Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
161 commits
Select commit Hold shift + click to select a range
96b3eb1
Merge pull request #2 from MicrosoftDocs/master
Sammak Dec 18, 2017
31acad9
task 950: Updates for ADN rules engine distinctions, acrolinx edits
Feb 17, 2018
cfe953b
edit pass: monitoring-overview
ShawnJackson Feb 20, 2018
85cb81f
task 950: Updates for ADN rules engine distinctions, acrolinx edits
Feb 20, 2018
00fa46a
Merge branch 'master' of https://github.com/MicrosoftDocs/azure-docs-…
ShawnJackson Feb 20, 2018
42c905f
adding new files for enabling msi on vmss
daveba Feb 20, 2018
c2ca5a1
Merge branch 'master' of https://github.com/MicrosoftDocs/azure-docs-…
daveba Feb 20, 2018
8f3f9a1
fixing toc file
daveba Feb 21, 2018
6236798
Merge branch 'master' of https://github.com/MicrosoftDocs/azure-docs-…
daveba Feb 21, 2018
337e848
edit pass: monitoring-overview
ShawnJackson Feb 21, 2018
05611a5
edit pass: monitoring-overview
ShawnJackson Feb 21, 2018
cb28cbe
task 950: Add procedures, edits, update screenshots
Feb 21, 2018
23f99e5
task 950: Edits, add rule engine link, shrink screenshot
Feb 21, 2018
3106eb6
task 950: Incorporate review comments, add screenshots
Feb 22, 2018
f1f2d7b
edit pass: grow-your-business-azure-marketplace
ShawnJackson Feb 22, 2018
82cb196
task 950: edits
Feb 22, 2018
7a03a35
updating the TOC and consolidating the docs into one docset
daveba Feb 22, 2018
f25d081
Merge branch 'master' of https://github.com/MicrosoftDocs/azure-docs-…
daveba Feb 22, 2018
aaaa102
corrections based on feedback
daveba Feb 22, 2018
eff8fd9
Merge branch 'master' of https://github.com/MicrosoftDocs/azure-docs-…
ShawnJackson Feb 23, 2018
84ad00f
edit pass: grow-your-business-azure-marketplace
ShawnJackson Feb 23, 2018
c27fb7a
Merge branch 'master' of https://github.com/MicrosoftDocs/azure-docs-…
ShawnJackson Feb 23, 2018
efbab61
edit pass: grow-your-business-azure-marketplace
ShawnJackson Feb 23, 2018
8f76bb2
Merge branch 'master' of https://github.com/MicrosoftDocs/azure-docs-…
ShawnJackson Feb 24, 2018
0bc19da
edit pass: grow-your-business-azure-marketplace
ShawnJackson Feb 24, 2018
bacba92
Merge branch 'master' of https://github.com/MicrosoftDocs/azure-docs-…
ShawnJackson Feb 26, 2018
3971011
Added rbac warning when transfering subscription
rolyon Feb 26, 2018
0fffa49
Merge branch 'master' of https://github.com/MicrosoftDocs/azure-docs-…
rolyon Feb 26, 2018
d98a6ca
fixing link
daveba Feb 26, 2018
339a4b3
Merge branch 'master' of https://github.com/MicrosoftDocs/azure-docs-…
daveba Feb 26, 2018
d138155
edit pass: grow-your-business-azure-marketplace
ShawnJackson Feb 26, 2018
5066778
edit pass: grow-your-business-azure-marketplace
ShawnJackson Feb 26, 2018
053e811
Merge pull request #3 from MicrosoftDocs/master
Sammak Feb 26, 2018
09325c3
Repositioned RBAC warning, updated wording to across tenants
rolyon Feb 27, 2018
dd09280
Merge branch 'master' of https://github.com/MicrosoftDocs/azure-docs-…
rolyon Feb 27, 2018
68fabb4
Moved RBAC warning before Specify New Owner screenshot
rolyon Feb 27, 2018
6b3ccae
Merge branch 'master' of https://github.com/MicrosoftDocs/azure-docs-…
rolyon Feb 27, 2018
b843908
Duplicated RBAC note at top of article
rolyon Feb 27, 2018
0f83918
Merge branch 'master' of https://github.com/MicrosoftDocs/azure-docs-…
rolyon Feb 27, 2018
31beb42
Updating documentation for language customization
Sammak Feb 28, 2018
f8aaa10
edit pass - Bing Search articles - draft 1
GitHubber17 Feb 28, 2018
56bee48
Merge branch 'master' of https://github.com/Microsoft/azure-docs-pr i…
GitHubber17 Feb 28, 2018
f6aa77a
Fixed typos, added to TOC
msmbaldwin Feb 28, 2018
aedf8be
making updates based on feedback
daveba Feb 28, 2018
d44a3a0
Merge branch 'master' of https://github.com/MicrosoftDocs/azure-docs-…
daveba Feb 28, 2018
6f80006
added alerts
eringreenlee Feb 28, 2018
e9fc804
edit pass: adjustments
GitHubber17 Feb 28, 2018
c40f2ab
Merge branch 'master' into master
eringreenlee Feb 28, 2018
24d96f0
fixed grammar in troubleshooting alerts
eringreenlee Feb 28, 2018
e522ef4
Merge branch 'master' of https://github.com/eringreenlee/azure-docs-pr
eringreenlee Feb 28, 2018
72f3d9a
Correcting typos
Sammak Feb 28, 2018
488cedc
Cleaning up the resources TOC section to remove extraneous entries an…
