You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: docs/fundamentals/concept-learn-about-groups.md
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -44,7 +44,7 @@ There are two group types and three group membership types. Review the options t
44
44
For example, you can create a security group so that all group members have the same set of security permissions. Members of a security group can include users, devices, [service principals](~/architecture/service-accounts-principal.md), and other groups (also known as nested groups), which define [access policy and permissions](identity-fundamental-concepts.md). Owners of a security group can include users and service principals.
45
45
46
46
> [!NOTE]
47
-
> When nesting an existing security group to another security group, only members in the parent group will have access to shared resources and applications. Nested group members don't have the same assigned membership as the parent group members. For more info about managing nested groups, see [How to manage groups](how-to-manage-groups.yml#add-members-or-owners-of-a-group).
47
+
> When nesting an existing security group to another security group, only members in the parent group will have access to shared resources and applications. Nested group members don't have the same assigned membership as the parent group members. For more info about managing nested groups, see [How to manage groups](how-to-manage-groups.yml#add-a-group-to-another-group).
48
48
49
49
**Microsoft 365:** Provides collaboration opportunities by giving group members access to a shared mailbox, calendar, files, SharePoint sites, and more.
Copy file name to clipboardExpand all lines: docs/identity/authentication/how-to-enable-authenticator-passkey.md
+5-2Lines changed: 5 additions & 2 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -5,7 +5,7 @@ description: Learn about how to enable passkeys in Microsoft Authenticator for M
5
5
ms.service: entra-id
6
6
ms.subservice: authentication
7
7
ms.topic: how-to
8
-
ms.date: 10/14/2024
8
+
ms.date: 10/23/2024
9
9
10
10
11
11
ms.author: justinha
@@ -47,7 +47,10 @@ An Authentication Policy Administrator needs to consent to allow Authenticator i
47
47
When attestation is enabled in the passkey (FIDO) policy, Microsoft Entra ID tries to verify the legitimacy of the passkey being created. When the user is registering a passkey in the Authenticator, attestation verifies that the legitimate Microsoft Authenticator app created the passkey by using Apple and Google services. Here’s more details:
48
48
49
49
- iOS: Authenticator attestation uses the [iOS App Attest service](https://developer.apple.com/documentation/devicecheck/preparing-to-use-the-app-attest-service) to ensure the legitimacy of the Authenticator app before registering the passkey.
50
-
50
+
51
+
>[!NOTE]
52
+
>Support for registering passkeys in Authenticator when attestation is enforced is currently rolling out to iOS Authenticator app users. Support for registering attested passkeys in Authenticator on Android devices is available to all users in the latest version of the app.
53
+
51
54
- Android:
52
55
- For Play Integrity attestation, Authenticator attestation uses the [Play Integrity API](https://developer.android.com/google/play/integrity/overview) to ensure the legitimacy of the Authenticator app before registering the passkey.
53
56
- For Key attestation, Authenticator attestation uses [key attestation by Android](https://developer.android.com/privacy-and-security/security-key-attestation) to verify that the passkey being registered is hardware-backed.
Copy file name to clipboardExpand all lines: docs/identity/authentication/how-to-register-passkey-authenticator.md
+8-3Lines changed: 8 additions & 3 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -5,7 +5,7 @@ description: Registration and management of passkey with Authenticator on Androi
5
5
ms.service: entra-id
6
6
ms.subservice: authentication
7
7
ms.topic: how-to
8
-
ms.date: 10/21/2024
8
+
ms.date: 10/23/2024
9
9
10
10
ms.author: justinha
11
11
author: justinha
@@ -24,6 +24,9 @@ This article shows how to register a passkey using Microsoft Authenticator on yo
24
24
25
25
Alternatively, you can add a passkey from your mobile device browser, or through cross-device registration using another device, such as a laptop. Your mobile device needs to run iOS version 17, or Android version 14, or later.
