The H1 now states the reader's goal and the trigger, and the three articles that link to it use matching link text. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: f42d872e-d26f-4e7c-91bc-cdab386b3ed3 * Rewrite the provisioning walkthrough around a governance scenario The tutorial was four disconnected examples, and two of them didn't work as written. Example 2 told the reader to provision Britta Simon while explaining that the default dirSyncEnabled IS FALSE clause admits only cloud-managed users, and she's a synchronized user. Each example also opened by creating a new configuration for the same domain, which a domain doesn't allow. The tutorial now follows one scenario. Contoso runs a Kerberos expense application that authorizes on an AD DS group, the cloud group that decides access holds both synchronized and cloud-managed members, and the cloud-managed members can't reach the application because they have no AD DS account to reference. - Add cloud-managed users to the cast, since user provisioning exists for them, and keep the synchronized users so the group has mixed membership. - Use one configuration throughout, and cover both scoping modes: Selected for the fastest sync, and All with attribute value filtering when the scope needs to hold at scale. - Test on demand before enabling, rather than after. - Explain that a provisioned account exists so Kerberos works, that the user signs in with a passwordless method through Cloud Kerberos Trust, and that applications requiring a password aren't supported until password writeback. - Connect the result to Microsoft Entra ID Governance, so access packages, access reviews, and lifecycle workflows reach the on-premises application. - Drop 11 bookmark anchors that preserved headings from an unpublished draft rather than any published anchor. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: f42d872e-d26f-4e7c-91bc-cdab386b3ed3 * Remove the user default security clause and add lifecycle and enforcement steps The docs stated a default security clause of dirSyncEnabled IS FALSE for users. The source article documents that condition only as part of the group default security grouping, so the user variant was an extrapolation. Removed it from the configure article, the deployment options article, and the tutorial. Synchronized users are already excluded because their Source of Authority is on-premises, so the tutorial now explains the exclusion that way instead of attributing it to a filter clause. Tutorial additions: - Add a step to mark the provisioned users and group for AD object enforcement, so the objects accept changes only from the provisioning service, with a recommendation to install the policy in Audit mode first. - Replace the governance section with the full lifecycle, from HR-driven provisioning into Microsoft Entra ID through access assignment, provisioning to AD DS, attribute changes, and offboarding, so the tutorial shows where provisioning sits in a joiner, mover, and leaver flow. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: f42d872e-d26f-4e7c-91bc-cdab386b3ed3 * Retire the superseded Entra ID to AD attribute mapping article Two articles covered scoping filters and attribute mapping for the Microsoft Entra ID to Active Directory direction. The older one predates user provisioning: its schema table lists only group attributes, it has no user schema, and it marks six mappings as not updatable in the UI even though the portal now supports adding mappings per object type for user, group, and contact. The configure article covers every section the older article had, for both users and groups, so the older article is removed rather than repaired. - Delete how-to-attribute-mapping-entra-to-active-directory.md and add a redirect to the configure article. - Remove its TOC entry and repoint the one inbound link in group-writeback-cloud-sync.md. - Remove nine images that no other article referenced. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: f42d872e-d26f-4e7c-91bc-cdab386b3ed3 * Remove Entra ID to AD content from the AD to Entra ID attribute mapping article The Active Directory to Microsoft Entra ID attribute mapping article carried a section for the opposite direction, so the Microsoft Entra ID to Active Directory procedure lived in an article whose title says it covers AD to Microsoft Entra ID. - Move the procedure for adding an attribute mapping into the configure article, which is now the only article covering the Microsoft Entra ID to Active Directory direction. The steps include selecting the object type, so they apply to users, groups, and contacts. - Remove the section and its bookmark from the AD to Microsoft Entra ID article, and repoint its opening cross-reference, which still named the article retired in the previous commit. - Remove the screenshot that no other article referenced. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: f42d872e-d26f-4e7c-91bc-cdab386b3ed3 * Fix two bookmarks left dangling by the attribute mapping consolidation Retiring the Microsoft Entra ID to Active Directory attribute mapping article, and removing the Entra ID to AD section from the AD to Entra ID article, left two links pointing at headings that no longer exist. The build reported the first as a bookmark-not-found warning. - migrate-group-writeback.md now points to the add-a-mapping steps in the configure article. - The governance include now points to the target container section of the configure article. - Expand Source of Authority on first use in the tutorial. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: f42d872e-d26f-4e7c-91bc-cdab386b3ed3 * Add recommended configuration guidance and correct attribute value filtering behavior Attribute value filtering is now available with the Selected users and groups scope. The admin center warns against it rather than blocking it, so three statements that described the old enforcement were wrong. - Correct the two statements in the configure article and one in the tutorial. - Add a Recommended configuration section to the deployment options article, covering the two scoping modes and the on-premises membership setting, with the reason each choice affects cycle time. The two scoping modes have opposite filter requirements, so the section states that directly and tells readers to remove filters when changing a configuration from All to Selected. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: f42d872e-d26f-4e7c-91bc-cdab386b3ed3 * Recommend cloud-managed groups over provisioning membership to on-premises users The guidance for the on-premises membership setting described it as a per-cycle cost to enable only when needed. The actual recommendation is architectural: convert the group's Source of Authority to the cloud and provision that cloud-managed group, which removes the need for membership links to synchronized users. - Rewrite the table row to say the setting is transitional. - Add a short section explaining the recommended end state and linking to group Source of Authority configuration. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: f42d872e-d26f-4e7c-91bc-cdab386b3ed3 * Remove remaining enforcement language for attribute value filtering Attribute value filtering is now warned about rather than blocked, so the surrounding text no longer describes it as a constraint. - Drop the unsupported-configuration bullet for unfiltered All scoping. It's covered by the Recommended configuration section, and it isn't a support boundary now. - Correct the scope-by-assignment intro, which said the choice determines whether filtering is available. It determines whether filtering is appropriate. - Change 'you must configure' and 'requires at least one attribute filter' to recommendations. - Correct alt text that described attribute filters as required, and add TODO comments marking two screenshots for recapture. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: f42d872e-d26f-4e7c-91bc-cdab386b3ed3 * Attribute scoping warnings to the provisioning configuration The warnings come from the provisioning configuration experience, not the Microsoft Entra admin center generally, so name the surface that shows them. Also correct the attribute value filtering guidance, which still called a filter 'required' with All users and groups. It's recommended, not enforced. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: f42d872e-d26f-4e7c-91bc-cdab386b3ed3 * Clarify why attribute value filtering suits only one scoping mode The guidance said a filter 'does real work' with All users and groups and 'only adds work' with Selected, using the same word for two different things. Name what the filter actually does: it narrows the scope in one mode, and adds processing time in the other. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: f42d872e-d26f-4e7c-91bc-cdab386b3ed3 * Correct on-demand provisioning direction and align both TOC trees The two on-demand articles each described the other direction. The Microsoft Entra ID to Active Directory article said it covered provisioning to Microsoft Entra ID, and pointed to itself as the article for the other direction. Correct both intros and point each at its counterpart. Also state that on-demand provisioning applies to a single user or group, matching the unified job, and flag the group-only steps and screenshots for update. In the TOC, list the same articles in the same order in both Provision Microsoft Entra ID to Active Directory trees, and move the directory extensions concept next to the tutorial that implements it. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: f42d872e-d26f-4e7c-91bc-cdab386b3ed3 * Restore the Active Directory to Microsoft Entra ID on-demand article That article is outside the scope of provisioning Microsoft Entra ID to Active Directory. Its intro has the same swapped-direction defect as its counterpart, but the fix belongs in separate work. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: f42d872e-d26f-4e7c-91bc-cdab386b3ed3 * Add a user example to the directory extensions tutorial The tutorial covered only groups, and only the scoping-filter use. Directory extensions also carry values into Active Directory attributes, and both uses work for users and groups. Restructure the article around Groups and Users tabs so the shared setup (Graph PowerShell SDK, CloudSyncCustomExtensionsApp, and its service principal) is written once instead of repeated per scenario. Add the user example: create a User-targeted extension, populate it, map it to an Active Directory attribute, and verify the result. Add a section for users whose Source of Authority is converted, which map from extensions that already hold the values rather than creating new ones. In the concept article, repair the table row that was missing its leading pipe, and point to the tutorial as covering both users and groups. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: f42d872e-d26f-4e7c-91bc-cdab386b3ed3 * Let readers expand the diagrams added in this pull request Six diagrams and illustrations were added without a lightbox, so readers couldn't enlarge them. Diagrams carry detail that's hard to read at inline width. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: f42d872e-d26f-4e7c-91bc-cdab386b3ed3 * Match each example's setup to the example, and correct stale link text The directory extensions tutorial listed one merged set of assumptions, so Users-tab readers saw four named users and three organizational units that only the Groups example uses, and never saw their own prerequisites. Tab the environment list, restore the user prerequisites, and move the group writeback diagram into the Groups tab. The provisioning walkthrough was retitled to reflect its governance scenario, but four links still called it 'Provision users and groups to Active Directory'. Point them at the current title. Rename two closing sections to Related content so the article set is consistent, and add the missing tutorial link to the directory extensions concept article. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: f42d872e-d26f-4e7c-91bc-cdab386b3ed3 * Give the provisioning articles a next step The articles form a sequence, from the overview through deployment options, prerequisites, configuration, testing, the tutorial, and enforcement, but each one ended in an undifferentiated list of related links. A reader finishing an article had no signal about which link continues the path. Add a Next step action to each article in the sequence, and route the three side branches (preserve a group's organizational unit, directory extensions, and the extensions tutorial) back to test and enable. Remove the promoted link from Related content so it isn't listed twice. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: f42d872e-d26f-4e7c-91bc-cdab386b3ed3 * Follow the task path in the next step, not the table of contents order The next step chain was built from table of contents order, which groups conceptual material ahead of procedures. That routed a reader who just chose a deployment option into How provisioning to Active Directory works, a reference article about Source of Authority scenarios, membership, and deletes, instead of into the setup they were ready to start. Point deployment options at the prerequisites, and keep how provisioning works reachable from Related content everywhere with its own next step back onto the path. Point test and enable at enforcement. The tutorial covers the same configuration end to end, so it reads as a parallel entry point rather than a follow-on step; it stays in Related content and still leads to enforcement. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: f42d872e-d26f-4e7c-91bc-cdab386b3ed3 * Describe the shipping behavior, not how it changed during development This is the first release of the feature, so readers have no earlier version to contrast against. Two screenshot notes described attribute value filtering as having changed from blocking to warning, and attributed the warning to the admin center rather than the provisioning configuration. Rewrite both notes to state what the capture should show. Also drop 'no longer required' from the isWritebackEnabled note, which implied a prior requirement the reader never saw. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: f42d872e-d26f-4e7c-91bc-cdab386b3ed3 * Remove the scope by attribute screenshot that shows filters as required The capture presents an attribute filter as required for each enabled object type, which isn't how the feature behaves. Removing it is better than shipping a screenshot that contradicts the surrounding text; the section reads fine without it, and a correct capture can be added later. Drop the speculative recapture note on the Selected users and groups screenshot. That capture shows the Scope by assignment step, which is accurate as it stands. In the on-demand article, generalize the procedure to cover selecting a user or a group, and note that the screenshots show the group flow. Preserve the old verify-a-group anchor on the renamed heading. Remove the directory extension questions about dropdown naming and repeated writes. The section doesn't assert either behavior, so the notes asked for detail to add rather than flagging anything incorrect. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: f42d872e-d26f-4e7c-91bc-cdab386b3ed3 * Set the users-only scale limit to 200K The previous 500K value was provisional and carried a note asking Engineering to confirm it. The supported ceiling is 200K users, matching the tenant scale conditions that group provisioning already documents: fewer than 200K users, fewer than 40K groups, and fewer than 1M group memberships. Add a Notes column so the users table explains the limit the way the groups table above it does. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: f42d872e-d26f-4e7c-91bc-cdab386b3ed3 * Shorten two titles past the search-result cutoff and break up dense sentences Search results and browser tabs truncate around 60 characters. The preserve-OU title ran to 85 and the tutorial to 79, so both lost their ending. Shorten each to lead with what the reader searches for; the H1 keeps the full phrasing. Trim the tutorial description from 214 characters, which also truncates in search results. Split four sentences that ran past 35 words, including the membership rule and the enforcement script prerequisite, where the length was burying the instruction. Convert the shared setup sentence in the directory extensions tutorial into the list it was describing. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: f42d872e-d26f-4e7c-91bc-cdab386b3ed3 * Show the Provision on demand experience for users and for groups The procedure described a single group-only flow, but the page has separate Users and Groups tabs that ask for different input: a user is chosen by name, while a group also asks which members to test. The two screenshots were generic and predated user provisioning. Mirror the page with Users and Groups tabs, add screenshots for each path, and describe the result page: the four steps it reports, what Success and Skipped mean, and the Retry and Provision another object buttons. Blur the tenant domain, configuration name, signed-in account, user and group names, the user principal name, and the group object ID in all five captures. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: f42d872e-d26f-4e7c-91bc-cdab386b3ed3 * Move the Source of Authority guidance updates out of this pull request Those articles describe converting Source of Authority, not provisioning to Active Directory, and their changes stand on their own. Three of them link to articles this pull request adds, so they follow it rather than ship with it. The full set is preserved on the upad-full-backup branch and reapplies once this pull request merges. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: f42d872e-d26f-4e7c-91bc-cdab386b3ed3 * Keep the duplicate attribute mapping article until its replacement ships Retiring that article depends on this pull request: the configure article only covers both object types for the Microsoft Entra ID to Active Directory direction once these changes merge, and one inbound link targets a heading this pull request adds. Restore the article, its nine images, its table of contents entry, and the two inbound links, and drop its redirect. The retirement follows as its own pull request. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: f42d872e-d26f-4e7c-91bc-cdab386b3ed3 * Repoint the Source of Authority links to the tutorial this pull request deletes Two Source of Authority articles link to the group provisioning tutorial that this pull request replaces. Reverting those articles to their published state reintroduced the links, and a relative link to a deleted file is a broken link no matter what redirect exists. Point them at how provisioning works, which now carries the nested membership behavior the second link was citing. Those two files otherwise stay at their published state and move with the rest of the Source of Authority work. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: f42d872e-d26f-4e7c-91bc-cdab386b3ed3 * Keep the image the published attribute mapping article still uses The image was deleted along with the group provisioning tutorial, but the Active Directory to Microsoft Entra ID attribute mapping article references it too, and that article stays at its published state in this pull request. Deleting the image left a broken reference behind. The image goes when the section that uses it goes, in the pull request that retires the duplicate article. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: f42d872e-d26f-4e7c-91bc-cdab386b3ed3 * Show the attribute value filtering warnings and refresh the outdated wizard captures Attribute value filtering is now reachable from Selected users and groups, so the wizard gained a Scope by attribute step and the captures showing six steps no longer match. Replace the Scope by assignment and Configure group membership captures with the current seven-step wizard, which also picked up revised on-screen text. Add captures of the Scope by attribute step for both scoping modes, showing the warning each one raises: add a filter with All users and groups, remove filtering with Selected users and groups. Correct the target container section, where two captures were transposed. The introduction showed the edit mapping pane while the expression bullet showed the wizard step, so neither matched its alt text. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: f42d872e-d26f-4e7c-91bc-cdab386b3ed3 * Repoint the last two links to the tutorial this pull request deletes Both use the site-relative form, so they weren't caught by the earlier pass that searched for the file path. The redirect resolves the address, but each link is labeled with an article title that no longer exists. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: f42d872e-d26f-4e7c-91bc-cdab386b3ed3 * Resolve the pre-review blocking issues State the password writeback limitation without dates. Learn doesn't allow future product plans, and every occurrence was about when password writeback ships, so each one now describes only what's true today: it isn't available, and Kerberos applications work through passwordless authentication instead. Rebuild the provisioning flow diagram without the Coming September badges, and keep the generator alongside it so the next edit doesn't need pixel work. Replace blurring with solid color blocks in nine screenshots, as the secure screenshot guidance requires. Crop the review and enable capture to the panel the step is about, which removes the surrounding tenant details and real job identifiers. Spell out the abbreviations two file names used: how-to-ad-object-enforcement becomes how-to-active-directory-object-enforcement, and the organizational unit image name is written out. Retarget the two existing enforcement redirects at the new name so they don't chain. Remove a hyphen that made a single instruction look like a list. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: f42d872e-d26f-4e7c-91bc-cdab386b3ed3 * Replace blurring in the two remaining flagged screenshots The distinguished name and Microsoft Graph captures still used blurring, which the secure screenshot guidance doesn't accept. Cover the SAM account name, security identifier, user principal name, organizational unit path, and the user identifier in the request URL with blocks matching the background. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: f42d872e-d26f-4e7c-91bc-cdab386b3ed3 * Rework the flagged screenshots to meet the redaction guidance Replace every remaining blurred area with a flat block sampled from the surrounding chrome, and crop the SOA-Policies capture to its callout since the rest of that screenshot was blur. Match the admin center's dark top bar instead of covering the account chip with white, and measure each block against the actual glyph and control bounds so no letter is half covered and no dialog border is cut. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: f42d872e-d26f-4e7c-91bc-cdab386b3ed3 * Point cross-references at the Entra ID to Active Directory articles Several links in the Entra ID to AD set resolved to the AD to Entra ID twin, which sends readers into the opposite provisioning direction: - Configure and Preserve OU both pointed at custom-attribute-mapping.md instead of custom-attribute-mapping-entra-to-active-directory.md. - The directory extensions article listed the AD to Entra ID attribute mapping article in Related content. - Object enforcement pointed at the general cloud sync prerequisites rather than the Entra ID to AD prerequisites. - Reworded the directory extensions intro so its link to the AD to Entra ID article reads as a cross-direction pointer rather than further reading. Links that intentionally cross directions, the shared provisioning agent requirements, and references to the cloud sync product overview are left as they were. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: f42d872e-d26f-4e7c-91bc-cdab386b3ed3 * Move on-demand provisioning under Configure provisioning to AD On-demand provisioning is how you validate a single user or group before enabling the job, so it belongs beside Test and enable provisioning rather than as a sibling of the Configure node. Applied to both the task tree and the cloud sync reference tree so the two stay aligned. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: f42d872e-d26f-4e7c-91bc-cdab386b3ed3 * Convert the remaining single-bullet prerequisites into sentences The pre-review asked for these one-item lists to be removed. The blocking instance was fixed, but the non-blocking ones were reported as done without actually being changed. This corrects all three. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: f42d872e-d26f-4e7c-91bc-cdab386b3ed3 * State the correct provisioning direction in the on-demand article intro The Active Directory to Microsoft Entra ID article said it covered provisioning from Microsoft Entra ID to Active Directory, then offered the same direction as the alternative, so both halves of the sentence pointed readers away from the article they were already on. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: f42d872e-d26f-4e7c-91bc-cdab386b3ed3 * Point to the on-demand article instead of repeating its steps The Test and enable article carried an abbreviated copy of the on-demand procedure and then linked to the full one, so readers met the same steps twice. The section now explains why you test on demand and what the results show, and sends readers to the article that documents the procedure for both users and groups. Removed the screenshot that duplicated one already in that article. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: f42d872e-d26f-4e7c-91bc-cdab386b3ed3 * Apply copy-edit findings and remove images this pull request orphaned Copy edit: align the on-demand article intro with its sibling's wording and state the direction consistently, move the post-test pointer above the link so the section doesn't end mid-flow, name what the portal message refers to, and drop the redundant extend-with-extensions phrasing. The eleven deleted images were referenced only by the tutorial this pull request removes or by the configure article before it was rewritten, so nothing points at them anymore. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: f42d872e-d26f-4e7c-91bc-cdab386b3ed3 * Replace tenant account data in the on-demand screenshots The result cards showed a real test tenant: a user principal name including the tenant's onmicrosoft.com domain, and a group object identifier. Both are now fictitious, using contoso.com and an approved sample object ID, rendered in the same face and size so the cards still read as product UI. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: f42d872e-d26f-4e7c-91bc-cdab386b3ed3 * Remove the settings icon left partly covered in the top bar The account chip block began mid-icon on three of the captures, leaving a five to eight pixel sliver of the settings gear. Removed the icon on all five rather than only the three reported, so the set doesn't end up showing a gear on two captures and none on the others. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: f42d872e-d26f-4e7c-91bc-cdab386b3ed3 --------- Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: c4c9f8b7-6dbe-4b35-add8-014778a06938 Copilot-Session: 636f04f7-246d-4c40-ac81-6e0ddd9b2a8f Copilot-Session: acef19f5-c154-4e27-936a-d80cb58f71b6 Copilot-Session: f42d872e-d26f-4e7c-91bc-cdab386b3ed3
Update road-to-the-cloud-introduction.md (#13968) * Learn Editor: Update road-to-the-cloud-introduction.md * Learn Editor: Update road-to-the-cloud-introduction.md
New multitenant arch guide per Ben Athawes, Ramiro Calderon (#13857) * New multitenant arch guide per Ben Athawes, Ramiro Calderon * fix issues 0.1 * fix issues 0.2 * fix issues 0.3 * change request 0.1 * fix issues 0.4 * fix issues 0.5 * change 0.6 * change 0.7 * change 0.8 * change 0.9 * change 1.0 * change 1.1 * Update description of separate tenant architecture (#9) Clarified that the separate tenant architecture decouples collaboration workloads rather than critical workloads from the main workforce tenant. * Enhance detail on administrative access approaches (#10) Added details on administrative access approaches in multitenant architecture. * Revise single production tenant article for clarity (#11) Updated the article to clarify the focus on operating a single production tenant, including workforce identities and external collaboration. * Apply suggestions from code review Co-authored-by: bathawes <61694741+bathawes@users.noreply.github.com> * Apply suggestions from code review Co-authored-by: bathawes <61694741+bathawes@users.noreply.github.com> * Fix invalid file link: Tenant Governance FAQ is faq.yml, not faq.md Resolves the Learn build warning 'file-not-found' at line 66 of docs/architecture/multitenant-architecture-guide.md. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: fc4d71de-b3ea-423a-91d5-40c82cc22dd1 * Apply suggestions from code review Applies the 33 suggested changes from Ben Athawes's review (pullrequestreview-4796399609) across the seven tenant estate guidance articles: - Rename the "Separate tenants for ..." pattern references to "Isolated tenants for ..." throughout the series. - Broaden the intended audience in the guide intro. - Add a "When to integrate an app or workload with an existing tenant" section to the guide, with a pointer to it from the baseline article. - Link parallel-identity-options.md from the guide body and Related content. - Retitle "People who shape architecture decisions" to "People whose needs shape tenant architecture". - Consolidate the cross-tenant topology diagrams in multitenant-organization.md to a single application-hub diagram and defer to the canonical topologies article. - Fix the broken in-article reference to the B2B limitations section. Two single-line suggestions on multitenant-organization.md lines 30 and 32 are superseded by the later lines 30-48 rewrite and were not applied separately. Co-authored-by: Ben Athawes <bathawes@users.noreply.github.com> Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 161e45b8-d1b4-4739-a5f0-4565ce997925 * Add ai-usage metadata to the tenant estate guidance articles The seven articles were edited with AI assistance, so they carry ai-usage: ai-assisted. Placement follows the repo convention of declaring ai-usage after ms.date. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 161e45b8-d1b4-4739-a5f0-4565ce997925 * Apply suggestions from code review Co-authored-by: bathawes <61694741+bathawes@users.noreply.github.com> * Apply suggestions from code review Co-authored-by: bathawes <61694741+bathawes@users.noreply.github.com> * Rename multitenant-* articles to tenant-estate-* and fix TOC labels (#14) Rename the 7 net-new tenant estate articles so their URL slugs reflect the tenant estate terminology (slug = file name), update all internal cross-article links, and correct the TOC node/group labels. - multitenant-architecture-guide -> tenant-estate-guide - multitenant-single-production -> tenant-estate-primary - multitenant-organization -> tenant-estate-collaborating - multitenant-nonproduction-environment -> tenant-estate-nonproduction - multitenant-critical-production -> tenant-estate-critical-production - multitenant-business-partner-access -> tenant-estate-business-partner - multitenant-hybrid-identity-isolation -> tenant-estate-hybrid-identity TOC: parent group -> "Microsoft Entra tenant estate guidance"; "Single production tenants" -> "Primary production tenants"; "Multitenant organizations" -> "Collaborating production tenants". No redirects needed (all files are net-new/unpublished). Co-authored-by: bathawes <bathawes@users.noreply.github.com> Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 5c5a15dd-b13b-4111-93d6-fb00ee45fd66 * Apply suggestions from code review Co-authored-by: Marsh Macy <253514592+mmacy-msft@users.noreply.github.com> * Apply suggestions from code review Co-authored-by: Marsh Macy <253514592+mmacy-msft@users.noreply.github.com> * Apply suggestion from @mmacy-msft --------- Co-authored-by: Lynne O'Connor <103511101+lynneoconnor@users.noreply.github.com> Co-authored-by: bathawes <61694741+bathawes@users.noreply.github.com> Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Co-authored-by: Ben Athawes <bathawes@users.noreply.github.com> Copilot-Session: fc4d71de-b3ea-423a-91d5-40c82cc22dd1 Copilot-Session: 161e45b8-d1b4-4739-a5f0-4565ce997925 Copilot-Session: 5c5a15dd-b13b-4111-93d6-fb00ee45fd66
Update how-to-universal-tenant-restrictions.md (#13959) * Update how-to-universal-tenant-restrictions.md * Update GSA PoC internet access documentation Removed validation step for Universal Tenant Restrictions from the documentation.