j-martens Feb 28, 2018
c8d9e2f
acrolinx cleanup
j-martens Feb 28, 2018
07d66c2
fixing capitalization and headings
j-martens Feb 28, 2018
4dbda5e
Merge pull request #13 from MicrosoftDocs/master
ajlam Mar 1, 2018
f07520e
Updating doc for blocking issues
Sammak Mar 1, 2018
2e2fc89
adding line showing support for 1709
Mar 1, 2018
6f1ce78
updating date
Mar 1, 2018
afafa8c
formatting fix
Mar 1, 2018
46a3cad
fixing screenshots
JasonWHowell Mar 1, 2018
4f0a44e
Fix for PR
j-martens Mar 1, 2018
bc04998
changes to restore portal articles
rachel-msft Mar 1, 2018
a3e41af
Initial drafts.
Mar 1, 2018
a99ff2a
AML: Usability updates for Tutorial 1
j-martens Mar 1, 2018
d4cc1da
Update data-lake-analytics-overview.md
Mar 1, 2018
18e35fe
Updates.
Mar 1, 2018
6e3a258
including new azure key content
anrothMSFT Mar 1, 2018
1d4212c
Updating screenshots
JasonWHowell Mar 1, 2018
135cce1
[HDI] incorporate usability study feedback
mumian Mar 1, 2018
3931013
Fix 3 problems in supported markets
MikeDodaro Mar 1, 2018
31e533b
AML: formatting fix
j-martens Mar 1, 2018
10636c2
fix a link
mumian Mar 1, 2018
8e9d826
importing 1.x for luis
v-geberr Mar 1, 2018
e7a59fc
Merge branch 'master' of https://github.com/MicrosoftDocs/azure-docs-…
v-geberr Mar 1, 2018
7c531a7
Change Tom Cruise to Harry Potter
MikeDodaro Mar 1, 2018
ff0aa82
Updating screenshots
JasonWHowell Mar 1, 2018
cc3fac5
edit pass: adjustments
GitHubber17 Mar 1, 2018
2f6ebff
Merge pull request #34164 from Sammak/master
GitHubber17 Mar 1, 2018
09d6149
Tom Cruise -> Harry Potter
MikeDodaro Mar 1, 2018
7889ba1
Updating screenshots
JasonWHowell Mar 1, 2018
6018c79
Merge pull request #34294 from MikeDodaro/typos
PRMerger12 Mar 1, 2018
bf1a232
Merge pull request #34287 from anrothMSFT/patch-2
PRMerger12 Mar 1, 2018
d551452
cost mgt - updated Activate Azure subscriptions
bandersmsft Mar 1, 2018
1a92325
updates
v-geberr Mar 1, 2018
2fe8f41
Merge pull request #34276 from rachel-msft/editr
GitHubber17 Mar 1, 2018
44db8eb
links
v-geberr Mar 1, 2018
f32d062
Merge pull request #34299 from bandersmsft/master
PRMerger15 Mar 1, 2018
7dca831
Removed article.
Mar 1, 2018
44b7ddd
Add check extension version
ajlam Mar 1, 2018
549b03c
update a screenshot
mumian Mar 1, 2018
6d6fb26
Update grow-your-business-azure-marketplace.md
ShawnJackson Mar 1, 2018
16de599
edits
v-geberr Mar 1, 2018
84e3ff9
Update tutorial with extension version check
ajlam Mar 1, 2018
c9af30d
Updating screenshots
JasonWHowell Mar 1, 2018
25f5237
Updated link and acrolinx fixes
Mar 1, 2018
194634f
Updated for 9.4.2
daveirwin1 Mar 1, 2018
4e8a671
Update sql-database-elastic-pool.md
CarlRabeler Mar 1, 2018
3a4dd50
Update sql-database-elastic-pool.md
CarlRabeler Mar 1, 2018
e72d393
Add update for PG
ajlam Mar 1, 2018
ac05950
Merge pull request #34306 from jeffgilb/jeff31
PRMerger10 Mar 1, 2018
7998f53
automation : delete missing vm change article
Mar 1, 2018
ee0e778
Merge pull request #34282 from saveenr/patch-20
PRMerger12 Mar 1, 2018
92f1585
fixed powershell script and picture
eringreenlee Mar 1, 2018
6f733fc
vnet-tutorials
Mar 1, 2018
9c0da8e
Merge branch 'master' of https://github.com/MicrosoftDocs/azure-docs-…
Mar 1, 2018
f849624
Merge pull request #34300 from jimdial/remove-vnet-article
GitHubber17 Mar 1, 2018
94de8c7
Merge pull request #34304 from ajlam/master
PRMerger15 Mar 1, 2018
0ac939b
Merge pull request #34307 from CarlRabeler/patch-7
PRMerger17 Mar 1, 2018
e062b71
updated
Mar 1, 2018
d6a83f9
Fixes.
Mar 1, 2018
dd08ab5
Merge branch 'master' of https://github.com/MicrosoftDocs/azure-docs-…
Mar 1, 2018
8aad49a
Merge pull request #34308 from daveirwin1/master
PRMerger18 Mar 1, 2018
9a85dff
Add samples for Mongoose and spring boot
vidhoonv Mar 1, 2018
f779ac1
Merge pull request #34021 from rolyon/rolyon-rbacwarn
PRMerger19 Mar 1, 2018
e0c32eb
links
v-geberr Mar 1, 2018
3e7fd52
Merge pull request #34296 from MikeDodaro/fixAmbig
Mar 1, 2018
565802b
Merge pull request #34036 from ShawnJackson/grow-your-business-azure-…
Ja-Dunn Mar 1, 2018
6499571
Merge pull request #34313 from vidhoonv/patch-2
Mar 1, 2018
03187d0
Add nuget.org
mrbullwinkle Mar 1, 2018
9f31adc
Merge pull request #34291 from mumian/0223-usability
ktoliver Mar 1, 2018
fa648a0
cost mgt - updated understanding cost reports
