Skip to content

Commit b87bc78

Browse files
authored
Update endpoint-security-account-protection-policy.md
Updating section "Configure the profile" from PM.
1 parent 1d90505 commit b87bc78

1 file changed

Lines changed: 7 additions & 5 deletions

File tree

memdocs/intune/protect/endpoint-security-account-protection-policy.md

Lines changed: 7 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,7 @@ keywords:
77
author: brenduns
88
ms.author: brenduns
99
manager: dougeby
10-
ms.date: 01/26/2022
10+
ms.date: 01/31/2022
1111
ms.topic: reference
1212
ms.service: microsoft-intune
1313
ms.subservice: protect
@@ -89,13 +89,15 @@ The following are the configurations you can make:
8989
9090
- **User selection type**: Choose how to select users. Options include:
9191

92-
- **Users**: Select the users and user groups from your Azure AD.
93-
- **Manual**: Specify Azure AD users and groups manually, by username, domain/username, or the groups security identifier (SID).
92+
- **Users**: Select the users and user groups from your Azure AD. (Supported for Azure AD joined devices only).
93+
- **Manual**: Specify Azure AD users and groups manually, by username, domain/username, or the groups security identifier (SID). (Supported for Azure AD joined and hybrid joined devices).
9494

9595
- **Selected user(s)**: Depending on your selection for *User selection type*, you’ll use one of the following options:
9696

9797
- **Select user(s)**: Select the users and user groups from your Azure AD.
98-
- **Add users(s)**: This opens the **Add users** pane where you can then specify one or more user identifiers as they appear on a device. You can specify the user by *Username, Domain/username*, or by *security identifier (SID)*.
98+
- **Add users(s)**: This opens the **Add users** pane where you can then specify one or more user identifiers as they appear on a device. You can specify the user by *security identifier (SID)*, *Domain/username*, or by *Username*.
99+
100+
Choosing the Manual option can be helpful in scenarios where you want to manage your on-prem Active Directory users from Active Directory to a local group for a hybrid Azure AD joined device. The supported formats of identifying the user selection in order of most to least preferred is through the SID, domain\username, or member’s username. Values from Active Directory must be used for hybrid joined devices, while values from Azure AD must be used for Azure AD join. Azure AD group SIDs can be obtained using [Graph API for Groups](https://docs.microsoft.com/graph/api/resources/group?view=graph-rest-1.0&preserve-view=true#json-representation).
99101

100102
:::image type="content" source="./media/endpoint-security-account-protection-policy/add-user.png" alt-text="Screen shot of the Add users page.":::
101103

@@ -115,4 +117,4 @@ Because the policy can contain multiple rules, consider the following:
115117

116118
## Next steps
117119

118-
[Configure Endpoint security policies](../protect/endpoint-security-policy.md#create-an-endpoint-security-policy)
120+
[Configure Endpoint security policies](../protect/endpoint-security-policy.md#create-an-endpoint-security-policy)

0 commit comments

Comments
 (0)