You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: src/react/docs/workshop-guidance/AI/AI_000.md
+3-3Lines changed: 3 additions & 3 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -1,10 +1,10 @@
1
1
# Require Users to Use Entra ID Auth to Interact with Agents
2
2
3
3
**Implementation Effort:** Medium – IT must configure agent authentication flows, consent, and app registrations that tie interactive agents to Entra ID, but this is a one‑time project rather than an ongoing program.
4
-
**User Impact:** Medium – Users may be prompted to sign in with Entra ID or grant delegated permissions when interacting with agents, but only those who use these agents are impacted.
4
+
**User Impact:** Medium – Users may be prompted to sign in with Entra ID or grant delegated permissions when interacting with agents, but only those who use these agents are impacted.
5
5
6
6
## Overview
7
-
Requiring users to authenticate with Microsoft Entra ID before interacting with an agent ensures that every user action is tied to a verified identity. Interactive agents use the Microsoft Entra Agent Identity platform to perform delegated actions on behalf of real users. To enable this, IT configures the agent to request user tokens via OAuth, validate them, and extract claims for authorization decisions. Doing this also provides IT visiblity of user activity and interaction with AI workloads, and enables implementation of controls such as strong authentication, compliant device, etc.
7
+
Requiring users to authenticate with Microsoft Entra ID before interacting with an agent ensures that every user action is tied to a verified identity. Interactive agents use Microsoft Entra Agent ID to perform delegated actions on behalf of real users. To enable this, IT configures the agent to request user tokens via OAuth, validate them, and extract claims for authorization decisions. Doing this also provides IT visibility of user activity and interaction with AI workloads, and enables implementation of controls such as strong authentication, compliant device, etc.
8
8
9
9
Without this setup, agents may operate without strong identity assurance, increasing risks such as unauthorized access, misuse of delegated permissions, or inability to enforce Zero Trust controls.
10
10
This activity supports the Zero Trust principle of Verify explicitly because user identity, tokens, claims, and delegated permissions are validated at every interaction.
Copy file name to clipboardExpand all lines: src/react/docs/workshop-guidance/data/RMT_006.md
+1-3Lines changed: 1 addition & 3 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -2,7 +2,7 @@
2
2
3
3
**Implementation Effort:** Medium - Definition of the taxonomy can be low effort and done quickly either when a taxonomy already exists for the company or the default taxonomy can be used.
4
4
5
-
**User Impact:** Medium - End user education on the company taxonomy and expetcations on usage.
5
+
**User Impact:** Medium - End user education on the company taxonomy and expectations on usage.
6
6
7
7
## Overview
8
8
@@ -24,5 +24,3 @@ Identify (but do not enforce at this time) access restrictions related to each s
24
24
25
25
* Create and publish sensitivity labels https://learn.microsoft.com/en-us/purview/create-sensitivity-labels
26
26
* Microsoft Information Protection Deployment Acceleration Guide: https://microsoft.github.io/ComplianceCxE/dag/mip-dlp/
Copy file name to clipboardExpand all lines: src/react/docs/workshop-guidance/devices/RMD_020.md
+1-2Lines changed: 1 addition & 2 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -5,10 +5,9 @@ The APP data protection configuration framework is organized into three distinct
5
5
6
6
**Level 1****enterprise basic data protection**– Microsoft recommends this configuration as the minimum data protection configuration for an enterprise device.
7
7
**Level 2****enterprise enhanced data protection** – Microsoft recommends this configuration for devices where users access sensitive or confidential information. This configuration is applicable to most mobile users accessing work or school data. Some of the controls may impact user experience.
8
-
**Level 3 enterprise high data protection** – Microsoft recommends this configuration for devices run by an organization with a larger or more sophisticated security team, or for specific users or groups who are at uniquely high risk (users who handle highly sensitive data where unauthorized disclosure causes considerable material loss to the organization). An organization likely to be targeted by well-funded and sophisticated adversaries should aspire to this configuration.