bandersmsft Mar 1, 2018
1762dbe
Merge pull request #34305 from v-geberr/0301-dashboard
PRMerger12 Mar 1, 2018
0001c68
Aligned to contributor guide
Mar 1, 2018
2a495b4
Merge pull request #34295 from v-geberr/0301-migration-guide
PRMerger13 Mar 1, 2018
cd9bf03
Fix
Mar 1, 2018
f4d9c5a
Merge pull request #34174 from GitHubber17/vsts-1192661
ShawnJackson Mar 1, 2018
4e7f06e
Updated next steps.
Mar 1, 2018
32e136f
Merge pull request #34273 from JasonWHowell/master
ktoliver Mar 1, 2018
816a3c2
Merge pull request #33688 from ShawnJackson/monitoring-overview
Ja-Dunn Mar 1, 2018
51b7d17
remove publish step
v-geberr Mar 1, 2018
4ccb031
adding System State to Azure Backup components table in Intro article
markgalioto Mar 1, 2018
fcc6152
Merge pull request #34319 from mrbullwinkle/mrb_03_01_2018
PRMerger19 Mar 1, 2018
1bcfa0f
move away from VIP language
christiankuhtz Mar 1, 2018
729cda3
Merge pull request #34318 from jimdial/patch-80
Mar 1, 2018
45804e2
Merge pull request #34324 from markgalioto/ab-3-1-2018
Mar 1, 2018
5fb52b1
Merge pull request #34244 from j-martens/master
Lisaco88 Mar 1, 2018
2739cb1
added subscription move limitation
christiankuhtz Mar 1, 2018
5d9be44
Merge branch 'master' of https://github.com/MicrosoftDocs/azure-docs-…
Mar 1, 2018
c86005e
Merge pull request #34310 from georgewallace/autovmfixes
Lisaco88 Mar 1, 2018
084e5fe
tweak
christiankuhtz Mar 1, 2018
48e6db8
Revert "Syntax fix for $, adding info on JMESPath queries"
neilpeterson Mar 1, 2018
86b532a
Merge pull request #34325 from christiankuhtz/patch-57
PRMerger10 Mar 1, 2018
6fcbfb9
Merge pull request #34240 from eringreenlee/master
Lisaco88 Mar 1, 2018
bc1028b
Merge pull request #34262 from dkkapur/master
PRMerger12 Mar 1, 2018
efb416e
Merge pull request #34326 from neilpeterson/revert-34166-k8s-deploy-c…
PRMerger13 Mar 1, 2018
09530ea
task 950: standardize titles for optimization-related articles
Mar 1, 2018
377f11f
Update storage-files-release-notes.md
klaaslanghout Mar 1, 2018
8bacb52
Merge pull request #34323 from christiankuhtz/patch-56
PRMerger15 Mar 1, 2018
43c8ce7
fixing issues found by pr reviewer
daveba Mar 1, 2018
3132f0a
Merge pull request #34316 from bandersmsft/master
PRMerger16 Mar 1, 2018
b915fe7
Merge branch 'master' of https://github.com/MicrosoftDocs/azure-docs-…
daveba Mar 1, 2018
08fb531
Merge pull request #34215 from msmbaldwin/healthblueprint
PRMerger17 Mar 1, 2018
85314e7
Merge pull request #34329 from klaaslanghout/patch-14
PRMerger18 Mar 1, 2018
05f047c
Merge pull request #34311 from jimdial/virtual-network
ktoliver Mar 1, 2018
c460331
fix link
v-geberr Mar 1, 2018
4537380
Merge pull request #34334 from v-geberr/0301-fix-link
PRMerger13 Mar 1, 2018
9c0aab4
Merge pull request #33588 from dksimpson/dean-950
Ja-Dunn Mar 1, 2018
57222e8
Merge pull request #34321 from v-geberr/0301-batch-testing
PRMerger13 Mar 1, 2018
c0f3838
Merge branch 'master' of https://github.com/MicrosoftDocs/azure-docs …
v-alje Mar 1, 2018
e7c205b
Merge pull request #34338 from MicrosoftDocs/FromPublicRepo
v-alje Mar 1, 2018
329b7b9
Merge pull request #33686 from daveba/configure-msi-for-azure-vmss
Lisaco88 Mar 1, 2018
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
10 changes: 10 additions & 0 deletions .openpublishing.redirection.json
Original file line number Diff line number Diff line change
Expand Up @@ -1718,6 +1718,11 @@
"redirect_url": "/azure/automation",
"redirect_document_id": false
},
{
"source_path": "articles/automation/automation-vm-change-tracking.md",
"redirect_url": "/azure/automation/automation-change-tracking",
"redirect_document_id": false
},
{
"source_path": "articles/automation/automation-azure-vm-alert-integration.md",
"redirect_url": "/azure/automation/automation-create-alert-triggered-runbook",
Expand Down Expand Up @@ -4818,6 +4823,11 @@
"redirect_url": "/azure/log-analytics/log-analytics-data-security",
"redirect_document_id": false
},
{
"source_path": "articles/log-analytics/log-analytics-change-tracking.md",
"redirect_url": "/azure/automation/automation-change-tracking",
"redirect_document_id": false
},
{
"source_path": "articles/log-analytics/log-analytics-configuration-assessment.md",
"redirect_url": "/azure/log-analytics/log-analytics-add-solutions",
Expand Down