26
26
27
+
>[!NOTE]
28
+
>Support for registering passkeys in Authenticator when attestation is enforced is currently rolling out to iOS Authenticator app users. Support for registering attested passkeys in Authenticator on Android devices is available to all users in the latest version of the app.
|**Same-device registration by signing into Authenticator**|✅|✅|
@@ -36,6 +39,7 @@ Alternatively, you can add a passkey from your mobile device browser, or through
36
39
37
40
### Registration by signing in to Authenticator (iOS) (preview)
38
41
42
+
39
43
You can sign in to Authenticator to create a passkey in the app and get seamless single sign-on (SSO) across Microsoft native apps. **This is the recommended and preferred flow to set up a passkey in Authenticator.** If you're signed in or already have an account in Authenticator, you still need to complete these steps to add a passkey in Authenticator.
40
44
41
45
1. Download Authenticator from the App Store, open it, and go through the privacy screens.
@@ -91,7 +95,7 @@ You can sign in to Authenticator to create a passkey in the app and get seamless
91
95
:::image type="content" border="true" source="media/howto-register-passwordless-passkey-direct-ios/new-authenticator-account.png" alt-text="Screenshot of a new account in Authenticator for iOS devices.":::
92
96
93
97
94
-
### Passkey registration from Security Info (iOS)
98
+
### Passkey registration from Security info (iOS)
95
99
96
100
Security info by default will prompt users to sign in to the Authenticator app to register their passkey.
97
101
@@ -114,6 +118,7 @@ Security info by default will prompt users to sign in to the Authenticator app t
114
118
:::image type="content" border="true" source="media/howto-authenticate-passwordless-passkey-ios/complete-setup-in-authenticator.png" alt-text="Screenshot of wizard to complete the passkey setup in Authenticator.":::
115
119
116
120
1. Add your account in Authenticator on your iOS device. If you just downloaded Authenticator, you can tap **Add work or school account** near the bottom of your iOS device. If already using Authenticator, tap **+** in the upper right corner of the app and then tap on **Add work or school account**.
121
+
117
122
:::image type="content" border="true" source="media/howto-register-passwordless-passkey-direct-ios/add-account-ios.png" alt-text="Screenshot 233x433 of how to register using Microsoft Authenticator for iOS devices.":::
118
123
119
124
1. The rest of the flow is similar to the flow shared earlier to sign in to the Authenticator and complete passkey registration. Complete MFA on your iOS device, and tap **Sign in**.
@@ -305,7 +310,7 @@ Security info by default will prompt users to sign in to the Authenticator app t
305
310
306
311
:::image type="content" border="true" source="media/howto-authenticate-passwordless-passkey-android/passkey-android-security-info-laptop.png" alt-text="Screenshot of a new passkey on Android sign-in method in Security info on your other device.":::
307
312
308
-
## Alternate registration flow on Security Info (Android)
313
+
## Alternate registration flow on Security info (Android)
309
314
310
315
If a user is unable to sign in to the Authenticator to register a passkey, you can fall back to triggering registration directly from Security Info. If initiating this flow from a browser on a different device, Bluetooth, an internet connection, and connectivity to these two endpoints must be allowed in your organization to enable cross-device registration and authentication:
Copy file name to clipboardExpand all lines: docs/identity/monitoring-health/howto-use-health-scenario-alerts.md
+7-7Lines changed: 7 additions & 7 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -1,21 +1,21 @@
1
1
---
2
-
title: How to use Microsoft Entra health monitoring alerts (preview)
2
+
title: How to use Microsoft Entra Health monitoring alerts (preview)
3
3
description: Learn how to use the Microsoft Entra health monitoring alerts to monitor and improve the health of your tenant.
4
4
author: shlipsey3
5
5
manager: amycolannino
6
6
ms.service: entra-id
7
7
ms.topic: how-to
8
8
ms.subservice: monitoring-health
9
-
ms.date: 10/14/2024
9
+
ms.date: 10/23/2024
10
10
ms.author: sarahlipsey
11
11
ms.reviewer: sarbar
12
12
13
13
# Customer intent: As an IT admin, I want to learn how to use Microsoft Entra health monitoring to observe and improve the health of my tenant.