8
+
**Level 3 enterprise high data protection** – Microsoft recommends this configuration for devices run by an organization with a larger or more sophisticated security team, or for specific users or groups who are at uniquely high risk (users who handle highly sensitive data where unauthorized disclosure causes considerable material loss to the organization). An organization likely to be targeted by well-funded and sophisticated adversaries should aspire to this configuration.
Copy file name to clipboardExpand all lines: src/react/docs/workshop-guidance/devices/RMD_153.md
+1-2Lines changed: 1 addition & 2 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -4,9 +4,8 @@
4
4
5
5
**Remote Help** is a feature that allows IT support to remotely assist users' devices using Microsoft Defender for Endpoint. It integrates with Intune to provide secure, role-based access for troubleshooting. It enhances security by using encrypted connections and role-based access control (RBAC) to ensure only authorized personnel can provide support.
6
6
7
-
Remote Help is available with an addon license or an Intune Suite license. For more information about licensing options, see [Microsoft Intune licensing](https://learn.microsoft.com/en-us/mem/intune/fundamentals/licenses).
7
+
Remote Help is available with an add-on license or an Intune Suite license. For more information about licensing options, see [Microsoft Intune licensing](https://learn.microsoft.com/en-us/mem/intune/fundamentals/licenses).
8
8
9
9
## Reference
10
10
11
11
*[Remote Help with Microsoft Intune](https://learn.microsoft.com/en-us/mem/intune/fundamentals/remote-help)
Copy file name to clipboardExpand all lines: src/react/docs/workshop-guidance/identity/RMI_023.md
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -2,7 +2,7 @@
2
2
3
3
## Overview
4
4
5
-
For new cloud applications that require user profile creation and are using Entra ID for single signon, enable automatic provision them via Entra ID as well. This is foundational step to enforce least privilege consistently (e.g. when an account is no longer assigned to an application for SSO, it will trigger a deactivation of the user profile within the application).
5
+
For new cloud applications that require user profile creation and are using Entra ID for single sign-on, enable automatic provisioning for them via Entra ID. This is a foundational step to enforce least privilege consistently (e.g. when an account is no longer assigned to an application for SSO, it will trigger a deactivation of the user profile within the application).
Copy file name to clipboardExpand all lines: src/react/docs/workshop-guidance/identity/RMI_027.md
+2-2Lines changed: 2 additions & 2 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -2,9 +2,9 @@
2
2
3
3
## Overview
4
4
5
-
Migrate exisiting SaaS application provisioning to automatic user provisioning in Microsoft Entra ID. This is foundational step to enforce least privilege consistently (e.g. when an account is no longer assigned to an application for SSO, it will trigger a deactivation of the user profile within the application).
5
+
Migrate existing SaaS application provisioning to automatic user provisioning in Microsoft Entra ID. This is a foundational step to enforce least privilege consistently (e.g. when an account is no longer assigned to an application for SSO, it will trigger a deactivation of the user profile within the application).
6
6
7
-
This migration will also help reducing dependencies and footprint of disjointed provisioning tools.
7
+
This migration will also help reduce dependencies and footprint of disjointed provisioning tools.
Copy file name to clipboardExpand all lines: src/react/docs/workshop-guidance/identity/RMI_030.md
+2-2Lines changed: 2 additions & 2 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -2,9 +2,9 @@
2
2
3
3
## Overview
4
4
5
-
Migrate existing on-premisis applications that require user profiles to use Entra ID Application provisioning. This is foundational step to enforce least privilege consistently (e.g. when a is no longer assigned to an application, it will trigger a deactivation of the user profile within the application).
5
+
Migrate existing on-premises applications that require user profiles to use Entra ID Application provisioning. This is foundational step to enforce least privilege consistently (e.g. when an account is no longer assigned to an application, it will trigger a deactivation of the user profile within the application).
6
6
7
-
This migration will also help reducing dependencies and footprint of disjointed provisioning tools.
7
+
This migration will also help reduce dependencies and footprint of disjointed provisioning tools.
0 commit comments