Large diffs are not rendered by default.

2 changes: 1 addition & 1 deletion articles/active-directory-domain-services/TOC.md
Original file line number Diff line number Diff line change
Expand Up @@ -22,6 +22,7 @@
## [Check a managed domain's health](active-directory-ds-check-health.md)
## [Use Azure AD Domain Services in Azure CSP subscriptions](active-directory-ds-csp.md)
## [Enable Azure AD Domain Services using PowerShell](active-directory-ds-enable-using-powershell.md)
## [Check your domain's health](active-directory-ds-check-health.md)
## Join a managed domain
### [Windows Server VM](active-directory-ds-admin-guide-join-windows-vm-portal.md)
### [Windows Server VM from template](active-directory-ds-join-windows-vm-template.md)
Expand All @@ -32,7 +33,6 @@
## Administer a managed domain
### [Administer a managed domain](active-directory-ds-admin-guide-administer-domain.md)
### [Administer DNS on a managed domain](active-directory-ds-admin-guide-administer-dns.md)

### Configure secure LDAP for a managed domain
#### [Task 1: obtain a certificate for secure LDAP](active-directory-ds-admin-guide-configure-secure-ldap.md)
#### [Task 2: export the secure LDAP certificate](active-directory-ds-admin-guide-configure-secure-ldap-export-pfx.md)
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -13,7 +13,7 @@ ms.workload: identity
ms.tgt_pltfrm: na
ms.devlang: na
ms.topic: article
ms.date: 02/05/2018
ms.date: 02/28/2018
ms.author: ergreenl