Revise tenant restrictions documentation for clarity (#13885) * Revise tenant restrictions documentation for clarity Updated sections on tenant restrictions, including enforcement points and validation steps. Modified headings and clarified details regarding Microsoft Entra ID and Microsoft Graph. * Update links and terminology for tenant restrictions
Redirect Entra group licensing UI docs to Microsoft 365 (#13731) * Redirect Entra group licensing UI docs to Microsoft 365 AB#593418 AB#592863 Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Add preserve-view to Microsoft 365 licensing links AB#593418 AB#592863 Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Flatten users troubleshooting TOC entries AB#593418 AB#592863 Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> --------- Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
new and updated articles per Ben Athawes (ADO 28575) (#13644) * new and updated articles per Ben Athawes (ADO 28575) * add files * fix issue 0.01
Add security operations for network access guide (#13531) * Add GSA security operations guide Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Fix GSA SecOps validation feedback Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Add GSA SecOps metadata reviewer Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Improve GSA SecOps article clarity Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Add architecture TOC pointer for GSA SecOps guide Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Rename GSA SecOps guide for network access Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Move GSA SecOps acronym table to end Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Revert "Move GSA SecOps acronym table to end" This reverts commit 5970e1d59edba962320b95cf79bae3b1147cc451. * Spell out Global Secure Access in SecOps guide Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Incorporate Global Secure Access SecOps feedback Updates the SecOps guide from Thomas Detzner's engineering feedback commits: - 6a4b566 Replace traffic-based new source IP rule with RN config-change hunting summary - 5574096 Restructure remote-network config-change detection proposal - 42f2407 Fix Private Access SecOps detections Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Update SecOps what to look for links Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> --------- Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
yml-conversion1-061926 (#13583) * yml-conversion1-061926 Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Remove circular redirect for how-to-manage-groups.yml Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> --------- Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
[BULK UPDATE] User Story 573314: Ensure every doc in MSec repos has an author from MSec Docs (entra-docs-pr 1) (#13305) * [BULK UPDATE] User Story 573314: Ensure every doc in MSec repos has an author from MSec Docs (entra-docs-pr 1) * Fix duplicate reviewer * Remove from individual files
Merge pull request #13379 from kenwith/kenwith/ado-582534-fix-ca-link Fix broken 'What is Conditional Access?' link in ID Protection analyze guide
Fix product name: 'Azure AD FS' -> 'AD FS' The hybrid authentication components list referred to 'Active Directory Federation Services (Azure AD FS)'. The correct product name is 'Active Directory Federation Services (AD FS)' — there is no 'Azure AD FS'. The same article already uses '(AD FS)' correctly elsewhere (line 82). Addresses AI-suggested content update entra-docs #12953 / ADO 582524. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Fix broken 'What is Conditional Access?' link The link pointed to /azure/data-explorer/security-conditional-access (an Azure Data Explorer path) instead of the Conditional Access overview. Repointed to the Conditional Access overview article via a relative repo link. Addresses AI-suggested content update entra-docs #12772 / ADO 582534. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>