14
14
---
15
15
16
-
# How to use Microsoft Entra health monitoring alerts (preview)
16
+
# How to use Microsoft Entra Health monitoring alerts (preview)
17
17
18
-
Microsoft Entra Health monitoring provides the ability to monitor the health of your Microsoft Entra tenant through a set of health metrics and intelligent alerts. Health metrics are fed into our anomaly detection service, which uses machine learning to understand the patterns for your tenant. When the anomaly detection service identifies a significant change one of the tenant-level patterns, it triggers an alert. You can also receive email notifications when a potential issue or failure condition is detected within the health scenarios. For more information on Microsoft Entra Health, see [What is Microsoft Entra Health](concept-microsoft-entra-health.md).
18
+
Microsoft Entra Health monitoring provides the ability to monitor the health of your Microsoft Entra tenant through a set of health metrics and intelligent alerts. Health metrics are fed into our anomaly detection service, which uses machine learning to understand the patterns for your tenant. When the anomaly detection service identifies a significant change in one of the tenant-level patterns, it triggers an alert. You can receive email notifications when a potential issue or failure condition is detected within the health scenarios. For more information on Microsoft Entra Health, see [What is Microsoft Entra Health](concept-microsoft-entra-health.md).
19
19
20
20
This article provides guidance on how to:
21
21
@@ -32,7 +32,7 @@ This article provides guidance on how to:
32
32
- Newly onboarded tenants might not have enough data to generate alerts for about 30 days.
33
33
- Currently, alerts are only available with the Microsoft Graph API.
34
34
35
-
## How to access Microsoft Entra Health
35
+
## Access Microsoft Entra Health
36
36
37
37
You can view the Microsoft Entra Health service level agreement (SLA) attainment report and the health monitoring signals from the Microsoft Entra admin center. You can also view these data streams, and the public preview of health monitoring alerts, using [Microsoft Graph APIs](/graph/api/resources/healthmonitoring-overview?view=graph-rest-beta&preserve-view=true). [Enable the Scenario monitoring preview](https://entra.microsoft.com/?feature.tokencaching=true&feature.internalgraphapiversion=true#view/Microsoft_AAD_IAM/FeaturePreviewsListBlade).
38
38
@@ -128,7 +128,7 @@ With the email notifications configured, you and your team can more effectively
128
128
```http
129
129
GET https://graph.microsoft.com/beta/reports/healthMonitoring/alerts/{alertId}
130
130
```
131
-
For sample requests and responses, see [Health monitoring List alert objects](/graph/api/healthmonitoring-healthmonitoringroot-list-alerts?view=graph-rest-beta&preserve-view=true).
131
+
For sample requests and responses, see [Health monitoring List alert objects](/graph/api/healthmonitoring-healthmonitoringroot-list-alerts?view=graph-rest-beta&preserve-view=true).
132
132
- The portion of the response after `impacts` make up the impact summary for the alert.
133
133
- The `supportingData` portion includes the full query used to generate the alert.
134
134
- The results of the query include everything identified by the anomaly detection service, but there might be results that aren't directly related to the alert.
@@ -139,7 +139,7 @@ For sample requests and responses, see [Health monitoring List alert objects](/
139
139
- If you need to modify Conditional Access policies, you need the [Conditional Access Administrator](../role-based-access-control/permissions-reference.md#conditional-access-administrator) role.
140
140
1. Browse to **Monitoring & health** > **Sign-in logs**.
141
141
- Adjust the time range to match the alert time frame.
142
-
- Add a **filter** for Conditional Access.
142
+
- Add a filter for Conditional Access.
143
143
- Select a log entry to view the sign-in logs details and select the Conditional Access tab to see the policies that were applied.
0 commit comments