---
Expand All @@ -31,6 +31,13 @@ Pick the troubleshooting steps that correspond to or alert ID or message you enc
| AADDS102 | *A Service Principal required for Azure AD Domain Services to function properly has been deleted from your Azure AD directory. This configuration impacts Microsoft's ability to monitor, manage, patch, and synchronize your managed domain.* | [Missing Service Principal](active-directory-ds-troubleshoot-service-principals.md) |
| AADDS103 | *The IP address range for the virtual network in which you have enabled Azure AD Domain Services is in a public IP range. Azure AD Domain Services must be enabled in a virtual network with a private IP address range. This configuration impacts Microsoft's ability to monitor, manage, patch and synchronize your managed domain.* | [Address is in a public IP range](#aadds103-address-is-in-a-public-ip-range) |
| AADDS104 | *Microsoft is unable to reach the domain controllers for this managed domain. This may happen if a network security group (NSG) configured on your virtual network blocks access to the managed domain. Another possible reason is if there is a user defined route that blocks incoming traffic from the internet.* | [Network Error](active-directory-ds-troubleshoot-nsg.md) |
| AADDS500 | *The managed domain was last synchronized with Azure AD on {0}. Users may be unable to sign-in on the managed domain or group memberships may not be in sync with Azure AD.* | [Synchronization hasn't happened in a while](#aadds500-synchronization-has-not-completed-in-a-while) |
| AADDS501 | *The managed domain was last backed up on XX.* | [A backup hasn't been taken in a while](#aadds501-a-backup-has-not-been-taken-in-a-while) |
| AADDS502 | *The secure LDAP certificate for the managed domain will expire on XX.* | [Expiring secure LDAP certificate](active-directory-ds-troubleshoot-ldaps.md#aadds502-secure-ldap-certificate-expiring) |
| AADDS503 | *The managed domain is suspended because the Azure subscription associated with the domain is not active.* | [Suspension due to disabled subscription](#aadds503-suspension-due-to-disabled-subscription) |
| AADDS504 | *The managed domain is suspended due to an invalid configuration. The service has been unable to manage, patch, or update the domain controllers for your managed domain for a long time.* | [Suspension due to an invalid configuration](#aadds504-suspension-due-to-an-invalid-configuration) |



## AADDS100: Missing directory
**Alert message:**
Expand Down Expand Up @@ -72,7 +79,7 @@ To restore your service, follow these steps:

Before you begin, read the **private IP v4 address space** section in [this article](https://en.wikipedia.org/wiki/Private_network#Private_IPv4_address_spaces).

Inside the virtual network, machines may make requests to Azure resources that are in the same IP address range as those configured for the subnet. However, since the virtual network is configured for this range, those requests will be routed within the virtual network and will not reach the intended web resources. This can lead to unpredictable errors with Azure AD Domain Services.
Inside the virtual network, machines may make requests to Azure resources that are in the same IP address range as those configured for the subnet. However, since the virtual network is configured for this range, those requests will be routed within the virtual network and will not reach the intended web resources. This configuration can lead to unpredictable errors with Azure AD Domain Services.

**If you own the IP address range in the internet that is configured in your virtual network, this alert can be ignored. However, Azure AD Domain Services cannot commit to the [SLA](https://azure.microsoft.com/support/legal/sla/active-directory-ds/v1_0/)] with this configuration since it can lead to unpredictable errors.**

Expand All @@ -90,6 +97,47 @@ Inside the virtual network, machines may make requests to Azure resources that a
4. To domain-join your virtual machines to your new domain, follow [this guide](active-directory-ds-admin-guide-join-windows-vm-portal.md).
8. To ensure the alert is resolved, check your domain's health in two hours.

## AADDS500: Synchronization has not completed in a while

**Alert message:**

*The managed domain was last synchronized with Azure AD on {0}. Users may be unable to sign-in on the managed domain or group memberships may not be in sync with Azure AD.*

**Remediation:**

[Check your domain's health](active-directory-ds-check-health.md) for any alerts that might indicate problems in your configuration of your managed domain. Sometimes, problems with your configuration can block Microsoft's ability to synchronize your managed domain. If you are able to resolve any alerts, wait two hours and check back to see if the synchronization has completed.


## AADDS501: A backup has not been taken in a while

**Alert message:**

*The managed domain was last backed up on XX.*

**Remediation:**

[Check your domain's health](active-directory-ds-check-health.md) for any alerts that might indicate problems in your configuration of your managed domain. Sometimes, problems with your configuration can block Microsoft's ability to synchronize your managed domain. If you are able to resolve any alerts, wait two hours and check back to see if the synchronization has completed.


## AADDS503: Suspension due to disabled subscription

**Alert message:**

*The managed domain is suspended because the Azure subscription associated with the domain is not active.*

**Remediation:**

To restore your service, [renew your Azure subscription](https://docs.microsoft.com/en-us/azure/billing/billing-subscription-become-disable) associated with your managed domain.

## AADDS504: Suspension due to an invalid configuration

**Alert message:**

*The managed domain is suspended due to an invalid configuration. The service has been unable to manage, patch, or update the domain controllers for your managed domain for a long time.*

**Remediation:**

[Check your domain's health](active-directory-ds-check-health.md) for any alerts that might indicate problems in your configuration of your managed domain. If you can resolve any of these alerts, do so. After, contact support to re-enable your subscription.

## Contact us
Contact the Azure Active Directory Domain Services product team to [share feedback or for support](active-directory-ds-contact-us.md).
Original file line number Diff line number Diff line change
Expand Up @@ -13,7 +13,7 @@ ms.workload: identity
ms.tgt_pltfrm: na
ms.devlang: na
ms.topic: article
ms.date: 02/02/2018
ms.date: 02/21/2018
ms.author: ergreenl

---
Expand Down Expand Up @@ -49,5 +49,15 @@ When secure LDAP is enabled, we recommend creating additional rules to allow inb
> Port 636 is not the only rule needed for Azure AD Domain Services to run smoothly. To learn more, visit the [Networking guidelines](active-directory-ds-networking.md) or [Troubleshoot NSG configuration](active-directory-ds-troubleshoot-nsg.md) articles.
>

## AADDS502: Secure LDAP certificate expiring

**Alert message:**

*The secure LDAP certificate for the managed domain will expire on XX.*

**Remediation:**

Create a new secure LDAP certificate by following the steps outlined in the [Configure secure LDAP](active-directory-ds-admin-guide-configure-secure-ldap.md) article.

## Contact us
Contact the Azure Active Directory Domain Services product team to [share feedback or for support](active-directory-ds-contact-us.md).
Original file line number Diff line number Diff line change
Expand Up @@ -13,7 +13,7 @@ ms.workload: identity
ms.tgt_pltfrm: na
ms.devlang: na
ms.topic: article
ms.date: 02/12/2018
ms.date: 03/01/2018
ms.author: ergreenl

---
Expand Down Expand Up @@ -55,7 +55,7 @@ Follow the instructions to [install the Azure PowerShell module and connect to y
> We recommend using the latest version of the Azure PowerShell module. If you already have an older version of the Azure PowerShell module installed, update to the latest version.
>

Use the following steps to create a new NSG using PowerShell.
Use the following steps to create a new NSG using PowerShell.
1. Log in to your Azure subscription.

```PowerShell
Expand All @@ -67,33 +67,34 @@ Use the following steps to create a new NSG using PowerShell.

```PowerShell
# Allow inbound HTTPS traffic to enable synchronization to your managed domain.
$SyncRule = New-AzureRmNetworkSecurityRuleConfig -Name AllowSyncWithAzureAD `
-Description "Allow synchronization with Azure AD" `
$SyncRule = New-AzureRmNetworkSecurityRuleConfig -Name AllowSyncWithAzureAD -Description "Allow synchronization with Azure AD" `
-Access Allow -Protocol Tcp -Direction Inbound -Priority 101 `
-SourceAddressPrefix * -SourcePortRange * -DestinationAddressPrefix * `
-DestinationPortRange 443

# Allow management of your domain over port 5986 (PowerShell Remoting)
$PSRemotingRule = New-AzureRmNetworkSecurityRuleConfig -Name AllowPSRemoting `
-Description "Allow management of domain through port 5986" `
$PSRemotingRule = New-AzureRmNetworkSecurityRuleConfig -Name AllowPSRemoting -Description "Allow management of domain through port 5986" `
-Access Allow -Protocol Tcp -Direction Inbound -Priority 102 `
-SourceAddressPrefix 52.180.183.8, 23.101.0.70, 52.225.184.198, 52.179.126.223, `
13.74.249.156, 52.187.117.83, 52.161.13.95, 104.40.156.18, 104.40.87.209, `
52.180.179.108, 52.175.18.134, 52.138.68.41, 104.41.159.212, 52.169.218.0, `
52.187.120.237, 52.161.110.169, 52.174.189.149, 13.64.151.161 `
-SourcePortRange * -DestinationAddressPrefix * `
-SourceAddressPrefix 52.180.183.8, 23.101.0.70, 52.225.184.198, 52.179.126.223, 13.74.249.156, 52.187.117.83, 52.161.13.95, 104.40.156.18, 104.40.87.209, 52.180.179.108, 52.175.18.134, 52.138.68.41, 104.41.159.212, 52.169.218.0, 52.187.120.237, 52.161.110.169, 52.174.189.149, 13.64.151.161 -SourcePortRange * -DestinationAddressPrefix * `
-DestinationPortRange 5986

#The following two rules are optional and needed only in certain situations.

# Allow management of your domain over port 3389 (remote desktop).
$RemoteDesktopRule = New-AzureRmNetworkSecurityRuleConfig -Name AllowRD `
-Description "Allow management of domain through port 3389" `
$RemoteDesktopRule = New-AzureRmNetworkSecurityRuleConfig -Name AllowRD -Description "Allow management of domain through port 3389" `
-Access Allow -Protocol Tcp -Direction Inbound -Priority 103 `
-SourceAddressPrefix * -SourcePortRange * -DestinationAddressPrefix * `
-SourceAddressPrefix 207.68.190.32/27, 13.106.78.32/27, 10.254.32.0/20, 10.97.136.0/22, 13.106.174.32/27, 13.106.4.96/27 -SourcePortRange * -DestinationAddressPrefix * `
-DestinationPortRange 3389

# Create the NSG with the 3 rules above
$Nsg = New-AzureRmNetworkSecurityGroup -ResourceGroupName $ResourceGroup -Location $Location `
-Name "AAD-DomainServices-NSG" -SecurityRules $SyncRule,$PSRemotingRule,$RemoteDesktopRule
# Secure LDAP rule, it is recommended to change the source address prefix to include only the IP addresses
$SecureLDAPRule = New-AzureRmNetworkSecurityRuleConfig -Name SecureLDAP -Description "Allow access through secure LDAP port" `
-Access Allow -Protocol Tcp -Direction Inbound -Priority 104 `
-SourceAddressPrefix * -SourcePortRange * -DestinationAddressPrefix * `
-DestinationPortRange 636

# Create the NSG with the rules above (if you need the remote desktop rule and secure ldap rule, add it below)
$nsg = New-AzureRmNetworkSecurityGroup -ResourceGroupName $resourceGroup -Location westus `
-Name "AADDomainServices-NSG" -SecurityRules $SyncRule, $PSRemotingRule
```

3. Lastly, associate the NSG with the vnet and subnet of choice.
Expand Down Expand Up @@ -124,33 +125,34 @@ $SubnetName = "exampleSubnet"
Login-AzureRmAccount

# Allow inbound HTTPS traffic to enable synchronization to your managed domain.
$SyncRule = New-AzureRmNetworkSecurityRuleConfig -Name AllowSyncWithAzureAD `
-Description "Allow synchronization with Azure AD" `
$SyncRule = New-AzureRmNetworkSecurityRuleConfig -Name AllowSyncWithAzureAD -Description "Allow synchronization with Azure AD" `
-Access Allow -Protocol Tcp -Direction Inbound -Priority 101 `
-SourceAddressPrefix * -SourcePortRange * -DestinationAddressPrefix * `
-DestinationPortRange 443

# Allow management of your domain over port 5986 (PowerShell Remoting)
$PSRemotingRule = New-AzureRmNetworkSecurityRuleConfig -Name AllowPSRemoting `
-Description "Allow management of domain through port 5986" `
$PSRemotingRule = New-AzureRmNetworkSecurityRuleConfig -Name AllowPSRemoting -Description "Allow management of domain through port 5986" `
-Access Allow -Protocol Tcp -Direction Inbound -Priority 102 `
-SourceAddressPrefix 52.180.183.8, 23.101.0.70, 52.225.184.198, 52.179.126.223, `
13.74.249.156, 52.187.117.83, 52.161.13.95, 104.40.156.18, 104.40.87.209, `
52.180.179.108, 52.175.18.134, 52.138.68.41, 104.41.159.212, 52.169.218.0, `
52.187.120.237, 52.161.110.169, 52.174.189.149, 13.64.151.161 `
-SourcePortRange * -DestinationAddressPrefix * `
-SourceAddressPrefix 52.180.183.8, 23.101.0.70, 52.225.184.198, 52.179.126.223, 13.74.249.156, 52.187.117.83, 52.161.13.95, 104.40.156.18, 104.40.87.209, 52.180.179.108, 52.175.18.134, 52.138.68.41, 104.41.159.212, 52.169.218.0, 52.187.120.237, 52.161.110.169, 52.174.189.149, 13.64.151.161 -SourcePortRange * -DestinationAddressPrefix * `
-DestinationPortRange 5986

#The following two rules are optional and needed only in certain situations.

# Allow management of your domain over port 3389 (remote desktop).
$RemoteDesktopRule = New-AzureRmNetworkSecurityRuleConfig -Name AllowRD `
-Description "Allow management of domain through port 3389" `
$RemoteDesktopRule = New-AzureRmNetworkSecurityRuleConfig -Name AllowRD -Description "Allow management of domain through port 3389" `
-Access Allow -Protocol Tcp -Direction Inbound -Priority 103 `
-SourceAddressPrefix * -SourcePortRange * -DestinationAddressPrefix * `
-SourceAddressPrefix 207.68.190.32/27, 13.106.78.32/27, 10.254.32.0/20, 10.97.136.0/22, 13.106.174.32/27, 13.106.4.96/27 -SourcePortRange * -DestinationAddressPrefix * `
-DestinationPortRange 3389

# Create the NSG with the 3 rules above
$Nsg = New-AzureRmNetworkSecurityGroup -ResourceGroupName $ResourceGroup -Location $Location `
-Name "AAD-DomainServices-NSG" -SecurityRules $SyncRule,$PSRemotingRule,$RemoteDesktopRule
# Secure LDAP rule, it is recommended to change the source address prefix to include only the IP addresses
$SecureLDAPRule = New-AzureRmNetworkSecurityRuleConfig -Name SecureLDAP -Description "Allow access through secure LDAP port" `
-Access Allow -Protocol Tcp -Direction Inbound -Priority 104 `
-SourceAddressPrefix * -SourcePortRange * -DestinationAddressPrefix * `
-DestinationPortRange 636

# Create the NSG with the rules above (if you need the remote desktop rule and secure ldap rule, add it below)
$nsg = New-AzureRmNetworkSecurityGroup -ResourceGroupName $resourceGroup -Location westus `
-Name "AADDomainServices-NSG" -SecurityRules $SyncRule, $PSRemotingRule

# Find vnet and subnet
$Vnet = Get-AzureRmVirtualNetwork -ResourceGroupName $ResourceGroup -Name $VnetName
Expand All @@ -161,9 +163,6 @@ $Subnet.NetworkSecurityGroup = $Nsg
Set-AzureRmVirtualNetwork -VirtualNetwork $Vnet
```

> [!NOTE]
> This default NSG does not lock down access to the port used for Secure LDAP. To lock down Secure LDAP access over the internet, see [this article](active-directory-ds-troubleshoot-ldaps.md).
>

## Need help?
Contact the Azure Active Directory Domain Services product team to [share feedback or for support](active-directory-ds-contact-us.md).
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
14 changes: 11 additions & 3 deletions articles/active-directory/TOC.yml
Original file line number Diff line number Diff line change
Expand Up @@ -51,15 +51,23 @@
- name: Using Azure Resource Manager template
href: msi-qs-configure-template-windows-vm.md
- name: Using Azure SDK
href: msi-qs-configure-sdk-windows-vm.md
- name: Grant a VM MSI access to Resource Manager
href: msi-qs-configure-sdk-windows-vm.md
- name: Configure MSI for Azure VMSS
items:
- name: Using the Azure Portal
href: msi-qs-configure-portal-windows-vmss.md
- name: Using Azure CLI
href: msi-qs-configure-cli-windows-vmss.md
- name: Using Azure Resource Manager template
href: msi-qs-configure-template-windows-vmss.md
- name: Grant a VM or VMSS MSI access to Resource Manager
items:
- name: Using Azure portal
href: msi-howto-assign-access-portal.md
- name: Using PowerShell
href: msi-howto-assign-access-powershell.md
- name: Using Azure CLI
href: msi-howto-assign-access-cli.md
href: msi-howto-assign-access-cli.md
- name: How to use a VM MSI
items:
- name: Acquire an access token
Expand Down
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading