{ "AndroidForWorkAppPermissions": { "Action": { "autoDeny": "Auto deny", "autoGrant": "Auto grant", "prompt": "Prompt" }, "addButtonLabel": "+Add", "addPermissionsTitle": "Add permissions", "addPermissionTableDescription": "Specify permissions you want to override. If they are not chosen/specified explicitly, then the default behavior will apply.", "learnMoreLink": "https://go.microsoft.com/fwlink/?linkid=850320", "learnMoreText": "Learn more about Android runtime permissions", "Permissions": { "accessBackgroundLocation": "Location access (background)", "accessCoarseLocation": "Location access (coarse)", "accessFineLocation": "Location access (fine)", "addVoicemail": "Add voicemail", "bluetoothConnect": "Bluetooth connect", "bodySensors": "Allow body sensor data", "bodySensorsBackground": "Allow background body sensor data", "callPhone": "Make phone calls", "camera": "Camera", "getAccounts": "Get accounts", "nearbyDevices": "Nearby Devices", "nearbyWifiDevices": "Nearby Wifi Devices", "postNotifications": "Post notifications", "processOutgoingCalls": "Process outgoing calls", "readCalendar": "Calendar (read)", "readCallLog": "Call log (read)", "readContacts": "Contacts (read)", "readExternalStorage": "External storage (read)", "readMediaAudio": "Media Audio (read)", "readMediaImages": "Media Images (read)", "readMediaVideo": "Media Video (read)", "readPhoneState": "Phone state (read)", "readSMS": "SMS (read)", "receiveMMS": "MMS (receive)", "receiveSMS": "SMS (receive)", "receiveWAPPush": "WAP push messages (receive)", "recordAudio": "Record audio", "sendSMS": "SMS (send)", "useSIP": "Use SIP service", "writeCalendar": "Calendar (write)", "writeCallLog": "Call log (write)", "writeContacts": "Contacts (write)", "writeExternalStorage": "External storage (write)" }, "permissionsTitle": "Permissions", "permissionTableDescription": "Permissions granted here will override the “Default app permissions” policy for the selected apps.", "RemoveDialog": { "description": "Are you sure you want to remove the permission?", "title": "Remove" }, "TableHeader": { "permission": "Permission", "permissionGroup": "Permission group", "permissionName": "Permission name", "permissionState": "Permission state" } }, "AppCategories": { "microsoftDefenderATP": "Microsoft Defender for Endpoint", "microsoftEdge": "Microsoft Edge, version 77 and later", "office365Suite": "Microsoft 365 Apps", "other": "Other", "storeApp": "Store app", "webApplication": "Web Application" }, "AppGroupType": { "allApps": "All Apps", "allMicrosoftApps": "All Microsoft Apps", "coreMicrosoftApps": "Core Microsoft Apps", "selectedPublicApps": "Selected apps" }, "AppInfoBalloonText": { "appInstallContext": "This specifies the install context to be associated with this app. For dual mode apps, select the desired context for this app. For all other apps, this is pre-selected based on the package and cannot be modified.", "autoUpdateMode": "Configure the update priority for the app. Select Default to require the device to be connected to WiFi, to be charging, and not to be actively in use before updating the app. Select High Priority to update the app as soon as the developer has published the app, regardless of charge status, WiFi capability, or end user activity on the device. Select Postponed to forgo app updates for up to 90 days. High priority and postponed will only take effect on DO devices.", "Certificate": { "customSubjectName": "CN={{UserName}},E={{EmailAddress}},OU=EnterpriseUsers,O=Contoso Corporation,L=Redmond,ST=WA,C=US\nor\nCN={{AAD_Device_ID}},E={{EmailAddress}},OU=EnterpriseUsers,O=Contoso Corporation,L=Redmond,ST=WA,C=US", "keySize": "Select the number of bits contained in the key.", "keyUsage": "Specify the cryptographic action that is required to exchange the certificate’s public key.", "renewalThreshold": "Enter the percentage (between 1 and 99 percent) of remaining certificate lifetime that is allowed before a device can request renewal of the certificate. The recommended amount in Intune is 20%. (1-99)", "rootCert": "Choose a previously configured and assigned root CA certificate profile. The CA certificate must match the root certificate of the CA that is issuing the certificate for this profile (the one you are currently configuring).", "scepServerUrl": "Enter a URL for the NDES Server that issues certificates through SCEP (Must be HTTPS). e.g. https://contoso.com/certsrv/mscep/mscep.dll", "scepServerUrls": "Add one or more URLs for the NDES Server that issues certificates through SCEP (Must be HTTPS). e.g. https://contoso.com/certsrv/mscep/mscep.dll", "subjectAlternativeName": "Subject alternative name", "subjectNameFormat": "Subject name format", "validityPeriod": "The amount of time remaining before the certificate expires. Enter a value that is equal to or lower than the validity period shown in the certificate template. Default is set at one year." }, "configurationSettingsFormat": "Configuration settings format text", "ignoreVersionDetection": "Set this to “Yes” for apps that are automatically updated by the app developer (such as Google Chrome).", "ignoreVersionDetectionMacOSLobApp": "Select \"Yes\" for apps that are automatically updated by app developer or to only check for app bundleID before installation. Select \"No\" to check for app bundleID and version number before installation.", "installAsManagedMacOSLobApp": "This setting only applies to macOS 11 and higher. The app will be installed but not managed on macOS 10.15 and lower.", "installContextDropdown": "Select the appropriate install context. User context will install the app only for the targeted user while device context will install the app for all users on the device.", "ldapUrl": "This is the LDAP hostname where clients can get the public encryption keys for email recipients. Emails will be encrypted when a key is available. Supported formats: ​", "permissionsSettings": "Select runtime permissions for the associated app.", "policyAssociatedApp": "Select the app that this policy will be associated with.", "policyConfigurationSettings": "Select the method you want to use to define configuration settings for this policy.", "policyDescription": "Optionally, enter a description for this configuration policy.", "policyEnrollmentType": "Choose whether these settings are managed through device management or apps made with Intune SDK.", "policyName": "Enter a name for this configuration policy.", "policyPlatform": "Select the platform this app configuration policy will apply to.", "policyProfileType": "Select the device profile types that this app configuration profile will apply to", "policySMime": "Configure S/MIME signing and encryption settings for Outlook.", "sMimeDeployCertsFromIntune": "Specify whether or not S/MIME certificates will be delivered from Intune for use with Outlook.\nIntune can automatically deploy signing and encryption certificates to users through the Company Portal.", "sMimeEnable": "Specify whether or not S/MIME controls are enabled when composing an email", "sMimeEnableAllowChange": "Specify if the user is allowed to change the Enable S/MIME setting.", "sMimeEncryptAllEmails": "Specify whether or not all emails must be encrypted.\nEncrypting converts data to cipher text so that only the intended recipient can read it.", "sMimeEncryptAllEmailsAllowChange": "Specify if the user is allowed to change the Encrypt all emails setting.", "sMimeEncryptionCertProfile": "Specify certificate profile for email encryption.", "sMimeSignAllEmails": "Specify whether or not all emails must be signed.\nA digital signature verifies the authenticity of the email and ensures that the contents are not tampered with in transit.", "sMimeSignAllEmailsAllowChange": "Specify if the user is allowed to change the Sign all emails setting.", "sMimeSigningCertProfile": "Specify certificate profile for email signing.", "sMimeUserNotificationType": "Method to notify users that they must open Company Portal to retrieve S/MIME certificates for Outlook." }, "AppInformationTab": { "descriptionPreview": "Preview", "descriptionPreviewLabel": "Preview", "descriptionRequired": "Description is required.", "editDescription": "Edit Description", "Info": { "applicableDeviceType": "Select the device types that can install this app.​", "appPackageFile": "A file that contains your app in a format that can be sideloaded on a device. Valid package types include: Android (.apk), iOS (.ipa), macOS (.pkg), Windows (.msi, .appx, .appxbundle, .msix, and .msixbundle).​", "AppStoreUrl": { "android": "Enter the link to the app listing in Google Play store. For example:", "androidLink": "https://play.google.com/store/apps/details?id=com.microsoft.office.outlook", "microsoftStore": "Enter the 'Link for Intune' URL for the app provided from the store. For more information, see {0}.", "microsoftStoreLink": "https://go.microsoft.com/fwlink/?linkid=2115228", "microsoftStoreLinkText": "Add Microsoft Store apps (legacy) to Microsoft Intune", "windows": "Enter the link to the app listing in the Microsoft Store. For example:", "windowsLink": "https://www.microsoft.com/p/microsoft-to-do-lists-tasks-reminders/9nblggh5r558" }, "category": "You can choose one or more categories to make it easier for users to find the app in Company Portal.", "categoryLearnMore": "Learn more about app categories", "categoryLink": "https://go.microsoft.com/fwlink/?linkid=2295954", "categoryWhenApprovalRequired": "You can choose one or more categories to make it easier for users to find the app in Company Portal. Though a change request is created, changing app categories doesn't require approval. Such a change takes place immediately.", "description": "Help your device users understand what the app is and/or what they can do in the app. This description will be visible to them in Company Portal.", "developer": "The name of the company or Individual that developed the app. This information will be visible to people signed into the admin center.", "displayVersion": "The version of the app. This information will be visible to users in the Company Portal.", "fullScreenEnabled": "If configured to yes, launches the web clip as a full-screen web app.", "ignoreManifestScope": "If configured to yes, a full screen web clip can navigate to an external web site without showing Safari UI. Otherwise, Safari UI appears when navigating away from the web clip’s URL. This key has no effect when Full screen is false.", "infoUrl": "Link people to a website or documentation that has more information about the app. The information URL will be visible to users in Company Portal.", "isFeatured": "Featured apps are prominently placed in Company Portal so that users can quickly get to them.", "logo": "Upload a logo that's associated with the app. This logo will appear next to the app throughout Company Portal.​", "macOSDmgAppPackageFile": "A file that contains your app in a format that can be sideloaded on a device. Valid package type: .dmg.​", "macOSPkgAppPackageFile": "A file that contains your app in a format that can be sideloaded on a device. Valid package type: .pkg.​", "minOperatingSystem": "Select the earliest operating system version on which the app can be installed. If you assign the app to a device with an earlier operating system, it will not be installed.​", "name": "Add a name for the app. This name will be visible in the Intune apps list and to users in the Company Portal.​", "notes": "Add additional notes about the app. Notes will be visible to people signed in to the admin center.", "owner": "The name of the person in your organization who manages licensing or is the point-of-contact for this app. This name will be visible to people signed in to the admin center.​", "packageId": "The app Package Identifier is the unique value that identifies the app.", "packageName": "Contact the device manufacturer to get the app's package name. Example package name: com.example.app​​", "preComposedIconEnabled": "If configured to yes, prevents SpringBoard from adding \"shine\" to the icon.", "privacyUrl": "Provide a link for people who want to learn more about the app's privacy settings and terms. The privacy URL will be visible to users in Company Portal.", "publisher": "The name of the developer or company that distributes the app. This information will be visible to users in Company Portal.", "selectApp": "Search the App Store for iOS store apps that you want to deploy with Intune.", "targetApplicationBundleIdentifier": "The application bundle identifier that specifies the application which opens the URL. Available in iOS 14 and later.", "useManagedBrowser": "If required, when a user opens the web app, it will open in an Intune-protected browser such as Microsoft Edge or Intune Managed Browser. This setting applies to both iOS and Android devices.", "useManagedBrowserLearnMore": "Learn more about managed browsers", "useManagedBrowserLink": "https://go.microsoft.com/fwlink/?linkid=2299509", "win32AppPackageFile": "A file that contains your app in a format that can be sideloaded on a device. Valid package type: .intunewin.​", "winGetStoreSelectApp": "Search the Microsoft Store app (new) for store apps that you want to deploy with Intune." }, "macOSMinOperatingSystemAdditionalInfo": "The minimum operating system for uploading a .pkg file is macOS 10.14. Upload a .pkg file to select an older minimum operating system.​", "markdownHelpLink": "Get help with markdown supported for descriptions.", "name": "App information", "nameForOfficeSuitApp": "App suite information", "Status": { "active": "Active", "deleted": "Deleted", "softDeleted": "Soft-Deleted" } }, "ApplicabilityRules": { "assignIf": "Assign profile if", "deleteWarning": "This will delete the selected Applicability Rule", "dontAssignIf": "Don't assign profile if", "editionDisplayText": "{0} {1}", "editionDisplayTextMore": "and {0} more", "GridLabel": { "property": "Property", "rule": "Rule", "ruleDetails": "Rule Details", "value": "Value" }, "instructions": "Specify how to apply this profile within an assigned group. Intune will only apply the profile to devices that meet the combined criteria of these rules.", "maxText": "Max", "minText": "Min", "noActionRow": "No Applicability Rules Specified", "oSVersion": "e.g. 1.2.3.4", "toText": "to", "windows10Education": "Windows 10/11 Education", "windows10EducationN": "Windows 10/11 Education N", "windows10Enterprise": "Windows 10/11 Enterprise", "windows10EnterpriseN": "Windows 10/11 Enterprise N", "windows10HolographicEnterprise": "Windows 10 Holographic for Business", "windows10Home": "Windows 10/11 Home", "windows10HomeChina": "Windows 10 Home China", "windows10HomeN": "Windows 10/11 Home N", "windows10HomeSingleLanguage": "Windows 10/11 Home Single Language", "windows10IoTCore": "Windows 10 IoT Core", "windows10IoTCoreCommercial": "Windows 10 IoT Core Commercial", "windows10Mobile": "Windows 10 Mobile", "windows10MobileEnterprise": "Windows 10 Mobile Enterprise", "windows10OsEdition": "OS edition", "windows10OsVersion": "OS version", "windows10Professional": "Windows 10/11 Professional", "windows10ProfessionalEducation": "Windows 10/11 Professional Education", "windows10ProfessionalEducationN": "Windows 10/11 Professional Education N", "windows10ProfessionalN": "Windows 10 Professional N", "windows10ProfessionalWorkstation": "Windows 10/11 Professional Workstation", "windows10ProfessionalWorkstationN": "Windows 10/11 Professional Workstation N", "windows11CloudEdition": "Windows 11 SE", "windows11CloudEditionN": "Windows 11 SE N" }, "ApplicableDeviceType": { "iPad": "iPad", "iPhoneAndIPod": "iPhone and iPod" }, "AppProtection": { "allAppTypes": "Target to all app types", "androidPlatformLabel": "Android", "appsInAndroidWorkProfile": "Apps in Android Work Profile", "appsOnAndroidEnterpriseDedicatedDevicesWithAzureAdSharedMode": "Apps On Android Enterprise Dedicated Devices With Microsoft Entra Shared Mode", "appsOnAndroidOpenSourceProjectUserAssociated": "Apps On Android Open Source Project User Associated", "appsOnAndroidOpenSourceProjectUserless": "Apps On Android Open Source Project Userless", "appsOnIntuneManagedDevices": "Apps on Intune managed devices", "appsOnUnmanagedDevices": "Apps on unmanaged devices", "iosAndroidMacPlatformLabel": "iOS, Android, Mac", "iosAndroidPlatformLabel": "iOS, Android", "iOSPlatformLabel": "iOS/iPadOS", "macPlatformLabel": "Mac", "notAvailable": "Not Available", "windows10PlatformLabel": "Windows 10 and later", "withEnrollment": "With enrollment", "withoutEnrollment": "Without enrollment" }, "AppRelationshipStatus": { "dependencyGraphAriaLabel": "App dependency chart", "Grid": { "appVersion": "App Version", "dependencyName": "Dependency name", "lastModifiedTime": "Last modified time", "relationship": "Relationship", "replaced": "Replaced", "searchPlaceholder": "Filter by app name", "status": "Status details", "statusDetails": "Status", "supersedenceName": "Supersedence name" }, "RelatedAppRelationship": { "dependencyDescendants": "Child dependency", "indirectSupersedence": "Not directly related", "supersedenceAncestors": "Superseding", "supersedenceDescendants": "Superseded" }, "SupersededReplaced": { "no": "No", "yes": "Yes" }, "supersedenceGraphAriaLabel": "App supersedence chart", "Tabs": { "chart": "Chart", "dependency": "Dependency", "label": "View: ", "supersedence": "Supersedence", "table": "Table" } }, "AppResources": { "AppSettingsUx": { "allowDownloadsOverCellular": "Allow downloads over cellular", "assignmentFilterColumnHeader": "Filter", "assignmentFilterTypeColumnHeader": "Filter mode", "assignmentToast": "End user notifications", "assignmentTypeTableHeader": "ASSIGNMENT TYPE", "associatedDomains": "Associated Domains", "associatedDomainsDirectDownloadAllowed": "Associated Domains Direct Download Allowed", "automaticAppUpdates": "Automatic app updates", "autoUpdate": "Auto-update", "deadlineTimeColumnLabel": "Installation deadline", "deliveryOptimizationPriorityHeader": "Delivery optimization priority", "detectAppsInUseHeader": "Detect in-use apps", "groupTableHeader": "Group", "installContextLabel": "Install Context", "isRemovable": "Install as removable", "licenseTypeLabel": "License type", "modeTableHeader": "Group mode", "policySet": "Policy Set", "preventAutoAppUpdate": "Prevent automatic app updates", "preventManagedAppBackup": "Prevent iCloud app backup", "restartGracePeriodHeader": "Restart grace period", "startTimeColumnLabel": "Availability", "statusTableHeader": "Status", "tapToPayScreenLockEnabled": "Tap to Pay Screen Lock Enabled", "tracks": "Tracks", "uninstallOnRemoval": "Uninstall on device removal", "updateMode": "Update Priority", "vPN": "VPN" }, "AppType": { "aADWebApp": "AAD web app", "androidAospReferencedApp": "Referenced app", "androidEnterpriseSystemApp": "Android Enterprise system app", "androidForWorkApp": "Managed Google Play store app", "androidLobApp": "Android line-of-business app", "androidStoreApp": "Android store app", "builtInAndroid": "Built-In Android app", "builtInApp": "Built-In app", "builtInIos": "Built-In iOS app", "iosIPadOSWebClip": "iOS/iPadOS web clip", "iosLobApp": "iOS line-of-business app", "iosStoreApp": "iOS store app", "iosVppApp": "iOS volume purchase program app", "lineOfBusinessApp": "Line-of-business app", "macOSDmgApp": "macOS app (DMG)", "macOSEdgeApp": "Microsoft Edge (macOS)", "macOSLobApp": "macOS line-of-business app", "macOSMicrosoftDefenderApp": "Microsoft Defender ATP (macOS)", "macOSOfficeSuiteApp": "macOS Office Suite", "macOSPkgApp": "macOS app (PKG)", "macOsVppApp": "macOS volume purchase program app", "macOSWebClip": "macOS web clip", "managedAndroidLobApp": "Managed Android line-of-business app", "managedAndroidStoreApp": "Managed Android store app", "managedGooglePlayApp": "Managed Google Play store app", "managedGooglePlayPrivateApp": "Managed Google Play private app", "managedGooglePlayWebApp": "Managed Google Play web link", "managedIosLobApp": "Managed iOS line-of-business app", "managedIosStoreApp": "Managed iOS store app", "microsoftStoreForBusinessApp": "Microsoft Store for Business app", "microsoftStoreForBusinessReleaseManagedApp": "Microsoft Store for Business", "officeAddIn": "Office add-in", "officeSuiteApp": "Microsoft 365 Apps (Windows 10 and later)", "sharePointApp": "SharePoint app", "teamsApp": "Teams app", "webApp": "Web link", "win32CatalogApp": "Windows catalog app (Win32)", "windowsAppXLobApp": "Windows AppX line-of-business app", "windowsAutoUpdateCatalogApp": "Windows auto-update catalog app", "windowsClassicApp": "Windows app (Win32)", "windowsEdgeApp": "Microsoft Edge (Windows 10 and later)", "windowsMobileMsiLobApp": "Windows MSI line-of-business app", "windowsPhone81AppXBundleLobApp": "Windows Phone 8.1 AppX line-of-business app", "windowsPhone81AppXLobApp": "Windows Phone 8.1 AppX line-of-business app", "windowsPhone81StoreApp": "Windows Phone 8.1 store app", "windowsPhoneXapLobApp": "Windows Phone XAP line-of-business app", "windowsStoreApp": "Microsoft Store app (legacy)", "windowsUniversalAppXLobApp": "Windows Universal AppX line-of-business app", "windowsUniversalLobApp": "Windows Universal line-of-business app", "windowsWebApp": "Windows web link", "winGetPublicApp": "Windows Package Manager Community Repository", "winGetStoreApp": "Microsoft Store app (new)" }, "AppTypePlatform": { "android": "Android", "ios": "iOS", "macOs": "macOS", "web": "Web", "windows": "Windows" }, "AssignmentAction": { "exclude": "Excluded", "include": "Included", "includeAllDevicesVirtualGroup": "Included", "includeAllUsersVirtualGroup": "Included" }, "AssignmentToast": { "hideAll": "Hide all toast notifications", "showAll": "Show all toast notifications", "showReboot": "Show toast notifications for computer restarts" }, "AutoUpdateSupersededApps": { "enabled": "Yes", "notConfigured": "No" }, "DeliveryOptimizationPriority": { "backgroundNormal": "Background", "displayText": "Content download in {0}", "foreground": "Foreground", "header": "Delivery optimization priority" }, "DeviceRestartBehaviorOptions": { "allow": "App install may force a device restart", "basedOnReturnCode": "Determine behavior based on return codes", "force": "Intune will force a mandatory device restart", "suppress": "No specific action" }, "FilterType": { "exclude": "Exclude", "include": "Include", "none": "None" }, "InstallIntent": { "available": "Available for enrolled devices", "availableWithoutEnrollment": "Available with or without enrollment", "notApplicable": "Not applicable", "required": "Required", "uninstall": "Uninstall" }, "SettingType": { "assignmentType": "Assignment type", "deviceLicensing": "License type", "installContext": "Uninstall on device removal", "toastSettings": "End user notifications", "vpnConfiguration": "VPN" }, "UpdateMode": { "default": "Default", "postponed": "Postponed", "priority": "High Priority" } }, "AppType": { "androidAospReferencedApp": "Android AOSP referenced app", "androidEnterpriseSystemApp": "Android Enterprise system app", "androidForWorkApp": "Managed Google Play store app", "androidLobApp": "Android line-of-business app", "androidStoreApp": "Android store app", "builtInAndroid": "Built-In Android app", "builtInApp": "Built-In app", "builtInIos": "Built-In iOS app", "default": "", "iosIPadOSWebClip": "iOS/iPadOS web clip", "iosLobApp": "iOS line-of-business app", "iosStoreApp": "iOS store app", "iosVppApp": "iOS volume purchase program app", "lineOfBusinessApp": "Line-of-business app", "macOSDmgApp": "macOS app (DMG)", "macOSEdgeApp": "Microsoft Edge (macOS)", "macOSLobApp": "macOS line-of-business app", "macOSMicrosoftDefenderApp": "Microsoft Defender for Endpoint (macOS)", "macOSOfficeSuiteApp": "Microsoft 365 Apps (macOS)", "macOSPkgApp": "macOS app (PKG)", "macOsVppApp": "macOS volume purchase program app", "macOSWebClip": "macOS web clip", "managedAndroidLobApp": "Managed Android line-of-business app", "managedAndroidStoreApp": "Managed Android store app", "managedGooglePlayApp": "Managed Google Play store app", "managedGooglePlayPrivateApp": "Managed Google Play private app", "managedGooglePlayWebApp": "Managed Google Play web link", "managedIosLobApp": "Managed iOS line-of-business app", "managedIosStoreApp": "Managed iOS store app", "microsoftStoreForBusinessApp": "Microsoft Store for Business app", "microsoftStoreForBusinessReleaseManagedApp": "Microsoft Store for Business", "officeSuiteApp": "Microsoft 365 Apps (Windows 10 and later)", "webApp": "Web link", "windowsAppXLobApp": "Windows AppX line-of-business app", "windowsAutoUpdateCatalogApp": "Windows Auto Update Catalog app", "windowsClassicApp": "Windows app (Win32)", "windowsEdgeApp": "Microsoft Edge (Windows 10 and later)", "windowsMobileMsiLobApp": "Windows MSI line-of-business app", "windowsPhone81AppXBundleLobApp": "Windows Phone 8.1 AppX line-of-business app", "windowsPhone81AppXLobApp": "Windows Phone 8.1 AppX line-of-business app", "windowsPhone81StoreApp": "Windows Phone 8.1 store app", "windowsPhoneXapLobApp": "Windows Phone XAP line-of-business app", "windowsStoreApp": "Microsoft Store app (legacy)", "windowsUniversalAppXLobApp": "Windows Universal AppX line-of-business app", "windowsUniversalLobApp": "Windows Universal line-of-business app", "windowsWebApp": "Windows web link" }, "ArchitectureOptions": { "arm64InstructionSet": "Install on ARM64 system", "checkBox": "Please select at least one architecture setting", "sixtyFourBit": "64-bit", "sixtyFourBitInstructionSet": "Install on x64 system", "thirtyTwoBit": "32-bit", "thirtyTwoBitInstructionSet": "Install on x86 system" }, "Assignment": { "AutoUpdateMode": { "default": "Default", "header": "Update Priority", "postponed": "Postponed", "priority": "High Priority" }, "AutoUpdateSupersededApps": { "label": "Auto-update", "sublabel": "If superseded app(s) have been installed by the user from Company Portal, require superseding app to be installed." }, "DeliveryOptimizationPriority": { "backgroundNormal": "Background", "displayText": "Content download in {0}", "foreground": "Foreground", "header": "Delivery optimization priority" }, "InUseDetection": { "countdownTimerLabel": "Notification countdown", "countdownTimerSubLabel": "minutes", "countdownTimerTooltip": "The amount of time a notification shows for before the enforcement occurs automatically. If there are deferrals remaining this is how long the user has to defer the install.", "numberOfDeferralsLabel": "Enforcement deferrals", "numberOfDeferralsTooltip": "Number of times the user can defer enforcement before it occurs automatically.", "sectionTitle": "App in use detection", "timeBetweenDeferralsLabel": "Time between deferrals", "timeBetweenDeferralsSubLabel": "minutes", "timeBetweenDeferralsTooltip": "Time between consecutive deferral opportunities.", "toggleLabel": "Notifications", "toggleTooltip": "Select enabled to show notifications to users and configure number of deferrals before processes are closed and the app is enforced." }, "RestartGracePeriod": { "allowSnooze": "Allow user to snooze the restart notification", "countdownDialog": "Select when to display the restart countdown dialog box before the restart occurs (minutes)", "durationInMinutes": "Device restart grace period (minutes)", "snoozeDurationInMinutes": "Select the snooze duration (minutes)" }, "restartGracePeriodHeader": "Restart grace period", "restartGracePeriodLabel": "Device restart grace period", "SoftwareInstallationTime": { "dateAndTimeLabel": "Date and time", "deadlineTimeColumnLabel": "Installation deadline", "deadlineTimeDatePickerErrorMessage": "Selected date must be after the available date", "deadlineTimeLabel": "App installation deadline", "defaultTime": "As soon as possible", "infoText": "This application will be available as soon as it has been deployed, unless you specify an availability time below. If this is a required application, you may specify the installation deadline.", "specificTime": "A specific date and time", "startTimeColumnLabel": "Availability", "startTimeDatePickerErrorMessage": "Selected date must be before the deadline date", "startTimeLabel": "App availability", "TimeZone": { "label": "Time zone", "local": "Device time zone", "utc": "UTC" } }, "summaryTitle": "End user experience" }, "AssignmentAction": { "exclude": "Excluded", "include": "Included", "includeAllDevicesVirtualGroup": "Included", "includeAllUsersVirtualGroup": "Included" }, "AssignmentFilters": { "assignmentFilterColumnHeader": "Filter", "noFilters": "None" }, "Autopilot": { "allDevices": "All devices", "allDevicesAlreadyAssignedError": "An Autopilot profile is already assigned to All Devices.", "assignedDevicesCount": "Assigned devices", "assignedDevicesResourceAccountDescription": "

To deploy this profile to a device, you must assign the device a Resource account. Select one device at a time to assign an existing Resource account or to create a new one. Learn more about Resource Accounts

", "assignedDevicesResourceAccountStatusBarMessage": "This table only lists the Surface Hub 2 devices that have been assigned this profile.", "assignFailedDescription": "Failed to update assignments for {0}.", "assignFailedTitle": "Failed to update Autopilot profile assignments.", "assigningDescription": "Updating assignments for {0}.", "assigningTitle": "Updating Autopilot profile assignments.", "AssignResourceAccount": { "createNewCommandMenu": "Create new", "createNewResourceAccountInfo": "

\nCreate a new resource account during enrollment. The Resource account will be added to the Resource account table right away, but won't be active until the device is enrolled, and the Surface Hub subscription is verified. Learn more about Resource Accounts

\n ", "createNewResourceTitle": "Create new resource account", "deviceNameInvalid": "Device name is in an invalid format", "deviceNameRequired": "A device name is required", "editResourceAccountLabel": "Edit", "selectExistingCommandMenu": "Select existing" }, "assignSuccessDescription": "Successfully updated assignments for {0}.", "assignSuccessTitle": "Successfully updated Autopilot profile assignments.", "assignSufaceHub2ProfileNextStep": "Next steps for this deployment", "assignSurfaceHub2ProfileToDeviceGroup": "1. Assign this profile to at least one device group", "assignSurfaceHub2ProfileToResourceAccount": "2. Assign a resource account to each Surface Hub device to which you deploy this profile", "autoremediationContext": "We've detected a hardware change on this device. We're trying to automatically register the new hardware. You don't need to do anything now; the status will be updated at the next check in with the result. Learn more about resetting the profile.", "autoremediationTitle": "Device {0} has a fix pending", "cannotDeleteMessage": "This profile is assigned to groups. You must unassign all groups from this profile before you can delete it.", "cannotDeleteTitle": "Cannot delete {0}", "createdDateTime": "Created", "deleteMessage": "If you delete this Autopilot profile, any devices assigned to this profile will display Unassigned.", "deleteMessageWithPolicySet": "{0} is included in one or more policy sets. If you delete {0}, you'll no longer be able to assign it via these policy sets.", "deleteTitle": "Are you sure you want to delete this profile?", "description": "Description", "Device": { "ComputerName": { "validFormat": "Names must be 15 characters or less, and can contain letters (a-z, A-Z), numbers (0-9), and hyphens. Names must not contain only numbers. Names cannot include a blank space." }, "Header": { "addressableUserName": "User friendly name", "azureADDevice": "Associated Microsoft Entra device", "batch": "Group tag", "dateAssigned": "Date assigned", "deviceAccountPwd": "Device account password", "deviceAccountUpn": "Device account", "deviceDisplayName": "Device name", "deviceFriendlyName": "Device friendly name", "deviceName": "Device name", "deviceUseType": "Device-use type", "enrollmentState": "Enrollment state", "intuneDevice": "Associated Intune device", "lastContacted": "Last contacted", "make": "Manufacturer", "model": "Model", "profile": "Assigned profile", "profileStatus": "Profile status", "purchaseOrderId": "Purchase order", "resourceAccount": "Resource account", "serialNumber": "Serial number", "userPrincipalName": "User" }, "SurfaceHub": { "friendlyNameRequired": "A friendly name is required", "pwdRequired": "A password is required", "pwdValidFormat": "Unable to update the password. The value provided for the new password does not meet the lenght or complexity requirements of the domain.", "upnRequired": "A device account is required", "upnValidFormat": "Values can contain letters (a-z, A-Z), numbers (0-9), and hyphens. Values cannot include a blank space." } }, "Devices": { "featureDescription": "Windows Autopilot lets you customize the out-of-box experience (OOBE) for your users.", "importErrorStatus": "Some devices were not imported. Click here for more information.", "importPendingStatus": "Import in progress. Elapsed time: {0} min. This process can take up to {1} min." }, "deviceType": "Device type", "deviceUse": "Device use", "DeviceUseType": { "meetingAndPresentation": "Meeting and presentation", "teamCollaboration": "Team collaboration" }, "DirectoryService": { "activeDirectoryAD": "Microsoft Entra hybrid joined", "activeDirectoryADLabel": "Microsoft Entra hybrid join with Autopilot", "azureAD": "Microsoft Entra joined", "unknownType": "Unknown Type" }, "directoryServiceHintForSurfaceHub2": "

\n Autopilot only supports Microsoft Entra Joined for Surface Hub 2 devices. Specify how devices join Active Directory (AD) in your organization.\n

\n \n ", "directoryServiceHintForWindowsPC": "\n

\n Specify how devices join Active Directory (AD) in your organization:\n

\n \n ", "directoryServiceLabel": "Join to Microsoft Entra ID as", "Filter": { "enrollmentState": "State", "profile": "Profile status" }, "getAssignedDevicesCountError": "An error occurred while fetching the assigned devices count.", "getAssignmentsError": "An error occurred while fetching Autopilot profile assignments.", "harvestDeviceId": "Convert all targeted devices to Autopilot", "harvestDeviceIdDescription": "By default, this profile can only be applied to Autopilot devices synced from the Autopilot service.", "harvestDeviceIdInfo": "\n Select Yes to register all targeted devices to Autopilot if they are not already registered. The next time registered devices go through the Windows Out of Box Experience (OOBE), they will go through the assigned Autopilot scenario.\n
\n Please note that certain Autopilot scenarios require specific minimum builds of Windows. Please make sure your device has the required minimum build to go through the scenario.\n
\n Removing this profile won’t remove affected devices from Autopilot. To remove a device from Autopilot, use the Windows Autopilot Devices view.\n ", "harvestDeviceIdWarning": "After conversion, Autopilot devices can only be reverted by deleting them from the Autopilot devices list.", "holoLensCommandMenu": "HoloLens", "info": "Windows Autopilot deployment profiles lets you customize the out-of-box experience for your devices.", "invalidProfileNameMessage": "Character \"{0}\" is not allowed", "joinTypeLabel": "Join Microsoft Entra ID as", "lastModifiedDateTime": "Last modified:", "manualRemediationContext": "We've detected a hardware change on this device. It won't automatically receive an Autopilot profile when it's reset unless you register the device again. Learn more about resetting the profile.", "manualRemediationTitle": "Device {0} needs your attention", "name": "Name", "noAutopilotProfile": "No Autopilot profiles", "notEnoughPermissionAssignedError": "You don't have enough permissions to assign this profile to one or more of your selected groups. Please contact your administrator.", "OOBE": { "accountType": "User account type", "accountTypeInfo": "Specify whether users are administrators or standard users on the device.  Note that this setting does not apply to Global Administrator or Company Administrator accounts. These accounts cannot be standard users because they have access to all administrative features in Microsoft Entra ID.", "AddressableUserName": { "validateEmpty": "User friendly name cannot be empty." }, "ApplyComputerNameTemplate": { "infoBalloon": "Create a naming template to add names to your devices during enrollment.", "label": "Apply device name template" }, "ApplyComputerNameTemplateDisabled": { "label": "For Microsoft Entra hybrid joined type of Autopilot deployment profiles, devices are named using settings specified in Domain Join configuration." }, "ComputerNameTemplate": { "emptyValue": "MyCompany-%RAND:4%", "label": "Enter a name", "noDisallowedChars": "Name must only contain alphanumeric characters, hyphens, %SERIAL%, or %RAND:x%", "serialLength": "Cannot use more than 7 characters with %SERIAL%", "validateLessThan15Chars": "Name must be 15 characters or less", "validateNoSpaces": "Computer names cannot contain spaces", "validateNotAllNumbers": "Name must also contain letters and/or hyphens", "validateNotEmpty": "Name cannot be empty", "validateOnlyOneMacro": "Name must only contain one of %SERIAL% or %RAND:x%" }, "configOOBEInfo": "

\nConfigure the out-of-box experience for your Autopilot devices\n

", "ConfigureComputerNameTemplate": { "description": "Create a unique name for your devices. Names must be 15 characters or less, and can contain letters (a-z, A-Z), numbers (0-9), and hyphens. Names must not contain only numbers. Names cannot include a blank space. Use the %SERIAL% macro to add a hardware-specific serial number. Alternatively, use the %RAND:x% macro to add a random string of numbers, where x equals the number of digits to add." }, "configureDevice": "Deployment mode", "configureDeviceHintForSurfaceHub2": "Autopilot only supports self-deploying mode for Surface Hub 2. This mode doesn't associate the user with the enrolled device, so it doesn't require user credentials.​", "configureDeviceHintForWindowsPC": "

\n Deployment mode controls if a user needs to provide credentials in order to provision the device.\n

\n ", "createSurfaceHub2Info": "Configure the Autopilot enrollment settings for your Surface Hub 2 devices. By default Autopilot enables skipping user authentication during OOBE. Learn more about Windows Autopilot for Surface Hub 2.", "createWindowsPCInfo": "\n

\nThe following options are automatically enabled for Autopilot devices in self-deploying mode:\n

\n", "EnableWhiteGlove": { "infoBalloon": "Enable pressing Windows key 5 times to run OOBE without user authentication to enroll device and provision all system-context apps and settings. User-context apps and settings will be delivered when the user signs in.", "label": "Allow pre-provisioned deployment" }, "endUserDevice": "User-Driven", "hideEscapeLink": "Hide change account options", "hideEscapeLinkInfo": "Options to change account and start over with a different account appear, respectively, during initial device setup on the company sign-in page, and on the domain error page. To hide these options, you must configure company branding in Microsoft Entra ID (requires Windows 10, 1809 or later, or Windows 11).", "HybridAzureADSkipConnectivityCheck": { "infoBalloon": "The Autopilot Microsoft Entra hybrid join flow will continue even if it does not establish domain controller connectivity during OOBE.", "label": "Skip AD connectivity check" }, "info": "Autopilot profile settings define the out-of-box experience users see when starting Windows for the first time. ", "language": "Language (Region)", "languageInfo": "Specify the language and region that will be used.", "licenseAgreement": "Microsoft Software License Terms", "licenseAgreementInfo": "Specify whether to show the EULA to users.", "plugAndForgetDevice": "Self-Deploying", "privacySettings": "Privacy settings", "privacySettingsInfo": "Specify whether to show privacy settings to users.", "privacySettingWarning": "The default value for diagnostic data collection has changed for devices running Windows 10, version 1903 and later, or Windows 11. ", "showCortanaConfigurationPage": "Cortana configuration", "showCortanaConfigurationPageInfo": "Show will enable the Cortana configuration introduction during startup.", "skipEULAWarning": "Important information about hiding license terms", "skipKeyboardSelection": "Automatically configure keyboard", "skipKeyboardSelectionInfo": "If true, skip the keyboard selection page if Language is set.", "subtitle": "Autopilot profiles", "title": "Out-of-box experience (OOBE)", "useOSDefaultLanguage": "Operating system default", "userSelect": "User select" }, "profile": "profile", "resourceAccountStatusBarMessage": "A Resource Account is required for each Surface Hub 2 device to which this profile is deployed. Click to learn more.", "selectServices": "Select directory service devices will join", "surfaceHub2CommandMenu": "Surface Hub 2", "surfaceHub2SCommandMenu": "Surface Hub 2S", "Sync": { "lastRequestedLabel": "Last sync request", "lastSuccessfulLabel": "Last successful sync", "syncInitiated": "Autopilot settings sync initiated.", "syncInProgress": "Sync is in progress. Check back again soon.", "syncSettingsTitle": "Sync Autopilot settings" }, "Title": { "devices": "Windows Autopilot devices" }, "Tooltips": { "addressableUserName": "Greeting name displayed during device setup.", "azureADDevice": "Go to device details for associated device. N/A means that there's no associated device.", "batch": "A string attribute that can be used to identify a group of devices. Intune's group tag field maps to the OrderID attribute on Microsoft Entra devices.", "dateAssigned": "Timestamp of when the profile was assigned to the device.", "deviceAccountPwd": "Device account password for Surface Hub devices. If entered, also fill out device account and friendly name.", "deviceAccountUpn": "Device account email for Surface Hub devices. If entered, also fill out device account password and friendly name.", "deviceDisplayName": "Configure a unique name for a device. This name will be ignored in Microsoft Entra hybrid joined deployments. Device name still comes from the domain join profile for Microsoft Entra hybrid devices.", "deviceFriendlyName": "Device friendly name for Surface Hub devices. If entered, also fill out device account and device account password.", "deviceName": "The name shown when someone tried to discover and connect to the device.", "deviceUseType": " Device would setup based on your choice. You can always change later in settings.​\n ", "enrollmentState": "Specifies if the device has enrolled.", "intuneDevice": "Go to device details for associated device. N/A means that there's no associated device.", "lastContacted": "Timestamp of when the device was last contacted.", "make": "Manufacturer of the selected device.", "model": "Model of the selected device", "profile": "Name of the profile assigned to the device.", "profileStatus": "Specifies if a profile is assigned to the device.", "purchaseOrderId": "Purchase order ID", "resourceAccount": "The device's identity, or user principal name (UPN).", "serialNumber": "Serial number of the selected device.", "userPrincipalName": "User to pre-fill authentication during device setup." }, "userAffinityLabel": "Deployment mode", "windowsPCCommandMenu": "Windows PC" }, "AzureCA": { "AdrsUserActionSelectionWarning": { "conditions": "Conditions that require device registration are not available with \"Register or join devices\" user action.", "message": "Only \"Require multifactor authentication\" or \"Require authentication strength\" can be used in policies created for the \"Register or join devices\" user action.{0}" }, "advancedTabText": "Advanced", "agentContextInfoBalloonAriaLabelAccessibility": "Additional information about assistive agent protections", "agentIdentitiesAlert": "Some controls are not available due to 'agents' selection in policy assignment", "agentIdentitiesInfo": "Apply policy to all agent identities.", "agentIdentitiesSectionTitle": "Select agent identities", "agentIdentitiesSelectInfo": "Apply policy to specific agent identities.", "agents": "Agents", "agentSessionRiskInfoBalloonAriaLabelAccessibility": "Additional information about agent session risk levels", "agentsLicenseText": "A Microsoft Agent 365 or Microsoft 365 E7 license is required to edit this policy.", "agentsLicensingEnforcementDescription": "Starting soon, Conditional Access for agents will require a Microsoft Agent 365 license.", "agentsLicensingEnforcementLearnMoreAriaLabel": "Learn more about upcoming licensing enforcement for agents", "agentsLicensingEnforcementTitle": "Upcoming licensing enforcement", "agentsPolicyDescription": "Agent-based policies apply when agents access resources using their own identity, not on behalf of a user", "agentUser": "Agent User (Preview)", "agentUsersAlert": "During public preview, block access to all resources is the only policy configuration allowed for 'All agents acting as users' selection. Additional conditions and controls are coming soon.", "agentUsersDescription": "Agent users enable AI-powered applications to interact with systems and services that require user identities.", "agentUsersInfo": "Apply policy to all agents acting as users.", "agentUsersSectionTitle": "Select agent users (Preview)", "agentUsersSelect": "Select agents acting as users", "agentUsersSelectInfo": "Apply policy to specific agent users.", "agentUsersSelectTitle": "Select agent users (Preview)", "agentUsersWarning": "All agents acting as users cannot be combined with other selections.", "allAgentResourcesInfo": "Apply this policy to all agent identity and agent blueprint token requests.", "allAgentUsers": "All agent users (Preview)", "allAgentUsersGA": "All agent users (Preview)", "allCloudAppsErrorBox": "\"All cloud apps\" must be selected when \"Require password change\" grant is selected", "allCloudAppsReauth": "\"All cloud apps\" must be selected when \"Sign-in frequency every time\" session control and \"sign-in risk\" condition are selected", "allCloudOrSpecificApps": "The \"sign-in frequency every time\" session control requires \"all cloud apps\" or specifically-supported apps to be selected", "allDayCheckboxLabel": "All day", "allDevicePlatforms": "Any device", "allGuestUserInfoContent": "Includes Microsoft Entra B2B guests, but not SharePoint B2B guests", "allGuestUserLabel": "All guest and external users", "allNetworkAccessLocationsLabel": "All Compliant Network locations", "allRiskLevelsOption": "All risk levels", "allTrustedLocationLabel": "All trusted locations", "allTrustedNetworkLocationLabel": "All trusted networks and locations", "allUserGroupSetSelectorLabel": "All users and groups selected", "allUsersReauth": "The \"sign-in frequency every time\" session control requires \"All Users\" to be selected", "allUsersString": "All users", "and": "{0} AND {1} ", "androidDisplayName": "Android", "andWithGrouping": "({0}) AND {1} ", "anyCloudAppSelection": "Any cloud app", "appContextOptionInfoContent": "Requested authentication tag", "appContextOptionLabel": "Requested authentication tag (Preview)", "appContextUriPlaceholder": "Example: uri:contoso.com:level3", "appEnforceInfoBubble": "App enforced restrictions might require additional admin configurations within the cloud apps. The restrictions will only take effect for new sessions.", "applyConditionClientAppInfoBalloonContent": "Configure client apps to apply the policy to specific client apps", "applyConditionDevicePlatformInfoBalloonContent": "Configure device platforms to apply the policy to specific platforms", "applyConditionDeviceStateInfoBalloonContent": "Configure device state to apply the policy to specific device state(s)", "applyConditionLocation": "Configure Locations", "applyConditionLocationInfoBalloonContent": "Configure locations to apply the policy to trusted/untrusted locations", "applyConditionLocationInfoBalloonContentAgentUser": "Configure network to apply the policy to any or compliant network locations.", "applyConditionSigninRiskInfoBalloonContent": "Configure sign-in risk to apply the policy to selected risk level(s)", "applyConditionUserRiskInfoBalloonContent": "Configure user risk to apply the policy to selected risk level(s)", "applyConditonLabel": "Configure", "appNotFound": "App not found", "appNotFoundWarning": "The application was not found or has been deleted.", "appNotSetSeletorLabel": "0 cloud apps selected", "appReauthNotSupported": "This app does not support the \"sign-in frequency every time\" session control.", "ariaLabelPolicyDisabled": "Policy is disabled", "ariaLabelPolicyEnabled": "Policy is enabled", "ariaLabelPolicyReportOnly": "Policy is in Report-only mode", "AuthContext": { "addNewAuthContext": "New authentication context", "authContextForWorkloadIdentitiesPrivatePreviewMessage": "Applying 'Authentication context' to 'Workload identities' is in private preview.", "authContextForWorkloadIdentitiesPublicPreviewMessage": "Applying 'Authentication context' to 'Workload identities' is in public preview.", "bannerText": "Create your own authentication context values and Conditional Access policies with Microsoft Entra ID Premium", "checkBoxInfo": "Select the authentication contexts this policy will apply to", "configure": "Configure authentication contexts", "createCA": "Assign Conditional Access policies to the authentication context", "dataGrid": "List of authentication contexts", "Delete": { "failure": "Failed to delete {0}", "failureCa": "Failed to delete {0} because it is referenced by CA policies", "modifying": "Deleting {0}", "success": "Successfully deleted {0}" }, "deleteFailedByReference": "You cannot delete this authentication context because it is being referenced by CA policies.", "description": "Description", "documentation": "Documentation", "getStarted": "Get started", "Included": { "none": "No cloud apps, actions, or authentication contexts selected", "plural": "{0} authentication contexts included", "singular": "1 authentication context included" }, "InfoBlade": { "createTitle": "Add authentication context", "deleteDisallowed": "You cannot delete this authentication context while it is referenced by your Conditional Access policies.", "descLimit": "Descriptions can be up to 150 characters long.", "descPlaceholder": "Add description for the authentication context", "modifyTitle": "Modify authentication context", "namePlaceholder": "Ex. Trusted location, Trusted device, Strong authorization", "publishDesc": "Publish to apps will make the authentication context available for apps to use. Publish once you finish configuring Conditional Access policy for the tag. [Learn more][1]\n[1]: https://go.microsoft.com/fwlink/?linkid=2150966", "publishLabel": "Publish to apps", "titleDesc": "Configure an authentication context that will be used to protect application data and actions. Use names and descriptions that can be understood by application administrators. [Learn more][1]\n[1]:https://go.microsoft.com/fwlink/?linkid=2150965", "unpublishWarning": "Unpublishing this authentication context could result in losing access to the resource that is being secured by the authentication context." }, "label": "Authentication context", "menuLabel": "Authentication contexts", "name": "Name", "noAuthContextConfigured": "No authentication contexts have been configured.", "noAuthContextSet": "There are no authentication contexts", "noData": "No authentication contexts to display", "Notify": { "failure": "Failed to update {0}", "modifying": "Modifying {0}", "success": "Successfully updated {0}" }, "selectionInfo": "Authentication context is used to secure application data and actions in apps like SharePoint and Microsoft Cloud App Security.", "selectionInfoAriaLabel": "Learn more about authentication context.", "step": "Step", "tabDescription": "Manage authentication context to protect data and actions in your apps. Authentication contexts cannot be deleted when they are referenced by Conditional Access policies. [Learn more][1]\n[1]:https://go.microsoft.com/fwlink/?linkid=2150965", "tagResources": "Tag resources with an authentication context", "WhatIf": { "selected": "Authentication context included" } }, "authContextCallFailure": "The call to fetch authentication contexts failed please try again later.", "authContextReauthWarning": "Over-prompting users can occur when the \"Sign-in Frequency - every time\" setting is enabled with authentication contexts. {0}Read more about the recommended scenarios.{1}", "authenticationFlowsInfoBalloonAriaLabelAccessibility": "Additional information about authentication flows", "AuthenticationStrength": { "Mode": { "deviceBasedPush": "Microsoft Authenticator (Phone Sign-in)", "email": "Email One-Time Passcode", "fido2": "FIDO2 Security Key", "hardwareOath": "Hardware OATH tokens", "microsoftAuthenticatorPush": "Microsoft Authenticator (Push Notification)", "password": "Password", "sms": "SMS", "softwareOath": "Software OATH tokens", "temporaryAccessPassMultiUse": "Temporary Access Pass (Multi-use)", "temporaryAccessPassOneTime": "Temporary Access Pass (One-time use)", "voice": "Voice", "windowsHelloForBusiness": "Windows Hello For Business", "x509CertificateMultiFactor": "Certificate-based Authentication (Multifactor)", "x509CertificateSingleFactor": "Certificate-based Authentication (Single factor)" } }, "badRequest": "Bad request", "blockAccess": "Block access", "builtInDirectoryRoleLabel": "Built-in directory roles", "caeDisableRequireEmptyExclude": "Cannot exclude apps when \"Customize continuous access evaluation\" - \"Disable\" session control is selected.", "cannotDeleteNamedLocationsConfiguredInCAPolicy": "The named location cannot be deleted because it is referenced by one or more Conditional Access policies. You must remove this named location from all associated Conditional Access policies before deletion.", "cannotDeleteTrustedNamedLocations": "The named location cannot be deleted because it is marked as a trusted location. You must unmark this named location before deletion.", "cannotExcludeBothAllMsftAppsAndO365": "Exclude Office 365 apps doesn't have an impact when all Microsoft apps have been excluded.", "CAS": { "BuiltinPolicy": { "ariaLabel": "Choose the kind of Conditional Access App Control to apply", "Option": { "blockDownloads": "Block downloads (Preview)", "monitorOnly": "Monitor only (Preview)", "protectDownloads": "Protect downloads (Preview)", "useCustomControls": "Use custom policy..." } } }, "casCustomControlInfo": "Custom policies need to be configured in Cloud App Security portal. This control works instantly for featured apps and can be self onboarded for any app.", "casInfoBubble": "This control works for various cloud apps.", "casPreconfiguredControlInfo": "This control works instantly for featured apps and can be self onboarded for any app.", "cert64DownloadCol": "Download base64 certificate", "cert64Name": "VpnBase64Cert", "certDownloadCol": "Download certificate", "certDurationCol": "Expiry", "certDurationStartCol": "Valid from", "certName": "VpnCert", "ChooseApplications": { "Grid": { "appIdAria": "App ID: {0}" }, "LowerGrid": { "ariaLabel": "List of selected cloud apps" }, "UpperGrid": { "ariaLabel": "List of cloud apps which match the search term" } }, "chooseApplicationsBladeSubtitle": "", "chooseApplicationsBladeTitle": "Choose Applications", "chooseApplicationsCartSubitle": "", "chooseApplicationsCartTitle": "Chosen Applications", "chooseApplicationsEmpty": "No Applications", "chooseApplicationsNone": "None", "chooseApplicationsNoneFound": "We didn't find \"{0}\". Try another name or ID.", "chooseApplicationsPlural": "{0} and {1} more", "chooseApplicationsReAuthEverytimeInfo": "Looking for your app? Some applications cannot be used with \"Require reauthentication - every time\" session control.", "chooseApplicationsRemove": "Remove", "chooseApplicationsReturnedPlural": "{0} applications found", "chooseApplicationsReturnedSingular": "1 application found", "chooseApplicationsSearchBalloon": "Search for an Application by entering its name or ID.", "chooseApplicationsSearchHint": "Search Applications...", "chooseApplicationsSearching": "Searching...", "chooseApplicationsSearchLabel": "Applications", "chooseApplicationsSelect": "Select", "chooseApplicationsSelected": "Selected", "chooseApplicationsSingular": "{0} and 1 more", "ChooseLocations": { "mAMWarning": "All Compliant Network locations\" does not work with \"Require app protection policy\" or \"Require approved client app\" grant controls.", "networkAndLocationsTabAllCloudsInfo": "'Locations' condition is moving! Locations will become the 'Network' assignment. No action required.", "networkAndLocationsTabPublicCloudsInfo": "'Locations' condition is moving! Locations will become the 'Network' assignment with a new Global Secure Access capability of 'All Compliant network locations'. No action required.", "privateLinksInfo": "Private Link for Microsoft Entra ID is best suited for Azure services. Ensure that the principals on which this policy is applied do not have requirement to hit any public services like M365.", "Validation": { "failed": "With \"Selected locations\" you must choose at least one location.", "selector": "Choose at least one location" } }, "chooseLocationsBladeSubtitle": "", "chooseLocationsBladeTitle": "Choose Locations", "chooseLocationsCartSubitle": "", "chooseLocationsCartTitle": "Chosen Locations", "chooseLocationSelectedLocationsLabel": "Selected locations", "chooseLocationsEmpty": "No Locations", "chooseLocationsExcludedSelectorTitle": "Select", "chooseLocationsIncludedSelectorTitle": "Select", "chooseLocationsNone": "None", "chooseLocationsPlural": "{0} and {1} more", "chooseLocationsRemove": "Remove", "chooseLocationsSelect": "Select", "chooseLocationsSelected": "Selected", "chooseLocationsSelectionBladeExcludedSelectorTitle": "Select", "chooseLocationsSelectionBladeIncludedSelectorTitle": "Select", "chooseLocationsSingular": "{0} and 1 more", "chooseLocationTrustedIpsItem": "Multifactor authentication trusted IPs", "chooseNetworkLocationSelectedNetworksLocationsLabel": "Selected networks and locations", "ClaimProvider": { "ControlsList": { "aria": "List of custom controls." } }, "claimProviderAddCommandText": "New custom control", "claimProviderAddNewBladeTitle": "New custom control", "claimProviderDeleteCommand": "Delete", "claimProviderDeleteDescription": "Are you sure you want to delete '{0}'? This action cannot be undone.", "claimProviderDeleteTitle": "Are you sure?", "claimProviderEditInfoText": "Enter the JSON for customized controls given by your claim providers.", "claimProviderNotificationCreateDescription": "Creating custom control named '{0}'", "claimProviderNotificationCreateFailedDescription": "Creating custom control '{0}' failed. Please try again later.", "claimProviderNotificationCreateFailedTitle": "Failed to create custom control", "claimProviderNotificationCreateSuccessDescription": "Created custom control named '{0}'", "claimProviderNotificationCreateSuccessTitle": "Created '{0}'", "claimProviderNotificationCreateTitle": "Creating '{0}'", "claimProviderNotificationDeleteDescription": "Deleting custom control named '{0}'", "claimProviderNotificationDeleteFailedDescription": "Deleting custom control '{0}' failed. Please try again later.", "claimProviderNotificationDeleteFailedTitle": "Failed to delete custom control", "claimProviderNotificationDeleteSuccessDescription": "Deleted custom control named '{0}'", "claimProviderNotificationDeleteSuccessTitle": "Deleted '{0}'", "claimProviderNotificationDeleteTitle": "Deleting '{0}'", "claimProviderNotificationUpdateDescription": "Updating custom control named '{0}'", "claimProviderNotificationUpdateFailedDescription": "Updating custom control '{0}' failed. Please try again later.", "claimProviderNotificationUpdateFailedTitle": "Failed to update custom control", "claimProviderNotificationUpdateSuccessDescription": "Updated custom control named '{0}'", "claimProviderNotificationUpdateSuccessTitle": "Updated '{0}'", "claimProviderNotificationUpdateTitle": "Updating '{0}'", "claimProvidersNone": "No custom controls", "claimProvidersSearchPlaceholder": "Search controls.", "claimProviderValidationAppIdInvalid": "The \"AppId\" value is not valid. Please review and try again.", "claimProviderValidationClientIdMissing": "The data is missing a \"ClientId\" value. Please review and try again.", "claimProviderValidationControlClaimsRequestedMissing": "The \"Control\" is missing a \"ClaimsRequested\" value. Please review and try again.", "claimProviderValidationControlClaimsRequestedTypeMissing": "The \"ClaimsRequested\" item is missing a \"Type\" value. Please review and try again.", "claimProviderValidationControlIdAlreadyExists": "The \"Control\" \"Id\" value already exists. Please review and try again.", "claimProviderValidationControlIdMissing": "The \"Control\" is missing an \"Id\" value. Please review and try again.", "claimProviderValidationControlIdReferencedInExistingPolicy": "The \"Control\" \"Id\" value cannot be removed because it is referenced in an existing policy. Please remove it from the policy first.", "claimProviderValidationControlIdTooManyControls": "The \"Control\" property has too many controls. Please review and try again.", "claimProviderValidationControlIdValueReserved": "The \"Control\" \"Id\" value is a reserved keyword, please use a different id.", "claimProviderValidationControlNameAlreadyExists": "The \"Control\" \"Name\" value already exists. Please review and try again.", "claimProviderValidationControlNameMissing": "The \"Control\" is missing a \"Name\" value. Please review and try again.", "claimProviderValidationControlsMissing": "The data is missing a \"Controls\" value. Please review and try again.", "claimProviderValidationDiscoveryUrlAbsolute": "The Discovery URL is missing the scheme (https). Please review and try again.", "claimProviderValidationDiscoveryUrlMalformed": "The \"DiscoveryUrl\" is malformed. Please review and try again.", "claimProviderValidationDiscoveryUrlMissing": "The data is missing a \"DiscoveryUrl\" value. Please review and try again.", "claimProviderValidationInvalid": "There data provided is not valid. Please review and try again.", "claimProviderValidationInvalidJsonDefinition": "Unable to save the custom control. Review the JSON text and try again.", "claimProviderValidationNameAlreadyExists": "The \"Name\" value already exists. Please review and try again.", "claimProviderValidationNameMissing": "The data is missing a \"Name\" value. Please review and try again.", "claimProviderValidationUnknown": "There was an unknown error while validating the data provided. Please review and try again.", "classicPoilcyFilterTitle": "Show", "classicPolicyAllPlatforms": "All Platforms", "classicPolicyClientAppBrowserAndNative": "Browser, mobile apps and desktop clients", "classicPolicyCloudAppTitle": "Cloud application", "classicPolicyControlAllow": "Allow", "classicPolicyControlBlock": "Block", "classicPolicyControlBlockWhenNotAtWork": "Block access when not at work", "classicPolicyControlRequireCompliantDevice": "Require compliant device", "classicPolicyControlRequireDomainJoinedDevice": "Require domain joined device", "classicPolicyControlRequireMfa": "Require multifactor authentication", "classicPolicyControlRequireMfaWhenNotAtWork": "Require multifactor authentication when not at work", "classicPolicyDeleteCommand": "Delete", "classicPolicyDeleteFailTitle": "Failed to delete classic policy", "classicPolicyDeleteInProgressTitle": "Deleting classic policy", "classicPolicyDeleteSuccessTitle": "Classic policy deleted", "classicPolicyDetailBladeTitle": "Details", "classicPolicyDisableCommand": "Disable", "classicPolicyDisableConfirmation": "Are you sure you want to disable '{0}'? This action cannot be undone.", "classicPolicyDisableFailDescription": "Failed to disable '{0}'", "classicPolicyDisableFailTitle": "Failed to disable classic policy", "classicPolicyDisableInProgressDescription": "Disabling '{0}'", "classicPolicyDisableInProgressTitle": "Disabling classic policy", "classicPolicyDisableSuccessDescription": "Successfully disabled '{0}'", "classicPolicyDisableSuccessTitle": "Classic policy disabled", "classicPolicyEasSupportedPlatforms": "Exchange ActiveSync supported platforms", "classicPolicyEasUnsupportedPlatforms": "Exchange ActiveSync unsupported platforms", "classicPolicyExcludedPlatformsTitle": "Excluded device platforms", "classicPolicyFilterAll": "All policies", "classicPolicyFilterDisabled": "Disabled policies", "classicPolicyFilterEnabled": "Enabled policies", "classicPolicyIncludedPlatformsTitle": "Included device platforms", "classicPolicyIncludeExcludeMembersDescription": "By excluding groups, you can perform phased migration of policies.", "classicPolicyIncludeExcludeMembersTitle": "Include/exclude groups", "classicPolicyManualMigrationMessage": "This policy needs to be migrated manually.", "classicPolicyMigrateCommand": "Migrate", "classicPolicyMigrateConfirmation": "Are you sure you want to migrate '{0}'? This policy can only be migrated once.", "classicPolicyMigratedSuccessDescription": "This classic policy can now be managed under Polices.", "classicPolicyMigratedSuccessDescriptionMultiple": "This classic policy is migrated as {0} new policies. New policies can be managed under Policies.", "classicPolicyMigrateFailDescription": "Failed to migrate '{0}'", "classicPolicyMigrateFailTitle": "Failed to migrate classic policy", "classicPolicyMigrateInProgressDescription": "Migrating '{0}'", "classicPolicyMigrateInProgressTitle": "Migrating classic policy", "classicPolicyMigrateRecommendText": "Recommendation: Migrate to the new Azure portal policies.", "classicPolicyMigrateSuccessTitle": "Classic policy migrated successfully", "classicPolicyNoEditPermissionMsg": "You don't have permission to edit this policy. Only global administrators and security administrators can edit the policy. Click here for more information.", "classicPolicySaveFailDescription": "Failed to save '{0}'", "classicPolicySaveFailTitle": "Failed to save classic policy", "classicPolicySaveInProgressDescription": "Saving '{0}'", "classicPolicySaveInProgressTitle": "Saving classic policy", "classicPolicySaveSuccessDescription": "Successfully saved '{0}'", "classicPolicySaveSuccessTitle": "Classic policy saved", "ClientApp": { "Clients": { "Validation": { "failed": "You must select at least one of the following clients" } } }, "clientAppBladeLegacyInfoBanner": "Legacy auth is currently not supported", "clientAppBladeLegacyUpsellBanner": "Block unsupported client apps (Preview)", "clientAppBladeTitle": "Client apps", "clientAppDescription": "Select the client apps this policy will apply to", "clientAppExchangeActiveSync": "Exchange ActiveSync", "clientAppExchangeActiveSyncCheckboxAriaLabel": "Group, select the client apps this policy will apply to. Legacy authentication clients, Exchange ActiveSync clients.", "clientAppExchangeWarning": "Exchange ActiveSync currently does not support all other conditions", "clientAppLearnMore": "Control user access to target specific client applications not using modern authentication.", "clientAppLearnMoreAriaLabel": "Learn more about client apps in Conditional Access conditions.", "clientAppLegacyHeader": "Legacy authentication clients", "clientAppMAMInvalidAppError": "MAM policy for Windows client platform can only apply to Browser and Exchange ActiveSync clients.", "clientAppMobileDesktop": "Mobile apps and desktop clients", "clientAppMobileDesktopCheckboxAriaLabel": "Group, select the client apps this policy will apply to. Modern authentication clients, mobile apps and desktop clients.", "clientAppModernHeader": "Modern authentication clients", "clientAppOnlySupportedPlatforms": "Apply policy only to supported platforms", "clientAppOtherCheckboxAriaLabel": "Group, select the client apps this policy will apply to. Legacy authentication clients, other clients.", "clientAppSelectSpecificClientApps": "Select client apps", "clientAppsInfoBalloonAriaLabelAccessibility": "Additional information about client apps", "clientAppsSelectedLabel": "{0} included", "clientAppWebBrowser": "Browser", "clientAppWebBrowserCheckboxAriaLabel": "Group, select the client apps this policy will apply to. Modern authentication clients, browser.", "ClientConditionsInfo": { "browserAndModern": "This policy only applies to browser and modern authentication apps. To apply the policy to all client apps, enable the client app condition and select all the client apps.", "classicExperience": "Since this policy was created, the default client apps configuration has been updated.", "legacyAuth": "When not configured, policies now apply to all client apps, including modern and legacy auth." }, "clientTypeBrowser": "Browser", "clientTypeEas": "Exchange ActiveSync clients", "clientTypeEasInfo": "Exchange ActiveSync clients that use legacy authentication only.", "clientTypeModernAuth": "Modern authentication clients", "clientTypeOtherClients": "Other clients", "clientTypeOtherClientsInfo": "This includes older office clients and other mail protocols(POP, IMAP, SMTP, etc). [Learn more][1]\n[1]: https://aka.ms/caclientapps\n", "CloudAppFilterBlade": { "AssignmentFilter": { "header": "Attribute", "placeholder": "Choose an attribute" }, "Configure": { "infoBalloon": "Configure custom security attributes you want the policy to apply to." }, "gridHeader": "Using custom security attributes you can use the rule builder or rule syntax text box to create or edit the filter rules. In the preview, only attributes of type String are supported. Attributes of type Integer or Boolean will not be shown.", "learnMoreAria": "More information about using the rule builder and syntax text box.", "noAttributes": "There are no custom attributes available to filter on. You will need to configure some attributes to employ this filter.", "NoPermissions": { "learnMoreAria": "More about custom security attribute permissions.", "message": "You do not have the permissions needed to use custom security attributes." }, "title": "Edit filter" }, "CloudappsSelectionBlade": { "AgenticResources": { "allAgenticResources": "All agent resources (Preview)", "allAgenticResourcesExcLower": "all agent resources (Preview) excluded", "allAgenticResourcesExcLowerGA": "all agent resources excluded", "allAgenticResourcesExcluded": "All agent resources (Preview) excluded", "allAgenticResourcesExcludedGA": "All agent resources excluded", "allAgenticResourcesGA": "All agent resources", "allAgenticResourcesIncluded": "All agent resources (Preview)", "allAgenticResourcesIncludedGA": "All agent resources" }, "AllInternetResources": { "excludedWithGSA": "All internet resources with Global Secure Access excluded", "excludedWithGSALower": "all internet resources with Global Secure Access excluded", "withGSA": "All internet resources with Global Secure Access" }, "Excluded": { "gridAria": "List of excluded cloud apps" }, "Filter": { "configured": "Configured", "descriptionAgents": "Apply policy to agent identities based on custom security attributes pre-assigned to them.", "descriptionAgentUsers": "Apply policy to agent users based on custom security attributes pre-assigned to them.", "label": "Edit filter", "resourceDescription": "Select resources based on custom security attributes.", "sPDescription": "Select service principals based on custom security attributes.", "titleAgents": "Select agent identities based on attributes", "titleAgentsShort": "Select based on attributes", "titleAgentUsers": "Select agent users based on attributes", "titleAgentUsersShort": "Select based on attributes", "titleResource": "Select resources based on attributes", "titleSP": "Select service principals based on attributes", "with": "{0} with {1}" }, "Included": { "gridAria": "List of included cloud apps" }, "Validation": { "authContext": "With \"authentication context\" you must configure at least one sub-item.", "networkAccess": "With \"Global Secure Access\" you must configure at least one traffic profile.", "selectApps": "\"{0}\" must be configured", "selector": "Select at least one app.", "userActions": "With \"User actions\" you must configure at least one sub-item." } }, "cloudappsSelectionBladeAllCloudapps": "All cloud apps", "cloudAppsSelectionBladeAllMicrosoftApps": "All Microsoft apps", "cloudappsSelectionBladeAllResources": "All resources (formerly 'All cloud apps')", "cloudappsSelectionBladeExcludeDescription": "Select the cloud apps to exempt from the policy", "cloudappsSelectionBladeExcludedSelectorTitle": "Select excluded cloud apps", "cloudappsSelectionBladeIncludeDescription": "Select the cloud apps this policy will apply to", "cloudappsSelectionBladeIncludedSelectorTitle": "Select", "cloudappsSelectionBladeSelectedCloudapps": "Select apps", "cloudappsSelectionBladeSelectedResources": "Select resources", "cloudappsSelectionDescription": "Select specific resources this policy targets.", "cloudappsSelectionTitle": "Select specific resources", "cloudappsSelectorInfoBallonText": "Services which the user accesses to do work. For example, 'Salesforce'", "cloudappsSelectorNone": "No cloud apps, actions, or authentication context selected", "cloudappsSelectorPluralExcluded": "{0} apps excluded", "cloudappsSelectorPluralIncluded": "{0} apps included", "cloudappsSelectorRequired": "Cloud apps, actions, or authentication context selection required", "cloudappsSelectorSingularExcluded": "1 app excluded", "cloudappsSelectorSingularIncluded": "1 app included", "cloudappsSelectorUserPlural": "{0} apps", "cloudappsSelectorUserSingular": "1 app", "CloudAppsUserActions": { "any": "Any cloud app or action", "infoBalloon": "Cloud app or user action you want to test. For example, 'SharePoint Online'", "learnMore": "Control access based on all or specific cloud apps or actions.", "learnMoreAllClouds": "Control access based on all or specific apps, actions, or authentication context.", "learnMoreAriaLabel": "Learn more about cloud apps, actions, and authentication context.", "learnMoreB2C": "Control access based on all or specific cloud apps.", "learnMoreNetworkAccess": "Control access based on all or specific network access traffic, cloud apps or actions.", "learnMorePublicClouds": "Control access based on all or specific apps, internet resources, actions, or authentication context.", "learnMorePublicCloudsAgents": "Control access based on all or specific apps, agents, internet resources, actions, or authentication context.", "title": "Cloud apps or actions" }, "computerUsingAgentInfoBalloonAriaLabelAccessibility": "Additional information about computer using agent", "conditionalAccessBladeTitle": "Conditional Access", "conditionLabelMulti": "{0} conditions selected", "conditionLabelOne": "1 condition selected", "Conditions": { "DevicePlatforms": { "headerDescription": "Apply policy to selected device platforms.", "headerLearnMoreAriaLabel": "Learn more about supported device platforms in Conditional Access." }, "Locations": { "agentNetworkHeaderDescription": "Control agent access based on their network or physical location.", "headerDescription": "Control user access based on their physical location.", "headerLearnMoreAriaLabel": "Learn more about using the location condition in a Conditional Access policy.", "networkHeaderDescription": "Control user access based on their network or physical location." } }, "conditionsInfoBalloonAriaLabelAccessibility": "Additional information about condition selection", "conditionsNotSelectedLabel": "Not configured", "conditionsReqMfaReauthSet": "Some options are not available due to the \"Require multifactor authentication\" grant and \"sign-in frequency every time\" session control currently being selected", "conditionsReqPwSet": "Some options are not available due to the \"Require password change\" grant currently being selected.", "configureCasText": "Configure Cloud App Security", "configureCustomControlsText": "Configure custom policy", "controlLabelMulti": "{0} controls selected", "controlLabelOne": "1 control selected", "controlsBlockAccessInfoBubble": "ControlsBlockAccessInfoBubble", "controlsDeviceComplianceAriaLabel": "Learn more about requiring compliant devices.", "controlsDeviceComplianceInfoBubble": "Device must be Intune compliant. If the device is non-compliant, the user will be prompted to bring the device under compliance.", "controlsDeviceComplianceInfoBubbleAgentUser": "Device must be Intune compliant. If the device is non-compliant, the agent will be blocked until the device is brought to compliance.", "controlsDomainJoinedAriaLabel": "Learn more about requiring Microsoft Entra hybrid joined devices.", "controlsDomainJoinedInfoBubble": "Devices must be Microsoft Entra hybrid joined.", "controlsMamAriaLabel": "Learn more about requiring approved client applications.", "controlsMamInfoBubble": "Device must use these approved client applications.", "controlsMfaInfoBubble": "User must complete additional security requirements like phone call, text", "controlsOrAndInfoBubble": "ControlsOrAndInfoBubble", "controlsRequireCompliantAppAriaLabel": "Learn more about requiring policy protected apps.", "controlsRequireCompliantAppInfoBubble": "Device must use policy protected apps.", "controlsRequirePasswordResetAriaLabel": "Learn more about requiring a password change.", "controlsRequirePasswordResetInfoBubble": "Users detected with risk will have all their sessions revoked after they complete a secure password change. If you have users using passwordless authentication methods, use 'Require risk remediation'.", "controlValidatorText": "Please select at least one control", "countriesRadiobuttonInfoBalloonContent": "The country/region a sign-in is coming from is determined by the user's IP address.", "createNewVpnCert": "New certificate", "customRoleLabel": "Custom roles (not supported)", "dateRangeTypeLabel": "Date range", "daysOfWeekPlaceholderText": "Filter days of the week", "daysOfWeekTypeLabel": "Days of the week", "deletePolicyNoLicenseText": "You can delete this policy now. Once deleted you will not be able to recreate it until you have the required licenses.", "descriptionContentForControlsAndOr": "For multiple controls", "detectLockoutRisk": "Detect lockout risk", "deviceFilterInformationalLearnMore": "Learn more", "deviceFilterInformationalResponse": "Microsoft recommends using at least one system-defined or admin-configured device attribute when creating filter rules.", "devicePlatform": "Device platform", "devicePlatformInclude": "{0} included", "devicePlatformIncludeExclude": "{0} and {1} excluded", "devicePlatformNoSelectionError": "Select device platforms requires one sub-item to be selected.", "devicePlatformsGroupAndroidCheckboxAriaLabel": "Device platforms group Android", "devicePlatformsGroupIosCheckboxAriaLabel": "Device platforms group iOS", "devicePlatformsGroupLinuxCheckboxAriaLabel": "Device platforms group Linux", "devicePlatformsGroupMacOsCheckboxAriaLabel": "Device platforms group macOS", "devicePlatformsGroupWindowsCheckboxAriaLabel": "Device platforms group Windows", "devicePlatformsGroupWindowsPhoneCheckboxAriaLabel": "Device platforms group Windows Phone", "devicePlatformsInfoBalloonAriaLabelAccessibility": "Additional information about device platforms", "devicePlatformsNone": "None", "devicePlatformWinMamMdmError": "MAM and MDM policies cannot both be applied to Windows clients.", "deviceSelectionBladeExcludeDescription": "Select the platforms to exempt from the policy", "deviceSelectionBladeIncludeDescription": "Select the device platforms to include in this policy", "DeviceState": { "LearnMore": { "ariaLabel": "Learn more about device state (deprecated) in Conditional Access conditions.", "message": "Control user access when the device the user is signing-in from is not \"Microsoft Entra hybrid joined\" or \"marked as compliant\".\n This has been deprecated. Use '{1}' instead." } }, "deviceStateAll": "All device state", "deviceStateCompliant": "Device marked as compliant", "deviceStateCompliantInfoContent": "Devices that are Intune compliant will be excluded from the evaluation of this policy, so for example if the policy blocks access it will block all devices except devices that are Intune compliant.", "deviceStateConditionConfigureInfoContent": "Configure policy based on device state", "deviceStateConditionSelectorInfoContent": "Whether the device the user is signing in from is 'Microsoft Entra hybrid joined' or 'marked as compliant'.\n This has been deprecated. Use '{1}' instead.", "deviceStateConditionSelectorLabel": "Device state (deprecated)", "deviceStateDeprecatedTextMessage": "'{0}' has been deprecated. Use '{1}' instead.", "deviceStateDomainJoined": "Device Microsoft Entra hybrid joined", "deviceStateDomainJoinedInfoContent": "Devices that are Microsoft Entra hybrid joined will be excluded from the evaluation of this policy, so for example if the policy blocks access it will block all devices except devices that are Microsoft Entra hybrid joined.", "deviceStateDomainJoinedInfoLinkText": "Learn more.", "deviceStateExcludeDescription": "Select the device state condition used to exclude devices from policy.", "deviceStateIncludeAndExcludeOneLabel": "{0} and exclude {1}", "deviceStateIncludeAndExcludeTwoLabel": "{0} and exclude {1}, {2}", "deviceStateInfoBalloonAriaLabelAccessibility": "Additional information about filter for devices", "directoryRoleInfoContent": "Assign policy to built-in directory roles.", "directoryRolesLabel": "Directory roles", "directoryRolesSearchPlaceholder": "Type to filter result", "discardbutton": "Discard", "dLPBrowserOnlyTextMessage": "Purview Data Loss Prevention condition can be applied to Browser client app only.", "duplicatePolicyName": "{0} COPY", "elevatedRisk": "Elevated", "endDatePickerLabel": "Ends", "endTimePickerLabel": "End time", "enterCountryText": "IP address and Country are evaluated in a pair. Select the Country.", "enterDateTimeText": "Time zone, date and time are evaluated together. Select the date and time.", "enterIpText": "IP address and Country are evaluated in a pair. Input the IP address.", "enterTimeZoneText": "Time zone, date and time are evaluated together. Select the time zone.", "enterUserText": "No user is selected. Select a user.", "Errors": { "notFound": "The policy was not found or has been deleted.", "notFoundDetailed": "The policy \"{0}\" no longer exists. It may have been deleted." }, "evaluationResult": "Evaluation result", "exchangeActiveSyncSelectedLabel": "Exchange ActiveSync", "exchangeActiveSyncSupportedPlatformOnlySelectedLabel": "Exchange ActiveSync with supported platforms only", "excludeAllTrustedLocationSelectorText": "all trusted locations", "featureRequiresP2": "This feature requires Microsoft Entra ID P2 license.", "friday": "Friday", "grantControlInfoBalloonAriaLabelAccessibility": "Additional information about grant controls", "grantControls": "Grant controls", "gridNetworkTrusted": "Trusted", "gridPolicyEnabled": "Enabled", "gridPolicyName": "Policy Name", "gridPolicyState": "State", "groupSelectionBladeExcludeDescription": "Select the groups to exempt from the policy", "groupSelectionBladeExcludedSelectorTitle": "Select excluded groups", "groupSelectionBladeSelect": "Select groups", "groupSelectorInfoBallonText": "Groups in the directory that the policy applies to. For example, 'Pilot group'", "groupsSelectionBladeTitle": "Groups", "GuestsOrExternalUsers": { "allExternalTenantsAriaLabel": "All external Microsoft Entra organizations", "allExternalTenantsLabel": "All", "b2bCollaborationGuestLabel": "B2B collaboration guest users", "b2bCollaborationMemberLabel": "B2B collaboration member users", "b2bDirectConnectUserLabel": "B2B direct connect users", "enumeratedExternalTenantsAriaLabel": "Select external Microsoft Entra organizations", "enumeratedExternalTenantsError": "Please select at least one external tenant", "enumeratedExternalTenantsLabel": "Select", "externalTenantsLabel": "Specify external Microsoft Entra organizations", "externalUserDropdownLabel": "Choose guest or external user types", "externalUsersError": "Select at least one external guest or user type", "externalUsersIncompatibleWithInsiderRiskError": "Insider risk condition is not valid for B2B direct connect users, service provider users and other external users.", "guestOrExternalUsersInfoContent": "Includes B2B Collaboration, B2B direct connect and other types of external users.", "guestOrExternalUsersLabel": "Guest or external users", "internalGuestLabel": "Local guest users", "otherExternalUserLabel": "Other external users", "serviceProviderUsersLabel": "Service provider users" }, "highRisk": "High", "includeAndExcludeAppsTextFormat": "Include: {0}. Exclude: {1}.", "includeAppsTextFormat": "Include: {0}.", "includeUnknownAreasCheckboxInfoBalloonContent": "Unknown areas are IP addresses that can't be mapped to a country/region.", "includeUnknownAreasCheckboxLabel": "Include unknown areas", "infoCommandLabel": "Info", "injectedPoliciesBlockDCFWarningInfobox": "This policy blocks device code flow unilaterally, which can be leveraged as part of a phishing attack.", "injectedPoliciesBlockLegacyWarningInfobox": "This policy blocks legacy authentication protocols, which cannot enforce multi-factor authentication. Disabling legacy authentication reduces compromises by 67%.", "injectedPoliciesMFAWarningInfobox": "This policy provides multi-factor authentication which can prevent 99.22% of account compromise.", "injectedPoliciesWarningInfobox": "99.22% of account compromise could be stopped by using multi-factor authentication, provided by this policy.", "insiderRiskInfoBalloonAriaLabelAccessibility": "Additional information about insider risk levels", "invalidCertDuration": "Invalid cert duration", "invalidIpAddress": "Value must be a valid IP address", "invalidReAuthSignInRiskOptionSelected": "The \"sign-in frequency every time\" session control does not allow the \"no risk\" selection in the \"sign-in risk\" condition control.", "invalidUriErrorMsg": "Please enter a valid Uri. For example,'uri:contoso.com:acr' ", "iosDisplayName": "iOS", "linuxDisplayName": "Linux", "loadAll": "Load all", "loading": "Loading...", "locationConfigureNamedLocationsText": "Configure all trusted locations", "locationNameTooLongError": "Location name is too long. Maximum is 256 characters", "locationsAllLocationsLabel": "Any location", "locationsAllNetworkLocationsLabel": "Any network or location", "locationsAllPrivateLinksLabel": "All Private Links in my tenant", "locationSelectionBladeExcludeDescription": "Select the locations to exempt from the policy", "locationSelectionBladeIncludeDescription": "Select the locations to include in this policy", "locationsIncludeExcludeLabel": "{0} and exclude all trusted IPs", "locationsRowDeletedSuccessfully": "{0} row deleted successfully", "locationsSelectedPrivateLinksLabel": "Selected Private Links", "lowRisk": "Low", "macOsDisplayName": "macOS", "managePoliciesLicenseText": "To manage Conditional Access policies, your organization needs Microsoft Entra ID P1 or P2.", "manageSecurityDefaultsAriaLabel": "Manage security defaults settings.", "markAsTrustedCheckboxInfoBalloonContent": "Signing in from a trusted location lowers a user's sign-in risk. Only mark this location as trusted if you know the IP ranges entered are established and credible in your organization.", "markAsTrustedCheckboxLabel": "Mark as trusted location", "mediumRisk": "Medium", "memberSelectionCommandRemove": "Remove", "menuItemBaselineScopes": "Baseline scope settings (Preview)", "menuItemClaimProviderControls": "Custom controls (Preview)", "menuItemClassicPolicies": "Classic policies", "menuItemDeletedPolicies": "Deleted Policies", "menuItemInsightsAndReporting": "Insights and reporting", "menuItemManage": "Manage", "menuItemNamedLocationsPreview": "Named locations (Preview)", "menuItemNamedNetworks": "Named locations", "menuItemPhasedRollout": "Phased rollout", "menuItemPolicies": "Policies", "menuItemPoliciesV2": "Policies V2 (Preview)", "menuItemPolicySettings": "Settings (Preview)", "menuItemTermsOfUse": "Terms of use", "microsoftAdminPortals": "Microsoft Admin Portals", "microsoftAdminPortalsInfoBox": "The admin portals include Microsoft 365 admin center, Exchange admin center, Azure portal, Microsoft Entra admin center, and others.", "MicrosoftManagedPolicies": { "alertBanner": "Microsoft-managed policies will be enabled no sooner than {0} days after creation unless you take action. We recommend that you review these policies and take the recommended actions.", "alertBannerV2": "Microsoft-managed policies in report-only state will be automatically turned on with advance email and {0}M365 message center{1} notifications. We recommend that you review these policies and recommended actions.", "bsmRecActionsGlobal2": "When you are ready to enable, switch its state to 'on'. If you do not want to enforce this policy for your organization, switch its state to 'off'.", "learnMoreLinkAriaLabel": "Learn more about Microsoft-managed policies.", "m365MessageCenterLinkAriaLabel": "M365 message center", "policySummaryBlockDCF": "This policy unilaterally blocks device code flow usage across all resources and all users. As a Microsoft-managed policy, only certain properties are editable.", "policySummaryBlockHighRiskAgents": "This policy blocks any sign-in attempt made by a high-risk agent identity", "policySummaryBlockHighRiskUsers": "This policy blocks any sign-in attempt made by a high-risk user", "policySummaryBlockLegacyAuth": "This policy blocks any sign-in attempt using legacy authentication and legacy authentication protocols from accessing applications. Legacy authentication refers to authentication requests made by: Clients that don't use modern authentication (e.g., Office 2010 clients). Clients that use older mail protocols such as IMAP, SMTP, or POP3.", "policySummaryMfa": "This policy requires some administrator roles to perform multifactor authentication when accessing Microsoft admin portals. Currently, the policy is in '{0}' mode. As a Microsoft-managed policy, only certain properties are editable.", "policySummaryMfaForAllUsers": "This policy requires all users to perform multifactor authentication when accessing any resources. Currently, the policy is in '{0}' mode. As a Microsoft-managed policy, only certain properties are editable.", "policySummaryMfaForGuestAccess": "This policy requires all guest and external users to perform multifactor authentication when accessing your organization's resources. Requiring multifactor authentication for guests reduces the risk of compromised external accounts gaining access to your data and applications.", "policySummaryPerUserMfaV2": "This policy covers per-user multifactor authentication enforced users with recent sign-ins and requires them to perform MFA while accessing cloud applications. There will be no change to the end user experience as a result of this policy and your organization is sufficiently licensed to use this policy. Currently, the policy is in '{0}' mode. As a Microsoft-managed policy, only certain properties are editable.", "policySummaryPerUserMfaViaGroup": "This policy covers per-user multifactor authentication enforced users with recent sign-ins and requires them to perform MFA while accessing cloud applications. There will be no change to the end user experience as a result of this policy and your organization is sufficiently licensed to use this policy. We'll assign eligible users into a new security group named 'Conditional Access: Per-user multifactor authentication users (a4ea6c0f-b8fb-4d29-91f1-9f8cf0601e97)'. Currently, the policy is in '{0}' mode. As a Microsoft-managed policy, only certain properties are editable.", "policySummaryPhishingResistantMfa": "Accounts that are assigned privileged administrative roles are frequent targets of attackers. Requiring phishing-resistant multifactor authentication (MFA) on those accounts is an easy way to reduce the risk of those accounts being compromised.", "policySummarySignInRisk": "High sign-in risk represents a high probability that the given authentication request isn't authorized by the identity owner. This policy incorporates high sign-in risk detections from Entra ID Protection in real-time to trigger multifactor authentication and reauthentication to prevent identity compromise. If users aren't registered for MFA, this policy will block their risky sign-ins to prevent MFA registration by an unauthorized actor. As a Microsoft-managed policy, only certain properties are editable.", "policySummarySignInRiskViaGroup": "High sign-in risk represents a high probability that the given authentication request isn't authorized by the identity owner. This policy incorporates high sign-in risk detections from Entra ID Protection in real-time to trigger multifactor authentication and reauthentication to prevent identity compromise. We'll assign eligible users into a new security group named 'Conditional Access: Risky sign-in multifactor authentication (a4ea6c0f-b8fb-4d29-91f1-9f8cf0601e98)'. As a Microsoft-managed policy, only certain properties are editable.", "policySummaryUserRiskRemediation": "This policy requires high-risk users to perform risk remediation, such as a secure password change and/or session revocation, before they can access resources", "recActionsGlobal1": "Review the policy and its benefits.", "recActionsGlobal2": "When you are ready to enable, switch its state to 'on'. If you do not want to enforce this policy for your organization, switch its state to 'off'. If you leave the policy in report-only mode, we will enable it for you.", "recActionsMfa1": "Exclude one or more break glass accounts from the policy.", "recActionsMfa2": "To prevent users from being locked out, verify that all users covered by this policy have at least one enabled authentication methods.", "recActionsMfa3": "Exclude your guest users if you're targeting them with a guest user specific policy.", "recActionsPerUserMfaV2": "After enabling this Conditional Access policy, it's recommended to disable per-user multifactor authentication for in-scope users.", "recActionsPerUserMfaViaGroup1": "When you are ready to enable, switch its state to 'on'. If you do not want to enforce this policy for your organization, switch its state to 'off'. If you leave the policy in report-only mode, we will enable it for you. Don't remove the user group for this policy to function.", "recommendedActions": "Recommended actions", "recommendedActionsIntro": "Before enabling this policy, or before Microsoft enables it automatically no sooner than {0} days after policy creation", "recommendedActionsIntroShort": "Before enabling this policy", "securityDefaultsBasedAdminMfaMMPolicySummary": "Require multifactor authentication for privileged administrative accounts to reduce risk of compromise. This policy will target the same roles as security defaults.", "securityDefaultsBasedAllUserMfaMMPolicySummary": "Require multifactor authentication for all user accounts to reduce risk of compromise.", "securityDefaultsBasedAzureManagementMMPolicySummary": "Require multifactor authentication to protect privileged access to Azure management.", "securityDefaultsBasedLegacyBlockMMPolicySummary": "Block legacy authentication endpoints that can be used to bypass multifactor authentication.", "securityDefaultsBasedMMPolicyRecommendationOverview": "Microsoft recommends leaving this policy enabled. If you need to make modifications beyond what is allowed in a Microsoft-managed policy, you can clone this policy and make those edits. Keep in mind that doing so will prevent Microsoft from improving the security posture for your organization through this policy.", "signInRiskActions2": "While we have scoped this policy to include users who are already enabled for multifactor authentication, we recommend you verify this using the report below as an extra precaution to prevent users from being locked out.", "signInRiskActionsViaGroup1": "This policy relies on its corresponding security group to function. We recommend you keep the group even if you don't intend to use the policy now.", "summary": "Summary" }, "minorRisk": "Minor", "mmpTurnOffAttackWarningWarningInfobox": "If you turn off this policy, your accounts will be susceptible to this attack.", "mmpTurnOffRiskWarningWarningInfobox": "If you turn off this policy, your accounts will be at risk for compromise.", "moderateRisk": "Moderate", "monday": "Monday", "MsGraphErrors": { "messageFromServer": "Message from server: {0}" }, "NamedLocation": { "Form": { "CountryLookup": { "ariaLabel": "Country lookup method", "gps": "Determine location by GPS coordinates", "info": "When the location condition of a Conditional Access policy is configured, users will be prompted by the Authenticator app to share their GPS location. ", "ip": "Determine location by IP address (IPv4 and IPv6)" }, "enter": "Enter a new IPv4 or IPv6 range", "example": "ex: 40.77.182.32/27 or 2a01:111::/32", "Header": { "new": "New location ({0})", "update": "Update location ({0})" }, "Include": { "infoBalloon": "Unknown countries/regions are IP addresses that are not associated with a specific country or region.", "infoBalloonCont": "\n \nThis includes:\n* IPv6 addresses\n* IPv4 addresses without a direct mapping\n ", "label": "Include unknown countries/regions" }, "Name": { "empty": "Name cannot be empty", "placeholder": "Name this location" }, "Search": { "countries": "Search countries", "names": "Search names", "privateLinks": "Search Private Links" }, "Trusted": { "label": "Mark as trusted location" } }, "Grid": { "aria": "List of countries" }, "iPRangeInvalidError": "Value must be a valid IPv4 or IPv6 range.", "iPRangeLinkOrSiteLocalError": "IP network detected as a link local or site local address.", "iPRangeOctetError": "IP network must not start with 0 or 255.", "iPRangePrefixError": "IP network prefix must be from /{0} to /{1}.", "iPRangePrivateError": "IP network detected as a private address.", "iPv6Announcement": "Microsoft Entra ID now supports IPv6! Update your IP ranges locations today with IPv6 ranges. ", "NetworkAccess": { "headerDescription": "Configure Network Access locations of my tenant.", "headerLearnMoreAriaLabel": "Learn more about Network Access locations.", "helpDescription": "Entra Network Access is disabled for your tenant.", "learnMoreAriaLabel": "Learn more about Network Access.", "subtitle": "Named location", "title": "All Network Access Location" }, "Notification": { "Create": { "Failed": { "description": "Failure in creating new location ({0})", "title": "Creation has failed" }, "InProgress": { "description": "Creating new location ({0})", "title": "Creation in progress" }, "Success": { "description": "Success in creating new location ({0})", "title": "Creation has succeeded" } }, "Delete": { "Failed": { "description": "Failure in deleting location ({0})", "title": "Deletion has failed" }, "InProgress": { "description": "Deleting location ({0})", "title": "Deletion in progress" }, "Success": { "description": "Success in deleting location ({0})", "title": "Deletion has succeeded" } }, "Update": { "Failed": { "description": "Failure in updating location ({0})", "title": "Updating has failed" }, "InProgress": { "description": "Updating location ({0})", "title": "Updating in progress" }, "Success": { "description": "Success in updating location ({0})", "title": "Updating has succeeded" } } }, "PrivateLink": { "headerDescription": "Create a new named location containing Private Links for Microsoft Entra ID.", "headerLearnMoreAriaLabel": "Learn more about Private Link named locations." }, "PrivateLinks": { "grid": "List of Private Links" }, "reactNamedLocationsAnnouncement": "This view will soon be replaced by the enhanced named locations list experience. Click here or use Preview features to enable the enhanced named locations list experience and refresh the tab. \n", "Type": { "countries": "Countries", "privateLinks": "Private Links", "serviceTags": "Service tags (Preview)", "title": "Location type" } }, "namedLocationCountryInfoBanner": "As of May 2023, both IPv4 and IPv6 addresses are mapped to countries/regions.", "namedLocationsHelpDescription": "Named locations are used by Microsoft Entra security reports to reduce false positives and Microsoft Entra Conditional Access policies.", "namedLocationsLearnMoreAriaLabel": "Learn more about named locations.", "namedLocationTypeCountry": "Countries/Regions", "namedLocationTypeLabel": "Define the location using:", "namedLocationUpsellBanner": "This view has been deprecated. Go to the new and improved 'Named locations' view.", "NamedNetwork": { "List": { "gridAria": "List of named locations" } }, "namedNetworkAddIpRanges": "Add a new IP range (ex: 40.77.182.32/27)", "namedNetworkCountryNeeded": "You need to select at least one country", "namedNetworkDeleteCommand": "Delete", "namedNetworkDeleteDescription": "Are you sure you want to delete '{0}'? This action cannot be undone.", "namedNetworkDeleteTitle": "Are you sure?", "namednetworkExceedingSizeErrorBladeTitle": "Error details", "namednetworkExceedingSizeErrorDetailText": "Click here for more details.", "namednetworkExceedingSizeErrorMessage": "You have exceeded the maximum allowed storage for named locations. Try again with a shorter list. Click here to view more details.", "namedNetworkInvalidRange": "Value must be a valid IP range.", "namedNetworkIpRangeNeeded": "You need at least one valid IP range", "namedNetworkIpRangesDescriptionContent": "Configure your organization's IP ranges", "namedNetworkIpRangesTab": "IP ranges", "namedNetworkListAdd": "New location", "namedNetworkListConfigureTrustedIps": "Configure multifactor authentication trusted IPs", "namedNetworkNameDescription": "Example: 'Redmond office'", "namedNetworkNameInvalid": "The supplied name is invalid.", "namedNetworkNameRequired": "You must supply a name for this location.", "namedNetworkNoIpRanges": "No IP ranges", "namedNetworkNotificationCreateFailedDescription": "Creating location '{0}' failed. Please try again later.", "namedNetworkNotificationDeleteDescription": "Deleting location named '{0}'", "namedNetworkNotificationDeleteFailedDescription": "Deleting location '{0}' failed. Please try again later.", "namedNetworkNotificationDeleteFailedTitle": "Failed to Delete location", "namedNetworkNotificationDeleteSuccessDescription": "Deleted location named '{0}'", "namedNetworkNotificationDeleteSuccessTitle": "Deleted '{0}'", "namedNetworkNotificationDeleteTitle": "Deleting '{0}'", "namedNetworkNotificationUpdateFailedDescription": "Updating location '{0}' failed. Please try again later.", "namedNetworksAdd": "New named location", "namedNetworkSearchPlaceholder": "Search locations.", "namedNetworksExcludeLabel": "{0} and {1} excluded", "namedNetworksIncludeLabel": "{0} included", "namedNetworksNone": "No named locations found.", "namedNetworksTitle": "Configure locations", "namedNetworkUploadFailedDescription": "There was an error parsing the supplied file. Please make sure to upload a plain-text file with each line in the CIDR format.", "namedNetworkUploadFailedTitle": "Failed to parse '{0}'", "namedNetworkUploadInProgressDescription": "Attempting to parse valid CIDR values from '{0}'.", "namedNetworkUploadInProgressTitle": "Parsing '{0}'", "namedNetworkUploadInvalidDescription": "'{0}' is either too large or in an invalid format.", "namedNetworkUploadInvalidTitle": "'{0}' Invalid", "namedNetworkUploadSuccessDescription": "{0} lines analyzed. {1} in a bad format. {2} skipped.", "namedNetworkUploadSuccessTitle": "Finished parsing '{0}'", "nameLabel": "Name", "needMfaOrAuthStrengthSpecificApps": "\"The \"sign-in frequency every time\" session control requires the \"Require multifactor authentication\" or \"Require authentication strength\" grant control when specifically-supported apps are selected", "needMfaOrAuthStrengthSpecificAppsRefresh": "\"The \"sign-in frequency every time\" session control requires the \"Require multifactor authentication\" or \"Require authentication strength\" grant control when Intune Enrollment is selected", "needMfaSpecificApps": "\"The \"sign-in frequency every time\" session control requires the \"Require multifactor authentication\" grant control when specifically-supported apps are selected", "needMfaSpecificAppsRefresh": "\"The \"sign-in frequency every time\" session control requires the \"Require multifactor authentication\" grant control when Intune Enrollment selected", "NetworkAccess": { "Included": { "none": "No target resources selected", "plural": "{0} network traffic profiles selected", "singular": "1 network traffic profile selected" }, "internetOptionText": "Internet traffic", "m365OptionText": "Microsoft 365 traffic", "privateOptionText": "Private traffic", "selectTrafficProfilesLabel": "Select the traffic profiles this policy applies to", "targetResourcesBalloonContext": "Target resources", "targetResourcesBalloonContextAllClouds": "Resources that the policy applies to, including apps, actions, or authentication context", "targetResourcesBalloonContextPublicClouds": "Resources that the policy applies to, including apps, internet resources, actions, or authentication context", "targetResourcesSelectorTitle": "Target resources", "trafficProfilesLearnMoreTooltip": "You can apply policies to the network traffic that your organization needs to secure and manage.", "ztnaEnableLearnMore": "Zero Trust Cloud Edge needs to be turned on to use network access controls. " }, "NetworkLocations": { "ValidateTenantOnboardedAndAdaptiveAccessSignalingEnabledInGSA": { "infoBox": "To create a Conditional Access policy ensuring your tenant's members are coming from their compliant network, make sure Global Secure Access (GSA) is deployed and Adaptive Access Signaling in GSA is enabled in your tenant. Learn more on how to ", "learnMoreLabel": "enable GSA Adaptive Access Signaling." } }, "networkResourcesInfoBalloonAriaLabelAccessibility": "Additional information about network resources", "newCertName": "new cert", "noAttributePermissionsError": "Insufficient privileges to create or update policy. Attribute definition reader role is required to add/edit dynamic filters.", "noneRisk": "No risk", "noPolicyRowMessage": "No policies", "noSPSelected": "No service principal selected", "noUpdatePermissionMessage": "You don't have permissions to update these settings. Please contact your global administrator to get access.", "noUserSelected": "No user selected", "ObjectPickerStrings": { "appId": "App Id", "blueprintId": "Blueprint Id", "objectId": "Object Id" }, "office365Description": "These apps include Microsoft Flow, Microsoft Forms, Microsoft Teams, Office 365 Exchange Online, Office 365 SharePoint Online, Office 365 Yammer, and others.", "office365InfoBox": "At least one of the apps selected is part of Office 365. We recommend setting the policy on the Office 365 app instead.", "oneUserSelected": "1 user selected", "onlyGlobalAdminsCanSaveThisPolicyConfig": "Only global administrators can save this policy.", "or": "{0} OR {1} ", "Overview": { "SignInsProtectedByCa": { "accessDenied": "Access denied", "accessDeniedReportOnly": "Access denied (report-only)", "accessGranted": "Access granted", "accessGrantedReportOnly": "Access granted (report-only)", "deniedEnforced": "Access denied - Policy controls applied", "deniedEnforcedReportOnly": "Access denied (report-only) - Policy controls applied", "grantedEnforced": "Access granted - Policy controls applied", "grantedEnforcedReportOnly": "Access granted (report-only) - Policy controls applied", "grantedNotEnforced": "Access granted - No policy controls applied", "grantedNotEnforcedReportOnly": "Access granted (report-only) - Policy not applied", "grantedNotScoped": "Access granted - No policy applied", "grantedNotScopedReportOnly": "Access granted (report-only) - No policy controls applied", "noPolicyApplied": "No Policy applied", "noPolicyControlApplied": "No controls applied", "policyControlsApplied": "Controls applied", "title": "Sign-ins protected by Conditional Access", "tooltip": "Sign-ins protected by Conditional Access", "totalSignIns": "Total sign-ins", "userActionRequired": "User action required (report-only)" } }, "partialEnablementCompatibleWithWorkloadIdentitiesOnlyError": "Staged rollout is compatible with workload identities only", "partialEnablementTargetRegionsError": "Select at least one target region", "passwordChangeRequireEmptyExclude": "Cannot exclude apps when \"Require password change\" grant is selected.", "pickerDoneCommand": "Done", "policiesBladeTitle": "Policies", "policiesHitMaxLimitStatusBarMessage": "You've reached the maximum number of policies for this tenant. Delete some policies before creating more.", "policiesNewTabBadge": "NEW", "Policy": { "Condition": { "ServicePrincipalRisk": { "description": "Configure service principal risk levels needed for policy to be enforced", "infoBalloonContent": "Configure service principal risk to apply the policy to selected risk level(s)", "title": "Service principal risk", "titlePreview": "Service principal risk" } } }, "policyAssignmentsSection": "Assignments", "PolicyBlade": { "B2C": { "Validation": { "failed": "You must configure the \"{0}\" section." } }, "Conditions": { "AgentContext": { "ContextPane": { "allAgentAssistedFlows": "All agent assisted flows (Preview)", "allHostingApplicationFlows": "All hosting application flows (Preview)", "configureInfoballoon": "Turning on this option allows you to configure more restrictive conditions and controls when agents are acting on the user's behalf", "infoBoxContent": "Agent-assisted flows initiated by users are included in this policy by default. Configure this setting only if you want to apply additional restrictions to actions performed by agents acting on the user's behalf. ", "infoBoxLinkLabel": "Learn more" }, "description": "Assistive agent protections provides the ability to apply more restrictive conditions and controls when agents are acting on the user's behalf.", "label": "Assistive agent protections (Preview)" }, "AgentContextCua": { "ContextPane": { "agentAssistedPublicClientSessions": "Agent-assisted public client sessions (Preview)", "agentUserSessionsInitiatedFromEndpoints": "Agent user sessions initiated from endpoints", "allAgentUserSessions": "All agent user sessions", "configureInfoballoon": "Configure agent execution environments to apply additional policy controls to specific agent user session types.", "excludeNone": "None", "infoBoxContent": "Agent-assisted public client sessions are included in this policy by default. Configure this setting only if you want to apply additional policy controls to agent-assisted public client sessions. " }, "description": "Configure Agent execution environments for additional policy restrictions based on where the agent user is executed.", "label": "Agent execution environments (Preview)" }, "AgentSessionRisk": { "agentContextRequiredInfo": "Configure assistive agent protections to enable agent session risk evaluation.", "ContextPane": { "header": "Select the agent session risk levels this policy will apply to." }, "description": "Agent session risk level is the likelihood that the agent is exhibiting anomalous behavior in a specific session.", "label": "Agent session risk (Preview)" }, "AuthenticationFlows": { "Selector": { "authenticationTransfer": "Authentication transfer", "deviceCodeFlow": "Device code flow", "infoBalloon": "How your organization uses certain authentication and authorization protocols and grants", "label": "Authentication flows", "multiple": "\"{0}\" and \"{1}\"", "protocolFlows": "Protocol and flows" }, "singular": "Authentication flow" }, "DeviceAttributes": { "AssignmentFilter": { "edited": "Edit", "instructions": "You can use the rule builder or rule syntax text box to create or edit the filter rule.", "maxLength": "The maximum length for the filter rule is {0} characters.", "Rules": { "addExpression": "Add expression", "AndOr": { "and": "And", "header": "And/Or", "or": "Or" }, "gridAria": "Editor for custom device filter", "Operator": { "header": "Operator", "Options": { "contains": "Contains", "endsWith": "Ends with", "equals": "Equals", "in": "In", "notContains": "Not contains", "notEndsWith": "Not ends with", "notEquals": "Not equals", "notIn": "Not in", "notStartsWith": "Not starts with", "startsWith": "Starts with", "unknown": "Unknown" }, "placeholder": "Choose an operator" }, "Property": { "header": "Property", "placeholder": "Choose a property" }, "ruleSyntax": "Rule syntax", "simpleRuleConversionFail": "Some items could not be displayed in the rule builder.", "Value": { "header": "Value", "placeholder": "Pick a property and operator first" } } }, "Blade": { "AppliesTo": { "excluded": "Exclude filtered devices from policy", "included": "Include filtered devices in policy", "label": "Devices matching the rule:" }, "Configure": { "infoBalloon": "Configure device filters you want to policy to apply to." }, "header": "You can use the rule builder or rule syntax text box to create or edit the filter rule.", "headerDescription": "Configure a filter to apply policy to specific devices.", "headerLearnMoreAriaLabel": "Learn more about filtering for devices with Conditional Access.", "RuleSyntax": { "infoBalloon": "The currently configured rule syntax (e.g. CustomSecurityAttribute.Name -eq \"Value\")", "invalidRule": "Invalid rule: {0}", "label": "Rule syntax" }, "title": "Filter for devices" }, "error": "'{0}' and '{1}' are both configured. This policy will not work as expected until one is deconfigured.", "info": "'{0}' and '{1}' cannot be configured simultaneously. '{0}' has been deprecated. Use '{1}' instead.", "Metadata": { "TrustType": { "adRegistered": "Microsoft Entra registered", "azureAd": "Microsoft Entra joined", "hybridAd": "Microsoft Entra hybrid joined" } }, "Parser": { "arrayFailed": "Failed to parse array value: {0}. This needs to be of the style \"single value\" or \"first item\", \"second item\".", "emptyArray": "Empty array: {0}", "invalidExpression": "Expression is not valid: {0}", "invalidProperty": "Invalid property expression: {0}", "invalidRoot": "Expression is not valid: {0}. Root expression must be type of {1}", "mismatchedArrayTypes": "Operands have to be the same type, but left: {0}, right: {1}", "mismatchedTypes": "Different types in array: {0}", "noQuotations": "String value should not be in single or double quotes", "parseString": "String value must be in double quotes: {0}", "unsupportedBoolean": "Boolean properties can only be '{0}' or '{1}'.", "unsupportedGrouping": "Cannot represent the rule in the rule builder.", "unsupportedInteger": "'{0}' cannot be parsed as a number.", "unsupportedOperationOnProperty": "'{0}' operation is not supported for property '{1}'", "unsupportedOperationOnResult": "This rule engine does not support '{0}' operation for '{1}'", "unsupportedProperty": "Unsupported property: '{0}', for target type: '{1}'" }, "Selector": { "exclude": "Exclude filtered devices", "include": "Include filtered devices", "infoBalloon": "Filter to apply to devices based on their attributes.", "label": "Filter for devices" }, "Tokenizer": { "closingParentheses": "Found an opening parenthesis without a matching closing parentheses", "invalidCharacters": "Invalid characters found in the rule: {0}", "invalidPrecedence": "Precedence is invalid", "nullExpression": "Expression is null/undefined", "openingParentheses": "Found a closing parenthesis without a matching opening parentheses", "unknownOperator": "Unknown operator: {0}" } }, "PurviewDLP": { "Selector": { "configured": "Configured", "infoBalloon": "This policy requires browsers that support Purview DLP. Users must use a Purview-supported browser to access this resource", "label": "Data Loss Prevention" } } }, "CustomRoleNotAllowed": { "plural": "{0} custom roles are included or excluded in this policy but don't affect the users and groups in the policy. Only built-in roles are enforced. You will need to remove the custom roles before saving this policy. ", "singular": "1 custom role is included or excluded in this policy but doesn't affect the users and groups in the policy. Only built-in roles are enforced. You will need to remove the custom roles before saving this policy. " }, "editClassic": "Edit classic", "editWithAI": "Edit with AI", "GSA": { "Banner": { "message": " This policy was built using a previous data model. Once you save this policy, it will be migrated to the new data model. The policy will continue to work with no interruptions." } }, "LearnMore": { "ariaLabel": "Learn more about building a Conditional Access policy.", "conditions": "Control access based on signals such as risk, device and location.", "conditionsAriaLabel": "Learn more about Conditional Access conditions.", "message": "Control access based on Conditional Access policy to bring signals together, to make decisions, and enforce organizational policies." }, "Removed": { "cloudApps": "{0} cloud app(s) configured in this policy are either unsupported or have been deleted from the directory. This does not affect the other apps in the policy. When you save the policy, the unsupported or deleted app(s) will be automatically removed from it.", "deletedGroups": "Deleted groups ({0})", "deletedUsers": "Deleted users ({0})", "deletedUsersAndGroups": "Deleted users and groups", "namedLocations": "{0} location(s) configured in this policy have been deleted from the directory, but this doesn't affect the other locations in the policy. When you save the policy the deleted location(s) will be automatically removed from it.", "usersOrGroups": "{0} included or excluded in this policy have been deleted from the directory, but this doesn't affect the other users and groups in the policy. When you save the policy the deleted users and/or groups will be automatically removed.", "viewDetails": "View details" }, "subtitle": "Conditional Access policy", "tabLabel": "Policy", "Validation": { "failed": "You must configure either the \"{0}\" or \"{1}\" section." }, "viewPolicyImpact": "View policy impact", "Warnings": { "readOnly": "This view is a read-only view of this policy. To change it, please click here to visit the \"{0}\" page." } }, "policyBlockAllInfoBox": "The configured policy will block all users, so it is not supported. Review the assignments and controls. Exclude the current user {0}, if you would like to save this policy.", "policyCloudAppsDisplayTextAllApp": "All apps", "policyCloudAppsLabel": "Cloud apps", "PolicyCondition": { "AgentRisk": { "descriptor": "Agent risk level is the likelihood that the agent is exhibiting anomalous behavior." }, "InsiderRisk": { "Checkbox": { "ElevatedRisk": { "ariaLabel": "Insider risk level this policy will apply to. Elevated insider risk level.", "infoballoon": "User performed activities that might indicate a high degree of risk. Typically requires an insider risk admin to take proactive measures to prevent further risky activity from occurring." }, "MinorRisk": { "ariaLabel": "Insider risk level this policy will apply to. Minor insider risk level.", "infoballoon": "User performed activities that might indicate a minimal degree of risk. Typically, insider risk admins will continue to detect risky user activity to determine whether further action is required." }, "ModerateRisk": { "ariaLabel": "Insider risk level this policy will apply to. Moderate insider risk level.", "infoballoon": "User performed activities that might indicate a moderate degree of risk. While not as severe as an elevated risk, insider risk admins will still take appropriate actions to prevent further risky activity from occurring." } }, "ContextPane": { "configureInfoballoon": "Configure insider risk to apply the policy to users who are assigned selected risk levels.", "header": "Select the risk levels that must be assigned to enforce the policy", "infoBoxContent": "The insider risk condition requires configuration in Adaptive Protection.", "infoBoxLinkLabel": "Go to Microsoft Purview", "LearnMore": { "ariaLabel": "Learn more about insider risk.", "label": "Control access for users who are assigned specific risk levels from Adaptive Protection, a Microsoft Purview Insider Risk Management feature. Insider risk levels are determined based on a user's risky data related activities." } }, "descriptor": "Insider risk assesses the user's risky data-related activity in Microsoft Purview Insider Risk Management.", "label": "Insider risk", "Selector": { "LearnMore": { "label": "Insider risk, configured in Adaptive Protection, assesses risk based on a user's risky data related activities." } } }, "SignInRisk": { "descriptor": "Sign-in risk level is the likelihood that the sign-in session is compromised." }, "SignInRiskDetections": { "ApplyCondition": { "info": "Configure risk detections to apply the policy to selected real-time sign-in risk detection(s)." }, "description": "This condition is satisfied if any of the included risk detections detect risk. This does not affect the sign-in risk level calculation.", "header": "Real-time built-in risk detections", "info": "Detections that detect risks during sign-ins.", "label": "Sign-in risk detections (Preview)", "LearnMore": { "ariaLabel": "Learn more about sign-in risk detections.", "message": "Control user access to respond to specific real-time sign-in risk detections." }, "title": "Sign-in risk detections" }, "UserRisk": { "descriptor": "User risk level is the likelihood that the user account is compromised." } }, "policyConditionClientAppDescription": "Software the user is employing to access the cloud app. For example, 'Browser'", "policyConditionClientAppV2Description": "Software the user is employing to access the cloud app. For example, 'Browser'", "policyConditionDevicePlatform": "Device platforms", "policyConditionDevicePlatformDescription": "Platform the user is signing in from. For example, 'iOS'", "policyConditionDevicePlatformDescriptionAgentUser": "Platform the agent user is signing in from. For example, 'iOS'.", "policyConditionHighUserRiskCheckboxAriaLabel": "Group, configure user risk levels needed for policy to be enforced. High user risk level.", "policyConditioniClientApp": "Client apps", "policyConditionLocation": "Locations", "policyConditionLocationDescription": "Locations (determined using IP address range) the user is signing in from", "policyConditionLocationPreview": "Locations (Preview)", "policyConditionLowUserRiskCheckboxAriaLabel": "Group, configure user risk levels needed for policy to be enforced. Low user risk level.", "policyConditionMediumUserRiskCheckboxAriaLabel": "Group, configure user risk levels needed for policy to be enforced. Medium user risk level.", "policyConditionNetwork": "Network", "policyConditionNetworkLocationDescription": "Network and locations (determined by IP address range or GPS coordinates) the user is signing in from", "policyConditionSigninRisk": "Sign-in risk", "policyConditionSigninRiskDescription": "Likelihood that the sign-in is coming from someone other than the user. Risk level can be high, medium or low. Requires Microsoft Entra ID P2 license.", "policyConditionUserAndSigninRiskWarning": "Avoid combining User Risk and Sign-in Risk in the same policy. These conditions rarely occur together, so Microsoft recommends creating separate policies - one for User Risk and another for Sign-in Risk.", "policyConditionUserRisk": "User risk", "policyConditionUserRiskDescription": "Configure user risk levels needed for policy to be enforced", "policyControlAllowAccessDisplayedName": "Grant access", "policyControlAuthenticationStrengthDisplayedName": "Require authentication strength", "PolicyControlAuthStrength": { "MultiFactorAuthentication": { "description": "Combinations of methods that satisfy strong authentication, such as Password + SMS", "displayName": "Multifactor authentication" }, "Passwordless": { "description": "Passwordless methods that satisfy strong authentication, such as Microsoft Authenticator ", "displayName": "Passwordless MFA" }, "PhishingResistant": { "description": "Phishing-resistant Passwordless methods for the strongest authentication, such as FIDO2 Security Key", "displayName": "Phishing-resistant MFA" } }, "policyControlBladeTitle": "Grant", "policyControlBlockAccessDisplayedName": "Block access", "policyControlCompliantDeviceDisplayedName": "Require device to be marked as compliant", "policyControlContentAriaLabel": "Learn more about the Conditional Access grant control.", "policyControlContentDescription": "Control access enforcement to block or grant access.", "policyControlInfoBallonText": "Block access or select additional requirements which need to be satisfied to allow access", "policyControlMfaChallengeDisplayedName": "Require multifactor authentication", "policyControlRequireCompliantAppDisplayedName": "Require app protection policy", "policyControlRequireDomainJoinedDisplayedName": "Require Microsoft Entra hybrid joined device", "policyControlRequiredPasswordChangeDisplayedName": "Require password change", "policyControlRequireMamDisplayedName": "Require approved client app", "policyControlRequireRiskRemediationDisplayedName": "Require risk remediation", "policyControlSelectAuthStrength": "Require authentication strength", "policyControlSelectRiskRemediation": "Require risk remediation", "policyControlsNoControlsSelected": "0 controls selected", "policyControlsSection": "Access controls", "policyControlVerifiedIdDisplayedName": "Require identity verification", "policyCreatBladeTitle": "New", "policyCreateButton": "Create", "policyCreateFailedMessage": "Error: {0}", "policyCreateFailedTitle": "Failed to create '{0}'", "policyCreateInProgressTitle": "Creating '{0}'", "policyCreateSuccessMessage": "Successfully created '{0}'. Policy will be enabled in a few minutes.", "policyCreateSuccessTitle": "Successfully created '{0}'", "policyDeleteConfirmation": "Are you sure you want to delete '{0}'? This action cannot be undone.", "policyDeleteFailTitle": "Failed to delete '{0}'", "policyDeleteInProgressTitle": "Deleting '{0}'", "policyDeleteSuccessTitle": "Successfully deleted '{0}'", "policyEnforceLabel": "Enable policy", "policyErrorCannotSetSigninRisk": "You don't have permission to save a policy with a sign-in risk condition.", "policyErrorNoPermission": "You don't have permission to save policy. Contact your global admin.", "policyErrorUnknown": "Something went wrong, please try again later.", "policyFallbackWarningMessage": "Failure to create or update '{0}' using MS Graph resulting in a fallback to AD Graph. Please investigate the following scenario as there is most likely a bug when calling the policy endpoint for MS Graph with an incompatible condition.", "policyFallbackWarningTitle": "Creating or updating '{0}' partially successful", "policyNameCannotBeEmpty": "Policy name can't be empty", "policyNameDevice": "Device policy", "policyNameFormat": "[{0}] {1}", "policyNameMam": "Mobile App Management policy", "policyNameMfaLocation": "Multifactor authentication and location policy", "policyNamePlaceholderText": "Example: 'Device compliance app policy'", "policyNameTooLongError": "Policy name is too long. Maximum 256 characters", "policyOff": "Off", "policyOffOptionsGroupItemAriaLabel": "Enable Policy: Off.", "policyOn": "On", "policyOnOptionsGroupItemAriaLabel": "Enable Policy: On.", "policyReportOnly": "Report-only", "policyReportOnlyOptionsGroupItemAriaLabel": "Enable Policy: Report-only.", "policyResourcesFormerlyCloudAppsLabel": "Resources (formerly cloud apps)", "policyResourcesLabel": "Resources", "policyReviewSection": "Review", "policySaveButton": "Save", "policySoftDeleteConfirmation": "Once deleted, you will have 30 days to restore this policy.", "policySoftDeleteConfirmationTitle": "Delete conditional access policy?", "policyStagedRollout": "Staged rollout", "policyStagedRolloutOptionsGroupItemAriaLabel": "Enable Policy: Staged rollout.", "PolicyState": { "off": "Off", "on": "On", "reportOnly": "Report-only", "stagedRollout": "Staged rollout" }, "policyStatusIconDescription": "Policy is Enabled", "policyStatusIconEnabled": "Enabled status icon", "policyTemplateName1": "Use app enforced restrictions for {0} browser access", "policyTemplateName2": "Allow {0} access only on managed devices", "policyTemplateName3": "Policy migrated from Continuous Access Evaluation settings", "PolicyTemplates": { "Summary": { "CloudApps": { "office365": "Office 365" } }, "TemplateId": { "AppEnforcedRestrictions": { "description": "Block or limit access to SharePoint, OneDrive, and Exchange content from unmanaged devices.", "name": "CA014: Use application enforced restrictions for unmanaged devices", "title": "Use application enforced restrictions for unmanaged devices" }, "ApprovedClientApps": { "description": "To prevent data loss, organizations can restrict access to approved modern auth client apps with Intune app protection.", "name": "CA012: Require approved client apps and app protection", "title": "Require approved client apps and app protection" }, "BlockAccessOnUnknowns": { "description": "Users will be blocked from accessing company resources when the device type is unknown or unsupported.", "name": "CA010: Block access for unknown or unsupported device platform", "title": "Block access for unknown or unsupported device platform" }, "BlockLegacyAuth": { "description": "Block legacy authentication endpoints that can be used to bypass multifactor authentication. ", "name": "CA003: Block legacy authentication", "title": "Block legacy authentication" }, "MicrosoftAdminPortals": { "title": "Require multifactor authentication for admins accessing Microsoft Admin Portals" }, "NoPersistentBrowserSession": { "description": "Protect user access on unmanaged devices by preventing browser sessions from remaining signed in after the browser is closed and setting a sign-in frequency to 1 hour.", "name": "CA011: No persistent browser session", "title": "No persistent browser session" }, "PhishingResistantAuthStrength": { "description": "Require phishing-resistant multifactor authentication for privileged administrative accounts to reduce risk of compromise and phishing attacks. This policy will target the same roles as Security Default.", "name": "CA016: Require phishing-resistant multifactor authentication for admins", "title": "Require phishing-resistant multifactor authentication for admins" }, "RequireCompliantOrHybridADAdmins": { "description": "Require privileged administrators to only access resources when using a compliant or Microsoft Entra hybrid joined device.", "name": "CA009: Require compliant or Microsoft Entra hybrid joined device for admins", "title": "Require compliant or Microsoft Entra hybrid joined device for admins" }, "RequireCompliantOrHybridADAllUsers": { "description": "Protect access to company resources by requiring users to use a managed device or perform multifactor authentication. (macOS or Windows only)", "name": "CA013: Require compliant or Microsoft Entra hybrid joined device or multifactor authentication for all users", "title": "Require compliant or Microsoft Entra hybrid joined device or multifactor authentication for all users" }, "RequireMFAAllUsers": { "description": "Require multifactor authentication for all user accounts to reduce risk of compromise.", "name": "CA004: Require multifactor authentication for all users", "title": "Require multifactor authentication for all users" }, "RequireMFAForAdmins": { "description": "Require multifactor authentication for privileged administrative accounts to reduce risk of compromise. This policy will target the same roles as Security Default.", "name": "CA001: Require multifactor authentication for admins", "title": "Require multifactor authentication for admins" }, "RequireMFAForAzureManagement": { "description": "Require multifactor authentication to protect privileged access to Azure resources.", "name": "CA006: Require multifactor authentication for Azure management", "title": "Require multifactor authentication for Azure management" }, "RequireMFAForGuestAccess": { "description": "Require guest users perform multifactor authentication when accessing your company resources.", "name": "CA005: Require multifactor authentication for guest access", "title": "Require multifactor authentication for guest access" }, "RequireMFAForRiskySignIn": { "description": "Require multifactor authentication if the sign-in risk is detected to be medium or high. (Requires a Microsoft Entra ID P2 License)", "name": "CA007: Require multifactor authentication for risky sign-ins", "title": "Require multifactor authentication for risky sign-ins" }, "RequirePasswordChangeForHighRiskUsers": { "description": "Require high-risk users to perform risk remediation, such as a secure password change and/or session revocation, before they can access resources. (Requires a Microsoft Entra ID P2 license)", "name": "CA008: Require risk remediation for high-risk users", "title": "Require risk remediation for high-risk users" }, "RequireSecurityInfo": { "description": "Secure when and how users register for Microsoft Entra multifactor authentication and self-service password. ", "name": "CA002: Securing security info registration", "title": "Securing security info registration" }, "VerifiedIdRecovery": { "description": "Secure when and how users register for Microsoft Entra multifactor authentication and self-service password. ", "name": "CA015: Secure account recovery with identity verification (preview)", "title": "Secure account recovery with identity verification (Preview)" } } }, "policyTriggerRiskSpecific": "Select specific risk level", "policyTriggersInfoBalloonText": "Conditions which define when the policy will apply. For example, 'location'", "policyTriggersNoConditionsSelected": "0 conditions selected", "policyTriggersSelectorLabel": "Conditions", "policyUpdateFailedMessage": "Error: {0}", "policyUpdateFailedTitle": "Failed to update {0}", "policyUpdateInProgressTitle": "Updating {0}", "policyUpdateSuccessMessage": "Successfully updated {0}. Policy will be enabled in a few minutes.", "policyUpdateSuccessTitle": "Successfully updated {0}", "primaryCol": "Primary", "privateLinkLabel": "Microsoft Entra Private Link", "purviewDLPGrantOnlyBlock": "Purview Data Loss Prevention condition only supports the Block access grant control.", "purviewDLPInfoBalloonAriaLabelAccessibility": "Additional information about Purview DLP", "purviewDLPNoSessionControls": "Purview Data Loss Prevention condition can't be applied together with session controls.", "purviewDLPNotSupportedForActor": "Purview Data Loss Prevention condition can't be applied when the policy targets workload identities or agents.", "purviewDLPNotSupportedForAgentContext": "Purview Data Loss Prevention condition can't be applied together with the agent context condition.", "purviewDLPNotSupportedForAgentSessionRisk": "Purview Data Loss Prevention condition can't be applied together with the agent session risk condition.", "purviewDLPRequireTargetResources": "Purview Data Loss Prevention condition must target at least one real application.", "purviewDLPRequireUsers": "Purview Data Loss Prevention condition must target at least one user, group, role, or guest.", "reportOnlyInfoBox": "Report-only mode: Policies are evaluated and logged at sign-in but do not impact users.", "requireAllControlsText": "Require all the selected controls", "requireAuthStrength": "Require authentication strength", "requireCompliantDevice": "Require compliant device", "requireDomainJoined": "Require domain-joined device", "requireGrantReauth": "The \"sign-in frequency every time\" session control requires a \"require multifactor authentication\" or \"require password change\" grant control when \"All cloud apps\" is selected", "requireMFA": "Require multifactor authentication", "requireMfaOrAuthStrengthGrantReauth": "The \"sign-in frequency every time\" session control requires a \"require multifactor authentication,\" \"require authentication strength,\" or \"require password change\" grant control when \"All cloud apps\" is selected", "requireMfaOrAuthStrengthReauth": "The \"sign-in frequency every time\" session control requires a \"require multifactor authentication\" or \"require authentication strength\" grant control for \"sign-in risk\"", "requireMfaReauth": "The \"sign-in frequency every time\" session control requires the \"require multifactor authentication\" grant control for \"sign-in risk\"", "requireOneControlText": "Require one of the selected controls", "requirePasswordChangeReauth": "The \"sign-in frequency every time\" session control requires the \"require password change\" grant control for \"user risk\"", "requireRiskReauth": "The \"sign-in frequency every time\" session control requires the \"user risk\" or \"sign-in risk\" session control when \"all cloud apps\" is selected.", "requireRiskReauthRiskNotEnabled": "The \"sign-in frequency every time\" session control is not available when \"all cloud apps\" is selected.", "requireRiskReauthSignInOnly": "The \"sign-in frequency every time\" session control requires the \"sign-in risk\" session control when \"all cloud apps\" is selected.", "requireRiskReauthUserOnly": "The \"sign-in frequency every time\" session control requires the \"user risk\" session control when \"all cloud apps\" is selected.", "resetFilters": "Reset filters", "ResourcesSelectionBlade": { "Exclude": { "description": "Select the resources to exempt from the policy" } }, "resourcesSelectorPluralExcluded": "{0} resources excluded", "resourcesSelectorPluralIncluded": "{0} resources included", "resourcesSelectorSingularExcluded": "1 resource excluded", "resourcesSelectorSingularIncluded": "1 resource included", "RiskRemediationValidation": { "mustNotSelect": "To enable Require Risk Remediation, you must not select {0}.", "mustSelect": "To enable Require Risk Remediation, you must select {0}.", "xOrY": "{0} or {1}" }, "SamlReauth": { "Filter": { "warning": "You are targeting applications using a dynamic query. Some applications might not be supported to use with \"sign-in frequency every time\" session control. {0}Read more about the recommended scenarios.{1}", "warningRefresh": "You are targeting applications using a dynamic query. Over-prompting users for reauthentication can occur when the \"sign-in frequency every time\" session control is enabled in some applications. {0}Read more about the recommended scenarios.{1}" } }, "saturday": "Saturday", "searchPlaceholder": "Search", "searchTextTooLongError": "The search text is too long. Maximum 256 characters", "securityDefaultsPolicyName": "Security defaults", "securityDefaultsTextMessage": "Security defaults must be disabled to enable Conditional Access policy.", "securityDefaultsUpdateInProgressText": "A security defaults update is in progress, please wait a moment and try again.", "securityDefaultsWarningMessage": "It looks like you're about to manage your organization's security configurations. That's great! You must first {0}disable security defaults{1} before enabling a Conditional Access policy.", "selectDevicePlatforms": "Select device platforms", "selectedSP": "Selected Service Principal", "selectNamedNetworksSubtitle": "", "selectNamedNetworksTitle": "Select locations", "SelectOrganizations": { "Blade": { "addTenantLabel": "Add tenant to selected", "customOrganizationDescription": "Add an organization with this tenant ID", "description": "Add a Microsoft Entra organization by typing one of its domain names.", "Lower": { "gridAria": "List of selected organizations" }, "notFoundResult": "Not found", "searchBoxPlaceholder": "Tenant ID or domain name", "subTitle": "Microsoft Entra organization", "tenantAdded": "This tenant ID has already been added.", "tenantIdNotFound": "Tenant ID not found", "Upper": { "gridAria": "List of available organizations" } }, "Selector": { "AdditionalDetails": { "aria": "Organization ID: {0}" }, "DisplayText": { "multiple": "{0} Microsoft Entra organizations selected", "single": "1 Microsoft Entra organization selected" }, "gridAria": "List of selected organizations" } }, "selectorRequiredAccessibility": "required", "servicePrincipalBladeExcludedSelectorTitle": "Select excluded service principals", "servicePrincipalBladeIncludedSelectorTitle": "Select service principals", "servicePrincipalDataGridAria": "List of available service principals", "servicePrincipalDropDownLabel": "What does this policy apply to?", "servicePrincipalInfoBox": "Some conditions are not available due to '{0}' selection in policy assignment", "servicePrincipalRiskInfoBalloonAriaLabelAccessibility": "Additional information about service principal risk levels", "servicePrincipals": "Service principals", "ServicePrincipalsCA": { "AgenticResources": { "agentCompliantDeviceInfo": "Device compliance signals are available only for agents running on endpoints, including local devices and virtual machines. To avoid unintended blocking, scope this policy to \"Agents initiated from endpoints\" using the Agent execution environments condition.", "agentDeviceConditionsInfo": "Device platforms and filter for devices require device information and only apply to agents running on endpoints, including local devices and cloud-hosted virtual machines.", "agentDevicePlatformPaneInfo": "This condition requires device information and only applies to agents running on endpoints, including local devices and cloud-hosted virtual machines.", "agentIdentities": "Agent identities (Preview)", "agentNetworkConditionsInfo": "The network condition only applies to agents running on endpoints (devices or cloud-hosted virtual machines) with a GSA client", "agentRisk": "Agent risk (Preview)", "agentRiskContextRequiredInfo": "Configure assistive agent protections to enable agent risk evaluation.", "agentRiskDescription": "Configure agent risk levels needed for policy to be enforced", "agentRiskInfo": "Agent risk level is the likelihood that the agent is compromised.", "allSelected": "All agent identities (Preview)", "allSelectedGA": "All agent identities", "multipleAgentsSelected": "{0} agents selected", "noneSelected": "0 users or agents (Preview) selected", "noneSelectedGA": "0 users or agents selected", "noneSelectedWithWorkloadIdentities": "0 users, agents (Preview) or workload identities selected", "selectAgents": "Select agents", "selectAgentsTitle": "Select individual agent identities", "selectAgentsTitleShort": "Select individual agents", "selectAgentUsersTitle": "Select individual agent users", "selectAgentUsersTitleShort": "Select individual agents", "selectExcluded": "Select excluded agents", "selectIncluded": "Select agents", "singleAgentSelected": "1 agent selected", "specificExcluded": "Specific agents (Preview) excluded", "specificExcludedGA": "Specific agents excluded", "specificIncluded": "Specific agents (Preview) included", "specificIncludedGA": "Specific agents included" }, "Radio": { "all": "All owned service principals", "allFirstPartyApps": "All Microsoft service principals", "allManagedIdentities": "All managed identities", "allThirdPartyApps": "All owned single and multi tenant service principals", "select": "Select service principals" } }, "servicePrincipalSelectionsAria": "Selected service principals grid", "servicePrincipalSelectorAria": "List of chosen service principals", "servicePrincipalSelectorMultiple": "{0} service principals selected", "servicePrincipalSelectorSingle": "1 service principal selected", "servicePrincipalSpecificExc": "Specific service principals excluded", "servicePrincipalSpecificInc": "Specific service principals included", "sessionControlBladeTitle": "Session", "sessionControlDescriptionContent": "Control access based on session controls to enable limited experiences within specific cloud applications.", "sessionControlDescriptionLearnMoreAriaLabel": "Learn more about application enforced restrictions.", "sessionControlDisableInfo": "This control only works with supported apps. Currently, Office 365, Exchange Online, and SharePoint Online are the only cloud apps that support app enforced restrictions.", "sessionControlInfoBallonText": "Session controls enable limited experience within a cloud app.", "sessionControlInfoBalloonAriaLabelAccessibility": "Additional information about session controls", "SessionControls": { "BlockSensitiveActions": { "checkboxLabel": "Block sensitive actions (Preview)", "infoBalloon": "When enabled, sensitive actions from risky sessions will be blocked." }, "Cae": { "checkboxLabel": "Customize continuous access evaluation", "disable": "Disable", "disableError": "Continuous access evaluation \"Disable\" can only be used when policy is assigned to \"All cloud apps\" and no conditions are selected.", "disableText": "Disable continuous access evaluation (CAE) only works correctly when \"{0}\" is selected, and no conditions has been chosen. Please change your cloud apps and condition selections.", "helpLabel": "See list of supported clients and resource providers", "infoBalloonText": "Continuous Access Evaluation (CAE) allows access tokens to be revoked based on critical events and policy evaluation in real time rather than relying on token expiration based on lifetime.\n* \"{0}\" works correctly when \"{1}\" is selected, and no condition has been chosen.\n* This setting does not work with report-only mode, but there are pre-published workbooks with data insights.", "label": "Continuous access evaluation settings", "none": "None", "notAvailableText": "Continuous access evaluation (CAE) controls will not be available unless you enable CAE for all users.", "notMigratedText": "Continuous access evaluation (CAE) control is not available until you complete the migration from the old CAE setting.", "SelectorLabel": { "disable": "Use continuous access evaluation - Disable", "strictEnforcement": "Use continuous access evaluation - Strict enforcement", "strictLocation": "Use continuous access evaluation - Strict location" }, "SP": { "checkboxLabel": "Customize continuous access evaluation (Preview)" }, "strictEnforcement": "Strict enforcement", "strictEnforcementSP": "Strict enforcement (coming soon!)", "strictEnforcementText": "This policy has strict enforcement for continuous access evaluation configured. Strict enforcement is currently not supported and has been rolled back. Saving this policy will automatically remove strict enforcement from the policy.", "strictLocation": "Strictly enforce location policies (Preview)" }, "Gsa": { "securityProfileWithNoGsaTargetSelection": "\"Global Secure Access security profile\" only works correctly when \"All Internet resources with Global Secure Access\" or \"All resources\" are selected. Please change your target selection." }, "NetworkAccessSecurity": { "checkboxLabel": "Use Global Secure Access security profile", "dropdownDefaultText": "Select a policy", "dropdownDefaultTextProfile": "Select a security profile", "infoboxSecurityProfileLoadFailedText": "Security profile assignment has been temporarily disabled due to a system error.", "infoboxSecurityProfileLoadFailedWithExistingProfileText": "Security profile assignment has been temporarily disabled due to a system error. This policy has an assigned profile.", "infoboxTargetResourceRequirementText": "This option only works with \"Global Secure Access\" as the targeted resource.", "infoboxTargetResourceRequirementTextGSA": "This option only works with Global Secure Access resources.", "selectorDisplayText": "Conditional Access Network Control selected", "tooltip": "Use this option to apply a policy profile for Global Secure Access targeted resources." }, "ResiliencyDefaults": { "checkboxLabel": "Disable resilience defaults", "infoBallonText": "During an outage, Microsoft Entra ID will extend access to existing sessions while enforcing Conditional Access policies. If a policy cannot be evaluated, access is determined by resilience settings. If resilience defaults are disabled, access is denied once existing sessions expire.", "infoBoxLabel": "To improve the resilience of Microsoft Entra ID, we are announcing Conditional Access resilience defaults. Learn more about managing this new setting for your policies." }, "SecureApp": { "checkboxLabel": "Require token protection for app sessions (Preview)" }, "SecureSignIn": { "checkboxLabel": "Require token protection for sign-in sessions", "error": "Policies enforcing Token Protection for Sign In Sessions must be scoped to supported platforms. {0}Learn more about token protection.{1}", "infoBallonText": "A secure sign-in session requires all long-lived tokens (the Microsoft Entra session cookie and refresh token) to be bound to the device using software key binding or hardware security module binding where available.", "warningInfoBoxText": "The control \"Require token protection for sign-in sessions\" only works with supported devices and applications. Unsupported devices and client applications will be blocked." }, "SignInFrequency": { "actorInvalid": "The \"sign-in frequency every time\" session control cannot be used with \"{0}\"", "appWarning": "Some of the applications currently selected are not compatible with the \"Sign-in frequency\" option of \"Every time\"", "everytime": "Every time (5-minute tolerance)", "EverytimeCA": { "secondaryOnly": "Secondary authentication methods only" }, "everytimeInfoBalloon": "\"Every time\" option is evaluated on every sign-in attempt to an application in scope for this policy.", "everyTimeStrict": "Every time (Strict - 10-second tolerance)", "everyTimeStrictInfoBalloon": "Prompt tolerance limits how often users can be re-prompted for reauthentication to prevent excessive prompts and loops.", "periodic": "Periodic reauthentication", "reqMFAWarning": "\"Require multifactor authentication\" must be selected when using \"Secondary authentication methods only\"", "selectorInvalid": "When \"Require password change\" grant is selected, only \"sign-in frequency every time\" session control can be used", "sleWarning": "Make sure to add the dedicated, enumerable egress IPs that the selected users use to reach Microsoft Entra and the selected CAE-capable resources to your IP-based named locations. Once the setting is enabled, requests from other IPs will be blocked.", "sleWarningLearnMoreAriaLabel": "Learn more about strictly enforce location policies impact", "warning": "\"Require password change\" can only be used with sign-in frequency of \"Every time\"" } }, "sessionControlsAppEnforcedLabel": "Use app enforced restrictions", "sessionControlsCasLabel": "Use Conditional Access App Control", "SessionControlsLabel": "Session controls", "sessionControlsSecureSignInLabel": "Require token protection", "SessionLifetime": { "mainOption": "Modify session lifetime", "mainOptionHelp": "Configure how often users will get prompted and whether browser sessions will be persisted. Applications that don't support modern authentication protocols might not honor these policies. In such cases please contact the application developer.", "PersistentBrowser": { "Error": { "notAllApps": "Persistent browser session policy only works correctly when \"All cloud apps\" is selected. Please update your cloud apps selection." }, "Option": { "always": "Always persistent", "help": "A persistent browser session allows users to remain signed in after closing and reopening their browser window.\n* This setting works correctly when \"All cloud apps\" are selected.\n* This does not affect token lifetimes or the sign-in frequency setting.\n* This will override the \"Show option to stay signed in\" policy in Company Branding.\n* \"Never persistent\" will override any persistent SSO claims passed in from federated authentication services.\n* \"Never persistent\" will prevent SSO on mobile devices across applications and between applications and the user's mobile browser.", "label": "Persistent browser session", "never": "Never persistent" }, "Warning": { "allApps": "Persistent browser session only works correctly when All cloud apps is selected. Please change your cloud apps selection." } }, "SignInFrequency": { "Aria": { "units": "Hours or days", "value": "Frequency" }, "Option": { "Day": { "plural": "{0} days", "singular": "1 day" }, "daysOption": "Days", "everytime": "Every time", "everyTimeStrict": "Every time (Strict)", "help": "Time period before a user is asked to sign-in again when attempting to access a resource. The default setting is a rolling window of 90 days, i.e. users will be asked to re-authenticate on the first attempt to access a resource after being inactive on their machine for 90 days or longer.", "Hour": { "plural": "{0} hours", "singular": "1 hour" }, "hoursOption": "Hours", "label": "Sign-in frequency", "placeholder": "Select units" } } }, "sharepointAppName": "SharePoint", "SigninRisk": { "LearnMore": { "ariaLabel": "Learn more about sign-in risk.", "message": "Control user access to respond to specific sign-in risk levels." } }, "signInRiskDetectionsInfoBalloonAriaLabelAccessibility": "Additional information about sign-in risk detections", "signinRiskInclude": "{0} included", "signInRiskInfoBalloonAriaLabelAccessibility": "Additional information about sign-in risk levels", "SigninRiskLevel": { "description": "Sign-in risk level is generated based on all real-time risk detections.", "header": "Select the sign-in risk level this policy will apply to", "highSignInRiskCheckboxAriaLabel": "Group, select the sign-in risk level this policy will apply to. High sign-in risk level.", "lowSignInRiskCheckboxAriaLabel": "Group, select the sign-in risk level this policy will apply to. Low sign-in risk level.", "mediumSignInRiskCheckboxAriaLabel": "Group, select the sign-in risk level this policy will apply to. Medium sign-in risk level.", "NoRiskSelected": { "warning": "When \"{0}\" is selected, the \"{1}\" condition will not be configurable." }, "noRiskSignInRiskCheckboxAriaLabel": "Group, select the sign-in risk level this policy will apply to. No sign-in risk." }, "signinRiskorAuthStrengthReauth": "\"Sign-in risk\" condition must be selected when \"require multifactor authentication\" or \"require authentication strength\" grant and \"sign-in frequency every time\" session control are selected", "signinRiskReauth": "\"Sign-in risk\" condition must be selected when \"Require multifactor authentication\" grant and \"sign-in frequency every time\" session control are selected", "signinRiskTriggerDescriptionContent": "Select the sign-in risk level", "SingleSelectorActive": { "failed": "Unable to load this data.", "reattempt": "Loading data. Reattempt {0} of {1}.", "SelectorCollapsed": { "withLabel": "{0} selector collapsed", "withoutLabel": "Selector collapsed" }, "SelectorExpanded": { "withLabel": "{0} selector expanded", "withoutLabel": "Selector expanded" } }, "singleTenantServicePrincipalInfoBallonText": "Policy only applies to single tenant service principals owned by your organization.", "specificSigninRiskLevelsOption": "Select specific sign-in risk levels", "specificUsersExcluded": "specific users excluded", "specificUsersIncluded": "Specific users included", "specificUsersIncludedAndExcluded": "Specific users excluded and included", "sPRequired": "Service principal required", "sPSelectorInfoBalloon": "User or Service Principal you want to test", "SSM": { "bladeTitle": "Continuous access evaluation", "description": "When a user's access is removed or a client IP address changes, Continuous access evaluation automatically blocks access to resources and applications in near real time. ", "MemberSelector": { "description": "Users and groups" }, "migrateLabel": "Migrate", "migrationError": "Migration failed due to the following error: {0}", "migrationInfo": "CAE setting has been moved under Conditional Access UX, please migrate with the \"Migrate\" button above and configure it with Conditional Access policy going forward. Click here to learn more.", "noLicenseMessage": "Manage smart session management settings with Microsoft Entra ID Premium", "Notification": { "error": "Failed to update Continuous access evaluation settings", "inProgress": "Updating Continuous access evaluation settings", "Migration": { "error": "Failed to migrate Continuous access evaluation settings to Conditional access policies", "inProgress": "Migrating Continuous access evaluation settings", "success": "Successfully migrated Continuous access evaluation settings to Conditional access policies", "successDescription": "Please proceed to Conditional access policies to view the migrated settings in the newly created policy named \"CA policy created from CAE settings\"." }, "success": "Successfully updated Continuous access evaluation settings" }, "optionsPickerTitle": "Enable/Disable Continuous access evaluation", "PreviewOptions": { "disable": "Disable preview", "enable": "Enable preview" }, "StrictLocationEnforcement": { "infoContent1": "Different IPs can be seen by Microsoft Entra ID and Resource Provider from the same client device due to network partition or IPv4/IPv6 mismatch. Strict Location Enforcement will enforce the Conditional Access policy based on both IP addresses seen by Microsoft Entra ID and Resource Provider.", "infoContent2": "To ensure maximum security, it is recommended to include all IPs that can be seen by both Microsoft Entra ID and Resource Provider in your Named Location policy and turn on \"Strict Location Enforcement\" mode.", "label": "Strict Location Enforcement", "title": "Additional enforcement modes" }, "upsellInfo": "You cannot change your settings on this page anymore and any settings here should be disregarded. Your previous setting will be honored. You can configure your CAE settings under Conditional Access going forward. Click here to learn more." }, "startDatePickerLabel": "Starts", "startFreeTrial": "Start a free trial", "startTimePickerLabel": "Start time", "sunday": "Sunday", "targetAppsReauthWarning": "Over prompting users for reauthentication can occur when the \"Sign-in Frequency - every time\" setting is enabled in some applications. {0}Read more about the recommended scenarios.{1}", "targetControlInfoBalloonAriaLabelAccessibility": "Additional information about target resources", "targetRegions": "Target regions", "TargetResources": { "ValidateTenantOnboardedToGSA": { "infobox": "To create a Conditional Access policy targeting members in your tenant with Global Secure Access (GSA) as a resource, make sure GSA is deployed in your tenant." } }, "targetSelect": "Select target type", "testButton": "What If", "thumbprintCol": "Thumbprint", "thursday": "Thursday", "TimeCondition": { "Errors": { "both": "Invalid \"Include\" or \"Exclude\" time range.", "daysOfWeek": "{0} Make sure to specify at least one day of the week.", "endBeforeStart": "{0} Make sure start date/time is earlier than end date/time.", "exclude": "Invalid \"Exclude\" time range.", "generic": "{0} Make sure both days of the week and time zone are set. If \"All day\" is not checked, start time and end time need to be set as well.", "include": "Invalid \"Include\" time range.", "timeMissing": "{0} Make sure to specify both a start and end time.", "timesAndZone": "{0} Make sure you set start time, end time and time zone.", "timeZone": "{0} Make sure to specify a time zone." } }, "timeConditionAllTimesLabel": "Any time", "timeConditionIntroText": "Configure the time this policy will apply to", "timeConditionSelectorInfoBallonContent": "When the user is signing in. For example, \"Wednesday 9am-5pm PST\"", "timeConditionSelectorLabel": "Time (Preview)", "timeConditionSpecificLabel": "Specific times", "timeSelectorAllTimesText": "Any time", "timeSelectorSpecificTimesText": "Specific times configured", "timeZoneDropdownInfoBalloonContent": "Select a time zone that defines the time range. This policy applies to users in all time zones. For example, 'Wednesday 9am - 5pm' for one user would be 'Wednesday 10am - 6pm' for a user in a different time zone.", "timeZoneDropdownLabel": "Time zone", "timeZoneDropdownPlaceholderText": "Select a time zone", "trustedLocationStatusIconDescription": "Location is trusted", "trustedLocationStatusIconEnabled": "Trusted status icon", "tuesday": "Tuesday", "uploadInBadState": "Unable to upload the specified file.", "UserActions": { "accessRequirement1": "Level 1", "accessRequirement2": "Level 2", "accessRequirement3": "Level 3", "accessRequirementsLabel": "Accessing secured app data", "accountRecovery": "Recover account", "accountRecoveryInfoText": "This user action requires the idenity verification grant control. Please select an identity verification profile.", "appsActionsAuthTitle": "Cloud apps, actions, or authentication context", "appsOrActionsSelectorInfoBallonText": "Applications accessed or user actions", "appsOrActionsTitle": "Cloud apps or actions", "Included": { "none": "No cloud apps or actions selected", "plural": "{0} user actions included", "singular": "1 user action included" }, "label": "User actions", "mainOptionsLabel": "Select what this policy applies to", "registerOrJoinDevices": "Register or join devices", "registerSecurityInfo": "Register security information", "selectionInfo": "Select the action this policy will apply to", "whatIf": "User action included" }, "userAgentOrSPSelectionBladeTitle": "Users, agents or workload identities", "userAppNoneOption": "None", "userNamePlaceholderText": "Enter User Name", "userNotSetSeletorLabel": "0 users and groups selected", "userOnlySelectionBladeExcludeDescription": "Select the users to exempt from the policy", "userOrAgentSelectionBladeTitle": "Users or agents (Preview)", "userOrAgentSelectionBladeTitleGA": "Users or agents", "userOrGroupSelectionCountDiffBannerText": "{0} configured in this policy have been deleted from the directory, but this doesn't affect the other users and groups in the policy. The next time you update the policy, the deleted users and/or groups will be automatically removed.", "userOrSPNotSetSelectorLabel": "0 users or workload identities selected", "userOrSPSelectionBladeTitle": "Users or workload identities", "userOrSPSelectorInfoBallonText": "Identities in the directory that the policy applies to, including users, groups, and service principals", "userRequired": "User Required", "userRiskErrorBox": "\"User risk\" condition must be selected when \"Require password change\" grant is selected", "userRiskInfoBalloonAriaLabelAccessibility": "Additional information about user risk levels", "userRiskReauth": "\"User risk\" condition and not \"Sign-in risk\" must be selected when \"Require password change\" grant and \"Sign-in frequency every time\" session control are selected", "usersAndGroupsPolicyDescription": "User-based policies apply when users access resources directly or through agents acting on the user's behalf", "UserSelectionBlade": { "DirectoryRoles": { "ariaLabel": "Choose directory roles" }, "Excluded": { "gridAria": "List of excluded users" }, "Included": { "gridAria": "List of included users" }, "learnMore": "Control access based on who the policy will apply to, such as users and groups, workload identities, directory roles, or external guests.", "learnMoreAgents": "Control access based on who the policy will apply to, such as users and groups, agents, workload identities, directory roles, or external guests.", "learnMoreAriaLabel": "Learn more about Conditional Access users, groups, and workload identities.", "Validation": { "customRoleIncluded": "\"Directory Roles\" includes at least one custom role", "customRoleSelected": "At least one custom role is selected", "failed": "\"{0}\" must be configured", "roles": "Select at least one role", "usersGroups": "Select at least one user or group" } }, "userSelectionBladeAllUsersAndGroups": "All users and groups", "userSelectionBladeExcludeDescription": "Select the users and groups to exempt from the policy", "userSelectionBladeExcludedSelectorTitle": "Select excluded users and groups", "userSelectionBladeExcludeTabTitle": "Exclude", "userSelectionBladeIncludeDescription": "Select the users this policy will apply to", "userSelectionBladeIncludedSelectorTitle": "Select", "userSelectionBladeIncludeTabTitle": "Include", "userSelectionBladeSelectedUsers": "Select users and groups", "userSelectionBladeSelectUsers": "Select users", "userSelectionBladeTitle": "Users and groups", "userSelectorBladeTitle": "Users", "userSelectorExcluded": "{0} excluded", "userSelectorGroupPlural": "{0} groups", "userSelectorGroupSingular": "1 group", "userSelectorIncluded": "{0} included", "userSelectorInfoBallonText": "Users and groups in the directory that the policy applies to. For example, 'Pilot group'", "userSelectorInfoBalloonAriaLabelAccessibility": "Additional information about user selection", "userSelectorSelected": "{0} selected", "userSelectorTitle": "User", "userSelectorUserAndGroup": "{0}, {1}", "userSelectorUserPlural": "{0} users", "userSelectorUserSingular": "1 user", "userSelectorWithExclusion": "{0} and {1}", "usersGroupsLabel": "Users and groups", "userSPRequired": "User or Service principal required", "userSPSelectorTitle": "User or Workload identity", "ValidationResult": { "blockEveryonePolicy": "Policy configuration not supported. Review the assignments and controls.", "invalidApplicationCondition": "Invalid cloud applications selected", "invalidClientTypesCondition": "Invalid client apps selected", "invalidConditions": "Assignments are not selected", "invalidControls": "Invalid controls selected", "invalidDevicePlatformsCondition": "Invalid device platforms selected", "invalidDevicesCondition": "Invalid device configuration. Likely an invalid \"{0}\" configuration.", "invalidGrantControlPolicy": "Invalid grant control", "invalidLocationsCondition": "Invalid locations selected", "invalidNetworkAccessSecurityPolicyId": "Policy attached to session network control in invalid.", "invalidPolicy": "Assignments are not selected", "invalidSessionControlPolicy": "Invalid session control", "invalidSignInRisksCondition": "Invalid sign-in risk selected", "invalidUserRisksCondition": "Invalid user risk selected", "invalidUsersCondition": "Invalid users selected", "mamPolicyShouldOnlyTargetAndroidIosOrWindowsPlatforms": "MAM policy can only be applied to Android, iOS or Windows client platforms.", "mamPolicyShouldOnlyTargetAndroidOrIosPlatforms": "MAM policy can only be applied to Android or iOS client platforms.", "networkAccessControlNeedsNetworkAccessTargetedTrafficProfile": "Network Access session policy only works correctly when a network access traffic profile is targeted. Please update your targeted resources section.", "notSupportedCombination": "Policy configuration is not supported. Learn more about supported policies.", "pending": "Validating policy", "requireComplianceEveryonePolicy": "Policy configuration will require device compliance for all users. Review the assignments selected.", "success": "Valid policy" }, "verifiedIdInfoBubble": "Users must present a Verified ID and complete Face Check", "viewApprovedAppsText": "See list of approved client apps", "viewCompliantAppsText": "See list of policy protected client apps", "viewPolicyInformation": "View policy information", "vpnAdminConsentButtonText": "Grant admin consent", "vpnAdminConsentRequired": "Admin consent is required for the 'VPN Server' application to complete VPN connectivity setup.", "vpnAdminConsentSuccess": "Admin consent has been successfully granted for the 'VPN Server' application.", "vpnBladeTitle": "VPN connectivity", "VpnCert": { "Grid": { "aria": "List of VPN Certificates" } }, "vpnCertCreateFailedMessage": "Error: {0}", "vpnCertCreateFailedTitle": "Failed to create {0}", "vpnCertCreateInProgressTitle": "Creating {0}", "vpnCertCreateSuccessMessage": "Successfully created {0}.", "vpnCertCreateSuccessTitle": "Successfully created {0}", "vpncertDropdownDefaultOption": "Duration", "vpncertDropdownInfoBalloonContent": "Select the duration for the cert you want to create", "vpncertDropdownLabel": "Select duration", "vpncertDropdownOneyearOption": "1 year", "vpncertDropdownThreeyearOption": "3 years", "vpncertDropdownTwoyearOption": "2 years", "vpnCertNoRowsMessage": "No VPN certificates found", "vpnCertUpdateFailedMessage": "Error: {0}", "vpnCertUpdateFailedTitle": "Failed to update {0}", "vpnCertUpdateInProgressTitle": "Updating {0}", "vpnCertUpdateSuccessMessage": "Successfully updated {0}.", "vpnCertUpdateSuccessTitle": "Successfully updated {0}", "vpnFeatureInfo": "For more information on VPN connectivity and Conditional Access, click here.", "vpnFeatureWarning": "Once a VPN certificate is created in the Azure portal, Microsoft Entra ID will start using it immediately to issue short lived certificates to the VPN client. It is critical that the VPN certificate be deployed immediately to the VPN server to avoid any issues with credential validation of the VPN client.", "vpnMenuText": "VPN connectivity", "WarningsInfo": { "Controls": { "AuthStrengthXtap": { "allUsers": "To enable all authentication strengths, configure cross-tenant access settings to accept claims coming from Microsoft Entra tenants for external users. Authentication strengths will only configure second factor authentication for external users.", "containsOnlyPasskeysAuthApp": "Don't lock your users out. Additional steps might be required to ensure users can register passkeys in Authenticator.", "containsPasskeysAuthApp": "Don't lock your users out. Additional steps might be required to ensure users can register passkeys in Microsoft Authenticator. To require authentication strengths for external users, configure cross-tenant access settings to accept claims from Microsoft Entra tenants.", "externalUsers": "To enable all built-in authentication strengths, configure cross-tenant access settings to accept claims coming from Microsoft Entra tenants for external users.", "nonAuthPhishResistant": "To require phishing-resistant authentication for external users, configure cross-tenant access settings to accept claims from Microsoft Entra tenants." }, "compliantDeviceEnabled": "Don't lock yourself out! Make sure that your device is compliant.", "domainJoinedDeviceEnabled": "Don't lock yourself out! Make sure that your device is Microsoft Entra hybrid joined.", "notAvailableForSP": "Some controls are not available due to '{0}' selection in policy assignment", "requireApprovedClientAppEnabled": "You should no longer use \"Require approved client app\", as we will soon stop updating it.", "requireAuthOrMfa": "\"{0}\" cannot be used with \"{1}\".", "requireMfa": "Consider testing the new \"{0}\".", "requirePasswordChangeEnabled": "\"Require password change\" can only be used when policy is assigned to \"All cloud apps\".", "requirePasswordChangeEnabledResource": "\"Require password change\" can only be used when policy is assigned to \"All resources\".", "requireRiskRemediation": "\"{0}\" can only be used when policy is assigned to \"{1}.\" This option requires multifactor authentication or authentication strengths controls. Other controls cannot be used. This option also requires the Session control \"Sign-in Frequency\" to be set to \"Every time.\"", "vidAmpWarning": "Before creating a Conditional Access policy, make sure Verified ID is turned on as an authentication method." }, "Policies": { "approvedAppMigrationSaveError": "Add at least one grant control, or switch to Block access, to save this policy.", "approvedAppReadOnly": "This policy is read-only because it uses the Require approved client app control. To edit, uncheck this control under Grant. Otherwise you can only disable or delete the policy.", "blockCurrentUserPolicy": "Don't lock yourself out! We recommend applying a policy to a small set of users first to verify it behaves as expected. We also recommend excluding at least one administrator from this policy. This ensures that you still have access and can update a policy if a change is required. Please review the affected users and apps.", "deviceFilterReportOnlyPolicy": "Policies in Report-only mode with device filters configured may prompt users to select a device certificate.", "devicePlatformsReportOnlyPolicy": "Policies in Report-only mode requiring compliant devices may prompt users on macOS, iOS, and Android to select a device certificate.", "excludeCurrentUserSelection": "Exclude current user, {0}, from this policy.", "excludeDevicePlatforms": "Exclude device platforms macOS, iOS, and Android from this policy.", "Linux": { "devicePlatformsReportOnlyPolicy": "Policies in Report-only mode requiring compliant devices may prompt users on macOS, iOS, Android, and Linux to select a device certificate.", "excludeDevicePlatforms": "Exclude device platforms macOS, iOS, Android, and Linux from this policy.", "proceedAnywayDevicePlatforms": "Proceed with selected configuration. Users on macOS, iOS, Android, and Linux may receive prompts when the device is checked for compliance." }, "microsoftAdminPortals": "Microsoft admin portals, including Microsoft 365 admin center and Azure portal, will be excluded from this policy. We recommend ensuring that admin portals are protected by a Conditional Access policy that requires admins to use multifactor authentication.", "preventCatastrophicAuthStrength": "Don't lock yourself out! Your current user is not capable of satisfying the selected Authentication Strength policy, '{0}'. We also recommend excluding at least one administrator from this policy. This ensures that you still have access and can update a policy if a change is required. Please review the affected users and authentication strengths.", "proceedAnywayDevicePlatforms": "Proceed with selected configuration. Users on macOS, iOS, and Android may receive prompts when the device is checked for compliance.", "proceedAnywaySelection": "I understand that my account will be impacted by this policy. Proceed anyway." }, "ServicePrincipals": { "blockExchange": "Selecting Office 365 Exchange Online will also affect apps such as OneDrive and Teams.", "blockPortal": "Don't lock yourself out! This policy impacts the Azure portal. Before you continue, ensure that you or someone else will be able to get back into the portal.", "blockPortalWithSession": "Don't lock yourself out! This policy impacts the Azure portal. Before you continue, ensure that you or someone else will be able to get back into the portal.
Disregard this warning if you are configuring persistent browser session policy that works correctly only if \"All cloud apps\" are selected.", "blockPortalWithSessionGSAGovParity": "Don't lock yourself out! This policy impacts the Azure portal. Before you continue, ensure that you or someone else will be able to get back into the portal.
Disregard this warning if you are configuring persistent browser session policy that works correctly only if \"All resources\" are selected.", "blockSharePoint": "Selecting SharePoint Online will also affect apps such as Microsoft Teams, Planner, Delve, MyAnalytics, and Newsfeed.", "blockSkype": "Selecting Skype for Business Online will also affect Microsoft Teams.", "includeOrExclude": "You can configure the App Filter for '{0}' or '{1}', but not both.", "selectAppsNAForSP": "Individual cloud apps cannot be selected due to '{0}' selection in policy assignment", "teamsBlocked": "Microsoft Teams will also be affected when apps such as SharePoint Online and Exchange Online are included in policy." }, "Users": { "blockAllUsers": "Don't lock yourself out! This policy will affect all of your users. We recommend applying a policy to a small set of users first to verify it behaves as expected.", "xtap": " Your \"Require authentication strengths\" configuration in grant control might not be valid for external users." } }, "wednesday": "Wednesday", "WhatIf": { "Device": { "AttributesGrid": { "aria": "List of attributes on the device employed during sign-in.", "infoBalloon": "List of attributes on the device employed during sign-in." } }, "noTenantSelected": "No tenant selected", "revertWhatIfPreview": "To revert to the classic 'What if' experience, click here. ", "selectOrganization": "Select organization", "tenantIdWithPlaceholder": "Tenant ID: {0}", "tenantSelectionRequired": "Tenant required", "tryWhatIfPreview": "Try the new 'What If' experience powered by Microsoft Graph to test the impact of Conditional Access policies which include conditions such as insider risk and authentication flows. To turn on this preview feature, click here." }, "whatIfAppEnforcedControl": "Use app enforced restrictions", "WhatIfBlade": { "authenticationStrength": "Authentication strength", "ClientApp": { "easSupported": "Mobile apps and desktop clients - Exchange ActiveSync clients (supported platforms)", "easUnsupported": "Mobile apps and desktop clients - Exchange ActiveSync clients (unsupported platforms)", "native": "Mobile apps and desktop clients - Modern authentication clients", "otherLegacy": "Mobile apps and desktop clients - Other clients" }, "DeviceState": { "compliant": "Device marked as compliant", "hybrid": "Device Microsoft Entra hybrid joined", "selectDeviceState": "Select device state..." }, "Filters": { "evaluationProblem": "There was a problem evaluating the filter on at least one policy. These policies may not have the correct evaluation result.", "header": "Has filter", "info": "Whether the policy has a filter on custom security attributes.", "problem": "Problem", "readingProblem": "There was a problem reading attributes on the selected Workload Identity or Cloud App. These policies may not have the correct evaluation result.", "separator": ", ", "warning": "Some of your Conditional Access policies use a filter with custom security attributes. For the What-if tool to correctly evaluate these policies, make sure you have access to read attribute assignments for the following attribute set(s):" }, "Grid": { "Applied": { "ariaLabel": "List of Conditional Access policies which applied to the sign-in." }, "NotApplied": { "ariaLabel": "List of Conditional Access policies which did not apply to the sign-in." } }, "loadingPermissions": "Loading permissions..." }, "whatIfBladeDescription": "Test the impact of Conditional Access on a user when signing in under certain conditions.", "whatIfBladeTitle": "What If", "whatIfClassicPoliciesWarning": "Classic policies are not evaluated by this tool.", "whatIfClientAppInfo": "The client app the user is signing in from. For example, 'Browser'.", "whatIfCountry": "Country", "whatIfCountryInfo": "The country the user is signing in from.", "whatIfDateTimeInfo": "Date and time the user is signing in.", "whatIfDateTimeInfoBoxText": "If using \"Time zone\" or \"Date and Time\", both fields will be required.", "whatIfDevicePlatformInfo": "The device platform the user is signing in from.", "whatIfDeviceStateInfo": "The device state the user is signing in from", "whatIfEnterIpAddress": "Enter IP address (ex: 40.77.182.32)", "whatIfErrorInvalidIpAddress": "An invalid IP address was specified.", "whatIfEvaResultApplication": "Cloud apps", "whatIfEvaResultClientApps": "Client app", "whatIfEvaResultDevicePlatform": "Device platform", "whatIfEvaResultEmptyPolicy": "Empty policy", "whatIfEvaResultInvalidCondition": "Invalid condition", "whatIfEvaResultInvalidPolicy": "Invalid policy", "whatIfEvaResultLocation": "Location", "whatIfEvaResultNotEnoughInformation": "Not enough information", "whatIfEvaResultPolicyNotEnabled": "Policy not enabled", "whatIfEvaResultSignInRisk": "Sign-in risk", "whatIfEvaResultTime": "Time", "whatIfEvaResultUsers": "Users and groups", "whatIfFormat": "{0} - {1}", "whatIfInsiderRiskInfo": "Insider risk that's assigned to user.", "whatIfIpAddress": "IP address", "whatIfIpAddressInfo": "IP address the user is signing in from.", "whatIfIpCountryInfoBoxText": "If using an IP address or Country, both fields will be required and should correctly map together.", "whatIfPolicyAppliesTab": "Policies that will apply", "whatIfPolicyAppliesTabWithCount": "Applicable policies ({0})", "whatIfPolicyDoesNotApplyTab": "Policies that will not apply", "whatIfPolicyDoesNotApplyTabWithCount": "Inapplicable policies ({0})", "whatIfPreviewTitle": "What If (Preview)", "whatIfReasons": "Reasons why this policy will not apply", "whatIfSelectAuthenticationFlow": "Select authentication flow...", "whatIfSelectClientApp": "Select a client app...", "whatIfSelectCountry": "Select country...", "whatIfSelectDateTime": "Date and time", "whatIfSelectDevicePlatform": "Select device platform...", "whatIfSelectInsiderRisk": "Select Insider risk...", "whatIfSelectPrivateLink": "Select private link...", "whatIfSelectServicePrincipalRisk": "Select service principal risk...", "whatIfSelectSignInRisk": "Select sign-in risk...", "whatIfSelectType": "Select identity type", "whatIfSelectUserRisk": "Select user risk...", "whatIfServicePrincipalRiskInfo": "The risk level associated with the service principal", "whatIfSignInRisk": "Sign-in risk", "whatIfSignInRiskInfo": "The risk level associated with the sign-in", "whatIfTimezoneInfo": "Time zone the user is signing in from.", "whatIfUnknownAreas": "Unknown Areas", "whatIfUserPickerLabel": "Selected user", "whatIfUserPickerNoRowsLabel": "No user or service principal selected", "whatIfUserRiskInfo": "The risk level associated with the user", "whatIfUserSelectorInfo": "User in the directory that you want to test", "windows365InfoBox": "Selecting Windows 365 will affect connections to Cloud PCs and Azure Virtual Desktop session hosts.", "windowsDisplayName": "Windows", "windowsPhoneDisplayName": "Windows Phone", "workloadIdentities": "Workload identities", "workloadIdentitiesLicenseText": "A workload identities premium license is required to edit this policy.", "workloadIdentitiesPreview": "Workload identities (preview)", "workloadIdentity": "Workload identity" }, "AzureIAM": { "advancedTabText": "Advanced", "allCloudAppsErrorBox": "\"All cloud apps\" must be selected when \"Require password change\" grant is selected", "allCloudAppsReauth": "\"All cloud apps\" must be selected when \"Sign-in frequency every time\" session control and \"sign-in risk\" condition are selected", "allCloudOrSpecificApps": "The \"sign-in frequency every time\" session control requires \"all cloud apps\" or specifically-supported apps to be selected", "allDayCheckboxLabel": "All day", "allDevicePlatforms": "Any device", "allGuestUserInfoContent": "Includes Microsoft Entra B2B guests, but not SharePoint B2B guests", "allGuestUserLabel": "All guest and external users", "allRiskLevelsOption": "All risk levels", "allTrustedLocationLabel": "All trusted locations", "allUserGroupSetSelectorLabel": "All users and groups selected", "allUsersReauth": "The \"sign-in frequency every time\" session control requires \"All Users\" to be selected", "allUsersString": "All users", "and": "{0} AND {1} ", "androidDisplayName": "Android", "andWithGrouping": "({0}) AND {1} ", "anyCloudAppSelection": "Any cloud app", "appContextOptionInfoContent": "Requested authentication tag", "appContextOptionLabel": "Requested authentication tag (Preview)", "appContextUriPlaceholder": "Example: uri:contoso.com:level3", "appEnforceInfoBubble": "App enforced restrictions might require additional admin configurations within the cloud apps. The restrictions will only take effect for new sessions.", "applyConditionClientAppInfoBalloonContent": "Configure client apps to apply the policy to specific client apps", "applyConditionDevicePlatformInfoBalloonContent": "Configure device platforms to apply the policy to specific platforms", "applyConditionDeviceStateInfoBalloonContent": "Configure device state to apply the policy to specific device state(s)", "applyConditionLocationInfoBalloonContent": "Configure locations to apply the policy to trusted/untrusted locations", "applyConditionSigninRiskInfoBalloonContent": "Configure sign-in risk to apply the policy to selected risk level(s)", "applyConditionUserRiskInfoBalloonContent": "Configure user risk to apply the policy to selected risk level(s)", "applyConditonLabel": "Configure", "appNotSetSeletorLabel": "0 cloud apps selected", "appReauthNotSupported": "This app does not support the \"sign-in frequency every time\" session control.", "ariaLabelPolicyDisabled": "Policy is disabled", "ariaLabelPolicyEnabled": "Policy is enabled", "ariaLabelPolicyReportOnly": "Policy is in Report-only mode", "AuthContext": { "Delete": { "failure": "Failed to delete {0}", "failureCa": "Failed to delete {0} because it is referenced by CA policies", "modifying": "Deleting {0}", "success": "Successfully deleted {0}" }, "menuLabel": "Authentication context", "Notify": { "failure": "Failed to update {0}", "modifying": "Modifying {0}", "success": "Successfully updated {0}" } }, "blockAccess": "Block access", "builtInDirectoryRoleLabel": "Built-in directory roles", "casCustomControlInfo": "Custom policies need to be configured in Cloud App Security portal. This control works instantly for featured apps and can be self onboarded for any app. Click here to learn more about both scenarios.", "casInfoBubble": "This control works for various cloud apps.", "casPreconfiguredControlInfo": "This control works instantly for featured apps and can be self onboarded for any app. Click here to learn more about both scenarios.", "cert64DownloadCol": "Download base64 certificate", "cert64Name": "VpnBase64Cert", "certainApps": "Only specifically-supported apps are enabled for \"Sign-in frequency every time\" if \"Require multifactor authentication\" and \"Require password change\" grants are not selected", "certDownloadCol": "Download certificate", "certDurationCol": "Expiry", "certDurationStartCol": "Valid from", "certName": "VpnCert", "chooseApplicationsBladeSubtitle": "", "chooseApplicationsBladeTitle": "Choose Applications", "chooseApplicationsCartSubitle": "", "chooseApplicationsCartTitle": "Chosen Applications", "chooseApplicationsEmpty": "No Applications", "chooseApplicationsNone": "None", "chooseApplicationsNoneFound": "We didn't find \"{0}\". Try another name or ID.", "chooseApplicationsPlural": "{0} and {1} more", "chooseApplicationsReAuthEverytimeInfo": "Looking for your app? Some applications cannot be used with \"Require reauthentication – every time\" session control", "chooseApplicationsRemove": "Remove", "chooseApplicationsReturnedPlural": "{0} applications found", "chooseApplicationsReturnedSingular": "1 application found", "chooseApplicationsSearchBalloon": "Search for an Application by entering its name or ID.", "chooseApplicationsSearchHint": "Search Applications...", "chooseApplicationsSearching": "Searching...", "chooseApplicationsSearchLabel": "Applications", "chooseApplicationsSelect": "Select", "chooseApplicationsSelected": "Selected", "chooseApplicationsSingular": "{0} and 1 more", "chooseApplicationsTooMany": "More results than can be shown. Please filter using the search box.", "chooseLocationCorpnetItem": "Corporate network", "chooseLocationsBladeSubtitle": "", "chooseLocationsBladeTitle": "Choose Locations", "chooseLocationsCartSubitle": "", "chooseLocationsCartTitle": "Chosen Locations", "chooseLocationSelectedLocationsLabel": "Selected locations", "chooseLocationsEmpty": "No Locations", "chooseLocationsExcludedSelectorTitle": "Select", "chooseLocationsIncludedSelectorTitle": "Select", "chooseLocationsNone": "None", "chooseLocationsNoneFound": "We didn't find \"{0}\". Try another name or ID.", "chooseLocationsPlural": "{0} and {1} more", "chooseLocationsRemove": "Remove", "chooseLocationsReturnedPlural": "{0} locations found", "chooseLocationsReturnedSingular": "1 location found", "chooseLocationsSearchBalloon": "Search for a Location by entering its name.", "chooseLocationsSearchHint": "Search Locations...", "chooseLocationsSearching": "Searching...", "chooseLocationsSearchLabel": "Locations", "chooseLocationsSelect": "Select", "chooseLocationsSelected": "Selected", "chooseLocationsSelectionBladeExcludedSelectorTitle": "Select", "chooseLocationsSelectionBladeIncludedSelectorTitle": "Select", "chooseLocationsSingular": "{0} and 1 more", "chooseLocationsTooMany": "More results than can be shown. Please filter using the search box.", "chooseLocationTrustedIpsItem": "Multifactor authentication trusted IPs", "claimProviderAddCommandText": "New custom control", "claimProviderAddNewBladeTitle": "New custom control", "claimProviderDeleteCommand": "Delete", "claimProviderDeleteDescription": "Are you sure you want to delete '{0}'? This action cannot be undone.", "claimProviderDeleteTitle": "Are you sure?", "claimProviderEditInfoText": "Enter the JSON for customized controls given by your claim providers.", "claimProviderNotificationCreateDescription": "Creating custom control named '{0}'", "claimProviderNotificationCreateFailedDescription": "Creating custom control '{0}' failed. Please try again later.", "claimProviderNotificationCreateFailedTitle": "Failed to create custom control", "claimProviderNotificationCreateSuccessDescription": "Created custom control named '{0}'", "claimProviderNotificationCreateSuccessTitle": "Created '{0}'", "claimProviderNotificationCreateTitle": "Creating '{0}'", "claimProviderNotificationDeleteDescription": "Deleting custom control named '{0}'", "claimProviderNotificationDeleteFailedDescription": "Deleting custom control '{0}' failed. Please try again later.", "claimProviderNotificationDeleteFailedTitle": "Failed to delete custom control", "claimProviderNotificationDeleteSuccessDescription": "Deleted custom control named '{0}'", "claimProviderNotificationDeleteSuccessTitle": "Deleted '{0}'", "claimProviderNotificationDeleteTitle": "Deleting '{0}'", "claimProviderNotificationUpdateDescription": "Updating custom control named '{0}'", "claimProviderNotificationUpdateFailedDescription": "Updating custom control '{0}' failed. Please try again later.", "claimProviderNotificationUpdateFailedTitle": "Failed to update custom control", "claimProviderNotificationUpdateSuccessDescription": "Updated custom control named '{0}'", "claimProviderNotificationUpdateSuccessTitle": "Updated '{0}'", "claimProviderNotificationUpdateTitle": "Updating '{0}'", "claimProvidersNone": "No custom controls", "claimProvidersSearchPlaceholder": "Search controls.", "claimProviderValidationAppIdInvalid": "The \"AppId\" value is not valid. Please review and try again.", "claimProviderValidationClientIdMissing": "The data is missing a \"ClientId\" value. Please review and try again.", "claimProviderValidationControlClaimsRequestedMissing": "The \"Control\" is missing a \"ClaimsRequested\" value. Please review and try again.", "claimProviderValidationControlClaimsRequestedTypeMissing": "The \"ClaimsRequested\" item is missing a \"Type\" value. Please review and try again.", "claimProviderValidationControlIdAlreadyExists": "The \"Control\" \"Id\" value already exists. Please review and try again.", "claimProviderValidationControlIdMissing": "The \"Control\" is missing an \"Id\" value. Please review and try again.", "claimProviderValidationControlIdReferencedInExistingPolicy": "The \"Control\" \"Id\" value cannot be removed because it is referenced in an existing policy. Please remove it from the policy first.", "claimProviderValidationControlIdTooManyControls": "The \"Control\" property has too many controls. Please review and try again.", "claimProviderValidationControlIdValueReserved": "The \"Control\" \"Id\" value is a reserved keyword, please use a different id.", "claimProviderValidationControlNameAlreadyExists": "The \"Control\" \"Name\" value already exists. Please review and try again.", "claimProviderValidationControlNameMissing": "The \"Control\" is missing a \"Name\" value. Please review and try again.", "claimProviderValidationControlsMissing": "The data is missing a \"Controls\" value. Please review and try again.", "claimProviderValidationDiscoveryUrlMissing": "The data is missing a \"DiscoveryUrl\" value. Please review and try again.", "claimProviderValidationInvalid": "There data provided is not valid. Please review and try again.", "claimProviderValidationInvalidJsonDefinition": "Unable to save the custom control. Review the JSON text and try again.", "claimProviderValidationNameAlreadyExists": "The \"Name\" value already exists. Please review and try again.", "claimProviderValidationNameMissing": "The data is missing a \"Name\" value. Please review and try again.", "claimProviderValidationUnknown": "There was an unknown error while validating the data provided. Please review and try again.", "classicPoilcyFilterTitle": "Show", "classicPolicyAllPlatforms": "All Platforms", "classicPolicyClientAppBrowserAndNative": "Browser, mobile apps and desktop clients", "classicPolicyCloudAppTitle": "Cloud application", "classicPolicyControlAllow": "Allow", "classicPolicyControlBlock": "Block", "classicPolicyControlBlockWhenNotAtWork": "Block access when not at work", "classicPolicyControlRequireCompliantDevice": "Require compliant device", "classicPolicyControlRequireDomainJoinedDevice": "Require domain joined device", "classicPolicyControlRequireMfa": "Require multifactor authentication", "classicPolicyControlRequireMfaWhenNotAtWork": "Require multifactor authentication when not at work", "classicPolicyDeleteCommand": "Delete", "classicPolicyDeleteFailTitle": "Failed to delete classic policy", "classicPolicyDeleteInProgressTitle": "Deleting classic policy", "classicPolicyDeleteSuccessTitle": "Classic policy deleted", "classicPolicyDetailBladeTitle": "Details", "classicPolicyDisableCommand": "Disable", "classicPolicyDisableConfirmation": "Are you sure you want to disable '{0}'? This action cannot be undone.", "classicPolicyDisableFailDescription": "Failed to disable '{0}'", "classicPolicyDisableFailTitle": "Failed to disable classic policy", "classicPolicyDisableInProgressDescription": "Disabling '{0}'", "classicPolicyDisableInProgressTitle": "Disabling classic policy", "classicPolicyDisableSuccessDescription": "Successfully disabled '{0}'", "classicPolicyDisableSuccessTitle": "Classic policy disabled", "classicPolicyEasSupportedPlatforms": "Exchange ActiveSync supported platforms", "classicPolicyEasUnsupportedPlatforms": "Exchange ActiveSync unsupported platforms", "classicPolicyExcludedPlatformsTitle": "Excluded device platforms", "classicPolicyFilterAll": "All policies", "classicPolicyFilterDisabled": "Disabled policies", "classicPolicyFilterEnabled": "Enabled policies", "classicPolicyIncludedPlatformsTitle": "Included device platforms", "classicPolicyIncludeExcludeMembersDescription": "By excluding groups, you can perform phased migration of policies.", "classicPolicyIncludeExcludeMembersTitle": "Include/exclude groups", "classicPolicyManualMigrationMessage": "This policy needs to be migrated manually.", "classicPolicyMigrateCommand": "Migrate", "classicPolicyMigrateConfirmation": "Are you sure you want to migrate '{0}'? This policy can only be migrated once.", "classicPolicyMigratedSuccessDescription": "This classic policy can now be managed under Polices.", "classicPolicyMigratedSuccessDescriptionMultiple": "This classic policy is migrated as {0} new policies. New policies can be managed under Policies.", "classicPolicyMigrateFailDescription": "Failed to migrate '{0}'", "classicPolicyMigrateFailTitle": "Failed to migrate classic policy", "classicPolicyMigrateInProgressDescription": "Migrating '{0}'", "classicPolicyMigrateInProgressTitle": "Migrating classic policy", "classicPolicyMigrateRecommendText": "Recommendation: Migrate to the new Azure portal policies.", "classicPolicyMigrateSuccessTitle": "Classic policy migrated successfully", "classicPolicyNoEditPermissionMsg": "You don't have permission to edit this policy. Only global administrators and security administrators can edit the policy. Click here for more information.", "classicPolicySaveFailDescription": "Failed to save '{0}'", "classicPolicySaveFailTitle": "Failed to save classic policy", "classicPolicySaveInProgressDescription": "Saving '{0}'", "classicPolicySaveInProgressTitle": "Saving classic policy", "classicPolicySaveSuccessDescription": "Successfully saved '{0}'", "classicPolicySaveSuccessTitle": "Classic policy saved", "clientAppBladeLegacyInfoBanner": "Legacy auth is currently not supported", "clientAppBladeLegacyUpsellBanner": "Block unsupported client apps (Preview)", "clientAppBladeTitle": "Client apps", "clientAppDescription": "Select the client apps this policy will apply to", "clientAppExchangeActiveSync": "Exchange ActiveSync", "clientAppExchangeWarning": "Exchange ActiveSync currently does not support all other conditions", "clientAppLearnMore": "Control user access to target specific client applications not using modern authentication.", "clientAppLegacyHeader": "Legacy authentication clients", "clientAppMobileDesktop": "Mobile apps and desktop clients", "clientAppModernHeader": "Modern authentication clients", "clientAppOnlySupportedPlatforms": "Apply policy only to supported platforms", "clientAppSelectSpecificClientApps": "Select client apps", "clientAppsSelectedLabel": "{0} included", "clientAppWebBrowser": "Browser", "clientTypeBrowser": "Browser", "clientTypeEas": "Exchange ActiveSync clients", "clientTypeEasInfo": "Exchange ActiveSync clients that use legacy authentication only.", "clientTypeModernAuth": "Modern authentication clients", "clientTypeOtherClients": "Other clients", "clientTypeOtherClientsInfo": "This includes older office clients and other mail protocols(POP, IMAP, SMTP, etc). [Learn more][1]\n[1]: https://aka.ms/caclientapps\n", "cloudAppCountDiffBannerText": "{0} cloud apps configured in this policy have been deleted from the directory, but this doesn't affect the other apps in the policy. The next time you update the application section of the policy, the deleted apps will be automatically removed from it.", "cloudappsSelectionBladeAllCloudapps": "All cloud apps", "cloudAppsSelectionBladeAllMicrosoftApps": "All Microsoft apps", "cloudappsSelectionBladeExcludeDescription": "Select the cloud apps to exempt from the policy", "cloudappsSelectionBladeExcludedSelectorTitle": "Select excluded cloud apps", "cloudappsSelectionBladeIncludeDescription": "Select the cloud apps this policy will apply to", "cloudappsSelectionBladeIncludedSelectorTitle": "Select", "cloudappsSelectionBladeSelectedCloudapps": "Select apps", "cloudAppsSelectionExcludeAllMicrosoftClients": "Allow Microsoft cloud, desktop and mobile apps (Preview)", "cloudappsSelectorInfoBallonText": "Services which the user accesses to do work. For example, 'Salesforce'", "cloudappsSelectorPluralExcluded": "{0} apps excluded", "cloudappsSelectorPluralIncluded": "{0} apps included", "cloudappsSelectorSingularExcluded": "1 app excluded", "cloudappsSelectorSingularIncluded": "1 app included", "cloudappsSelectorUserPlural": "{0} apps", "cloudappsSelectorUserSingular": "1 app", "conditionalAccessBladeTitle": "Conditional Access", "conditionLabelMulti": "{0} conditions selected", "conditionLabelOne": "1 condition selected", "conditionsNotSelectedLabel": "Not configured", "conditionsReqMfaReauthSet": "Some options are not available due to the \"Require multifactor authentication\" grant and \"sign-in frequency every time\" session control currently being selected", "conditionsReqPwSet": "Some options are not available due to the \"Require password change\" grant currently being selected", "configureCasText": "Configure Cloud App Security", "configureCustomControlsText": "Configure custom policy", "controlLabelMulti": "{0} controls selected", "controlLabelOne": "1 control selected", "controlsBlockAccessInfoBubble": "ControlsBlockAccessInfoBubble", "controlsDeviceComplianceAriaLabel": "Learn more about requiring compliant devices.", "controlsDeviceComplianceInfoBubble": "Device must be Intune compliant. If the device is non-compliant, the user will be prompted to bring the device under compliance.", "controlsDomainJoinedAriaLabel": "Learn more about requiring Microsoft Entra hybrid joined devices.", "controlsDomainJoinedInfoBubble": "Devices must be Microsoft Entra hybrid joined.", "controlsMamAriaLabel": "Learn more about requiring approved client applications.", "controlsMamInfoBubble": "Device must use these approved client applications.", "controlsMfaInfoBubble": "User must complete additional security requirements like phone call, text", "controlsOrAndInfoBubble": "ControlsOrAndInfoBubble", "controlsRequireCompliantAppAriaLabel": "Learn more about requiring policy protected apps.", "controlsRequireCompliantAppInfoBubble": "Device must use policy protected apps.", "controlsRequirePasswordResetAriaLabel": "Learn more about requiring a password change.", "controlsRequirePasswordResetInfoBubble": "Require password change to lower user risk. This option also requires multifactor authentication. Other controls can't be used.", "controlValidatorText": "Please select at least one control", "countriesRadiobuttonInfoBalloonContent": "The country/region a sign-in is coming from is determined by the user's IP address.", "createdTimeLabel": "Creation time", "createNewVpnCert": "New certificate", "customRoleLabel": "Custom roles (not supported)", "dateRangeTypeLabel": "Date range", "daysOfWeekPlaceholderText": "Filter days of the week", "daysOfWeekTypeLabel": "Days of the week", "deletePolicyNoLicenseText": "You can delete this policy now. Once deleted you will not be able to recreate it until you have the required licenses.", "descriptionContentForControlsAndOr": "For multiple controls", "devicePlatform": "Device platform", "devicePlatformConditionHelpDescription": "Apply policy to selected device platforms.\n[Learn more][1]\n[1]: https://go.microsoft.com/fwlink/?linkid=2044750", "devicePlatformInclude": "{0} included", "devicePlatformIncludeExclude": "{0} and {1} excluded", "devicePlatformNoSelectionError": "Select device platforms requires one sub-item to be selected.", "devicePlatformsNone": "None", "deviceSelectionBladeExcludeDescription": "Select the platforms to exempt from the policy", "deviceSelectionBladeIncludeDescription": "Select the device platforms to include in this policy", "deviceStateAll": "All device state", "deviceStateCompliant": "Device marked as compliant", "deviceStateCompliantInfoContent": "Devices that are Intune compliant will be excluded from the evaluation of this policy, so for example if the policy blocks access it will block all devices except devices that are Intune compliant.", "deviceStateConditionConfigureInfoContent": "Configure policy based on device state", "deviceStateConditionSelectorInfoContent": "Whether the device the user is signing in from is 'Microsoft Entra hybrid joined' or 'marked as compliant'.\n This has been deprecated. Use '{1}' instead.", "deviceStateConditionSelectorLabel": "Device state (deprecated)", "deviceStateDomainJoined": "Device Microsoft Entra hybrid joined", "deviceStateDomainJoinedInfoContent": "Devices that are Microsoft Entra hybrid joined will be excluded from the evaluation of this policy, so for example if the policy blocks access it will block all devices except devices that are Microsoft Entra hybrid joined.", "deviceStateDomainJoinedInfoLinkText": "Learn more.", "deviceStateExcludeDescription": "Select the device state condition used to exclude devices from policy.", "deviceStateIncludeAndExcludeOneLabel": "{0} and exclude {1}", "deviceStateIncludeAndExcludeTwoLabel": "{0} and exclude {1}, {2}", "directoryRoleInfoContent": "Assign policy to built-in directory roles.", "directoryRolesLabel": "Directory roles", "discardbutton": "Discard", "downloadDefaultFileName": "IP Ranges", "downloadExampleFileName": "Example", "downloadExampleHeader": "This is an example file with demonstrations of the kinds of data which can be accepted. Lines starting with # will be ignored.", "duplicate": "Duplicate", "duplicatePolicyName": "{0} COPY", "endDatePickerLabel": "Ends", "endTimePickerLabel": "End time", "enterCountryText": "IP address and Country/Region are evaluated in a pair. Select the Country.", "enterIpText": "IP address and Country/Region are evaluated in a pair. Input the IP address.", "enterUserText": "No user is selected. Select a user.", "evaluationResult": "Evaluation result", "exchangeActiveSyncSelectedLabel": "Exchange ActiveSync", "exchangeActiveSyncSupportedPlatformOnlySelectedLabel": "Exchange ActiveSync with supported platforms only", "excludeAllTrustedLocationSelectorText": "all trusted locations", "featureRequiresP2": "This feature requires Microsoft Entra ID P2 license.", "friday": "Friday", "grantControls": "Grant controls", "gridNetworkTrusted": "Trusted", "gridPolicyCreatedDateTime": "Creation Date", "gridPolicyEnabled": "Enabled", "gridPolicyModifiedDateTime": "Modified Date", "gridPolicyName": "Policy Name", "gridPolicyState": "State", "groupSelectionBladeExcludeDescription": "Select the groups to exempt from the policy", "groupSelectionBladeExcludedSelectorTitle": "Select excluded groups", "groupSelectionBladeSelect": "Select groups", "groupSelectorInfoBallonText": "Groups in the directory that the policy applies to. For example, 'Pilot group'", "groupsSelectionBladeTitle": "Groups", "helpCommonScenariosText": "Interested in common scenarios?", "helpCondition1": "When any user is outside the company network", "helpCondition2": "When users in the 'Managers' group sign-in", "helpConditionsTitle": "Conditions", "helpControl1": "They're required to sign in with multifactor authentication", "helpControl2": "They are required be on an Intune compliant or domain-joined device", "helpControlsTitle": "Controls", "helpIntroText": "Conditional Access gives you the ability to enforce access requirements when specific conditions occur. Let's take a few examples", "helpIntroTitle": "What is Conditional Access?", "helpLearnMoreText": "Want to learn more about Conditional Access?", "helpStartStep1": "Create your first policy by clicking \"+ New policy\"", "helpStartStep2": "Specify policy Conditions and Controls", "helpStartStep3": "When you are done, don't forget to Enable policy and Create", "helpStartTitle": "Get started", "highRisk": "High", "includeAndExcludeAppsTextFormat": "Include: {0}. Exclude: {1}.", "includeAppsTextFormat": "Include: {0}.", "includeUnknownAreasCheckboxInfoBalloonContent": "Unknown areas are IP addresses that can't be mapped to a country/region.", "includeUnknownAreasCheckboxLabel": "Include unknown areas", "infoCommandLabel": "Info", "invalidCertDuration": "Invalid cert duration", "invalidIpAddress": "Value must be a valid IP address", "invalidReAuthSignInRiskOptionSelected": "The \"sign-in frequency every time\" session control does not allow the \"no risk\" selection in the \"sign-in risk\" condition control.", "invalidUriErrorMsg": "Please enter a valid Uri. For example,'uri:contoso.com:acr' ", "iosDisplayName": "iOS", "linuxDisplayName": "Linux", "loadAll": "Load all", "loading": "Loading...", "locationConfigureNamedLocationsText": "Configure all trusted locations", "locationConfigureNamedLocationsUri": "{0}/usermanagement/mfasettings.aspx?tenantid={1}&culture={2}", "locationNameTooLongError": "Location name is too long. Maximum is 256 characters", "locationsAllLocationsLabel": "Any location", "locationsAllNamedLocationsLabel": "All trusted IPs", "locationsAllPrivateLinksLabel": "All Private Links in my tenant", "locationSelectionBladeExcludeDescription": "Select the locations to exempt from the policy", "locationSelectionBladeIncludeDescription": "Select the locations to include in this policy", "locationsIncludeExcludeLabel": "{0} and exclude all trusted IPs", "locationsSelectedPrivateLinksLabel": "Selected Private Links", "lowRisk": "Low", "macOsDisplayName": "macOS", "managePoliciesLicenseText": "To manage Conditional Access policies, your organization needs Microsoft Entra ID P1 or P2.", "manageSecurityDefaultsAriaLabel": "Manage security defaults settings.", "markAsTrustedCheckboxInfoBalloonContent": "Signing in from a trusted location lowers a user's sign-in risk. Only mark this location as trusted if you know the IP ranges entered are established and credible in your organization.", "markAsTrustedCheckboxLabel": "Mark as trusted location", "mediumRisk": "Medium", "memberSelectionCommandRemove": "Remove", "menuItemClaimProviderControls": "Custom controls (Preview)", "menuItemClassicPolicies": "Classic policies", "menuItemInsightsAndReporting": "Insights and reporting", "menuItemManage": "Manage", "menuItemNamedLocationsPreview": "Named locations (Preview)", "menuItemNamedNetworks": "Named locations", "menuItemPolicies": "Policies", "menuItemTermsOfUse": "Terms of use", "modifiedTimeLabel": "Modified time", "monday": "Monday", "namedLocationCountryInfoBanner": "Only IPv4 addresses are mapped to countries/regions. IPv6 addresses are included in unknown countries/regions.", "namedLocationsHelpDescription": "Named locations are used by Microsoft Entra ID security reports to reduce false positives and Microsoft Entra Conditional Access policies.\n[Learn more][1]\n[1]: https://aka.ms/namedlocationupdate", "namedLocationTypeCountry": "Countries/Regions", "namedLocationTypeLabel": "Define the location using:", "namedLocationUpsellBanner": "This view has been deprecated. Go to the new and improved 'Named locations' view.", "namedNetworkAddIpRanges": "Add a new IP range (ex: 40.77.182.32/27)", "namedNetworkCountryNeeded": "You need to select at least one country/region", "namedNetworkDeleteCommand": "Delete", "namedNetworkDeleteDescription": "Are you sure you want to delete '{0}'? This action cannot be undone.", "namedNetworkDeleteTitle": "Are you sure?", "namedNetworkDownloadIpRange": "Download", "namednetworkExceedingSizeErrorBladeTitle": "Error details", "namednetworkExceedingSizeErrorDetailText": "Click here for more details.", "namednetworkExceedingSizeErrorMessage": "You have exceeded the maximum allowed storage for named locations. Try again with a shorter list. Click here to view more details.", "namedNetworkInvalidRange": "Value must be a valid IP range.", "namedNetworkIpRangeNeeded": "You need at least one valid IP range", "namedNetworkIpRangesDescriptionContent": "Configure your organization's IP ranges", "namedNetworkIpRangesTab": "IP ranges", "namedNetworkListAdd": "New location", "namedNetworkListConfigureTrustedIps": "Configure multifactor authentication trusted IPs", "namedNetworkNameDescription": "Example: 'Redmond office'", "namedNetworkNameInvalid": "The supplied name is invalid.", "namedNetworkNameRequired": "You must supply a name for this location.", "namedNetworkNoIpRanges": "No IP ranges", "namedNetworkNotificationCreateDescription": "Creating location named '{0}'", "namedNetworkNotificationCreateFailedDescription": "Creating location '{0}' failed. Please try again later.", "namedNetworkNotificationCreateFailedTitle": "Failed to create location", "namedNetworkNotificationCreateSuccessDescription": "Created location named '{0}'", "namedNetworkNotificationCreateSuccessTitle": "Created '{0}'", "namedNetworkNotificationCreateTitle": "Creating '{0}'", "namedNetworkNotificationDeleteDescription": "Deleting location named '{0}'", "namedNetworkNotificationDeleteFailedDescription": "Deleting location '{0}' failed. Please try again later.", "namedNetworkNotificationDeleteFailedTitle": "Failed to Delete location", "namedNetworkNotificationDeleteSuccessDescription": "Deleted location named '{0}'", "namedNetworkNotificationDeleteSuccessTitle": "Deleted '{0}'", "namedNetworkNotificationDeleteTitle": "Deleting '{0}'", "namedNetworkNotificationUpdateDescription": "Updating location named '{0}'", "namedNetworkNotificationUpdateFailedDescription": "Updating location '{0}' failed. Please try again later.", "namedNetworkNotificationUpdateFailedTitle": "Failed to Update location", "namedNetworkNotificationUpdateSuccessDescription": "Updated location named '{0}'", "namedNetworkNotificationUpdateSuccessTitle": "Updated '{0}'", "namedNetworkNotificationUpdateTitle": "Updating '{0}'", "namedNetworksAdd": "New named location", "namedNetworksConditionHelpDescription": "Control user access based on their physical location.\n[Learn more][1]\n[1]: http://aka.ms/ux_ca_locationcondition", "namedNetworkSearchPlaceholder": "Search locations.", "namedNetworksExcludeLabel": "{0} and {1} excluded", "namedNetworksHelpDescription": "Named locations are used by Microsoft Entra ID security reports to reduce false positives and Microsoft Entra Conditional Access policies.\n[Learn more][1]\n[1]: https://aka.ms/ux_ca_namedlocations", "namedNetworksIncludeLabel": "{0} included", "namedNetworksNone": "No named locations found.", "namedNetworksTitle": "Configure locations", "namedNetworkUploadFailedDescription": "There was an error parsing the supplied file. Please make sure to upload a plain-text file with each line in the CIDR format.", "namedNetworkUploadFailedTitle": "Failed to parse '{0}'", "namedNetworkUploadInProgressDescription": "Attempting to parse valid CIDR values from '{0}'.", "namedNetworkUploadInProgressTitle": "Parsing '{0}'", "namedNetworkUploadInvalidDescription": "'{0}' is either too large or in an invalid format.", "namedNetworkUploadInvalidTitle": "'{0}' Invalid", "namedNetworkUploadIpRange": "Upload", "namedNetworkUploadSuccessDescription": "{0} lines analyzed. {1} in a bad format. {2} skipped.", "namedNetworkUploadSuccessTitle": "Finished parsing '{0}'", "nameLabel": "Name", "needMfaSecondary": "\"Require multifactor authentication\" must be selected when \"Sign-in frequency every time\" is selected with \"Secondary authentication methods only\"", "needMfaSpecificApps": "\"The \"sign-in frequency every time\" session control requires the \"Require multifactor authentication\" grant control when specifically-supported apps are selected", "newCertName": "new cert", "noAttributePermissionsError": "Insufficient privileges to create or update policy. Attribute definition reader role is required to add/edit dynamic filters.", "noneRisk": "No risk", "noPolicyRowMessage": "No policies", "noSPSelected": "No service principal selected", "noUpdatePermissionMessage": "You don't have permissions to update these settings. Please contact your global administrator to get access.", "noUserSelected": "No user selected", "office365Description": "These apps include Microsoft Flow, Microsoft Forms, Microsoft Teams, Office 365 Exchange Online, Office 365 SharePoint Online, Office 365 Yammer, and others.", "office365InfoBox": "At least one of the apps selected is part of Office 365. We recommend setting the policy on the Office 365 app instead.", "oneUserSelected": "1 user selected", "onlyGlobalAdminsCanSaveThisPolicyConfig": "Only global administrators can save this policy.", "or": "{0} OR {1} ", "pickerDoneCommand": "Done", "policiesBladeAdPremiumUpsellBannerText": "Create your own policies and target specific conditions like Cloud apps, Sign-in risk, and Device platforms with Microsoft Entra ID Premium", "policiesBladeTitle": "Policies", "policiesBladeTitleWithAppName": "Policies: {0}", "policiesDisabledBannerText": "Creating and editing policies is prohibited for applications with a linked sign-on attribute.", "policiesHitMaxLimitStatusBarMessage": "You've reached the maximum number of policies for this tenant. Delete some policies before creating more.", "policyAssignmentsSection": "Assignments", "policyBlockAllInfoBox": "The configured policy will block all users, so it is not supported. Review the assignments and controls. Exclude the current user {0}, if you would like to save this policy.", "policyCloudAppsDisplayTextAllApp": "All apps", "policyCloudAppsLabel": "Cloud apps", "policyConditionClientAppDescription": "Software the user is employing to access the cloud app. For example, 'Browser'", "policyConditionClientAppV2Description": "Software the user is employing to access the cloud app. For example, 'Browser'", "policyConditionDevicePlatform": "Device platforms", "policyConditionDevicePlatformDescription": "Platform the user is signing in from. For example, 'iOS'", "policyConditioniClientApp": "Client apps", "policyConditionLocation": "Locations", "policyConditionLocationDescription": "Location (determined using IP address range) the user is signing in from", "policyConditionLocationPreview": "Locations (Preview)", "policyConditionSigninRisk": "Sign-in risk", "policyConditionSigninRiskDescription": "Likelihood that the sign-in is coming from someone other than the user. Risk level can be high, medium or low. Requires Microsoft Entra ID P2 license.", "policyConditionUserRisk": "User risk", "policyConditionUserRiskDescription": "Configure user risk levels needed for policy to be enforced", "policyControlAllowAccessDisplayedName": "Grant access", "policyControlAuthenticationStrengthDisplayedName": "Require authentication strength (Preview)", "policyControlBladeTitle": "Grant", "policyControlBlockAccessDisplayedName": "Block access", "policyControlCompliantDeviceDisplayedName": "Require device to be marked as compliant", "policyControlContentDescription": "Control access enforcement to block or grant access.", "PolicyControlFedAuthMethod": { "ariaLabel": "Learn more about requiring authentication methods satisfied by federation providers.", "certificate": "Certificate authentication", "infoBubble": "Specify a required authentication method, that must be satisfied by federation provider, such as ADFS.", "multifactor": "Multifactor authentication", "require": "Require federated authentication method (Preview)", "whatIfFormat": "{0} - {1}" }, "policyControlInfoBallonText": "Block access or select additional requirements which need to be satisfied to allow access", "policyControlMfaChallengeDisplayedName": "Require multifactor authentication", "policyControlRequireCompliantAppDisplayedName": "Require app protection policy", "policyControlRequireDomainJoinedDisplayedName": "Require Microsoft Entra hybrid joined device", "policyControlRequiredPasswordChangeDisplayedName": "Require password change", "policyControlRequireMamDisplayedName": "Require approved client app", "policyControlSelectAuthStrength": "Require authentication strength", "policyControlsNoControlsSelected": "0 controls selected", "policyControlsSection": "Access controls", "policyCreatBladeTitle": "New", "policyCreateButton": "Create", "policyCreateFailedMessage": "Error: {0}", "policyCreateFailedTitle": "Failed to create '{0}'", "policyCreateInProgressTitle": "Creating '{0}'", "policyCreateSuccessMessage": "Successfully created '{0}'. Policy will be enabled in a few minutes if you have \"Enable policy\" set to \"On\".", "policyCreateSuccessTitle": "Successfully created '{0}'", "policyDeleteConfirmation": "Are you sure you want to delete '{0}'? This action cannot be undone.", "policyDeleteFailTitle": "Failed to delete '{0}'", "policyDeleteInProgressTitle": "Deleting '{0}'", "policyDeleteSuccessTitle": "Successfully deleted '{0}'", "policyEnforceLabel": "Enable policy", "policyErrorCannotSetSigninRisk": "You don't have permission to save a policy with a sign-in risk condition.", "policyErrorNoPermission": "You don't have permission to save policy. Contact your global admin.", "policyErrorUnknown": "Something went wrong, please try again later.", "policyFallbackWarningMessage": "Failure to create or update '{0}' using MS Graph resulting in a fallback to AD Graph. Please investigate the following scenario as there is most likely a bug when calling the policy endpoint for MS Graph with an incompatible condition.", "policyFallbackWarningTitle": "Creating or updating '{0}' partially successful", "policyNameCannotBeEmpty": "Policy name can't be empty", "policyNameDevice": "Device policy", "policyNameFormat": "[{0}] {1}", "policyNameMam": "Mobile App Management policy", "policyNameMfaLocation": "Multifactor authentication and location policy", "policyNamePlaceholderText": "Example: 'Device compliance app policy'", "policyNameTooLongError": "Policy name is too long. Maximum 256 characters", "policyOff": "Off", "policyOn": "On", "policyReportOnly": "Report-only", "policyReviewSection": "Review", "policySaveButton": "Save", "policyStatusIconDescription": "Policy is Enabled", "policyStatusIconEnabled": "Enabled status icon", "policyTemplateName1": "Use app enforced restrictions for {0} browser access", "policyTemplateName2": "Allow {0} access only on managed devices", "policyTemplateName3": "Policy migrated from Continuous Access Evaluation settings", "policyTriggerRiskSpecific": "Select specific risk level", "policyTriggersInfoBalloonText": "Conditions which define when the policy will apply. For example, 'location'", "policyTriggersNoConditionsSelected": "0 conditions selected", "policyTriggersSelectorLabel": "Conditions", "policyUpdateFailedMessage": "Error: {0}", "policyUpdateFailedTitle": "Failed to update {0}", "policyUpdateInProgressTitle": "Updating {0}", "policyUpdateSuccessMessage": "Successfully updated {0}. Policy will be enabled in a few minutes if you have \"Enable policy\" set to \"On\".", "policyUpdateSuccessTitle": "Successfully updated {0}", "primaryCol": "Primary", "privateLinkLabel": "Microsoft Entra ID Private Link", "reportOnlyInfoBox": "Report-only mode: Policies are evaluated and logged at sign-in but do not impact users.", "requireAllControlsText": "Require all the selected controls", "requireCompliantDevice": "Require compliant device", "requireDomainJoined": "Require domain-joined device", "requireGrantReauth": "The \"sign-in frequency every time\" session control requires a \"require multifactor authentication\" or \"require password change\" grant control when \"All cloud apps\" is selected", "requireMFA": "Require multifactor authentication", "requireMfaReauth": "The \"sign-in frequency every time\" session control requires the \"require multifactor authentication\" grant control for \"sign-in risk\"", "requireOneControlText": "Require one of the selected controls", "requirePasswordChangeReauth": "The \"sign-in frequency every time\" session control requires the \"require password change\" grant control for \"user risk\"", "requireRiskReauth": "The \"sign-in frequency every time\" session control requires the \"user risk\" or \"sign-in risk\" session control when \"all cloud apps\" is selected.", "requireRiskReauthRiskNotEnabled": "The \"sign-in frequency every time\" session control is not available when \"all cloud apps\" is selected.", "requireRiskReauthSignInOnly": "The \"sign-in frequency every time\" session control requires the \"sign-in risk\" session control when \"all cloud apps\" is selected.", "requireRiskReauthUserOnly": "The \"sign-in frequency every time\" session control requires the \"user risk\" session control when \"all cloud apps\" is selected.", "resetFilters": "Reset filters", "saturday": "Saturday", "searchTextTooLongError": "The search text is too long. Maximum 256 characters", "securityDefaultsPolicyName": "Security defaults", "securityDefaultsTextMessage": "Security defaults must be disabled to enable Conditional Access policy.", "securityDefaultsUpdateInProgressText": "A security defaults update is in progress, please wait a moment and try again.", "securityDefaultsWarningMessage": "It looks like you're about to manage your organization's security configurations. That's great! You must first {0}disable security defaults{1} before enabling a Conditional Access policy.", "selectDevicePlatforms": "Select device platforms", "selectedSP": "Selected Service Principal", "selectNamedNetworksSubtitle": "", "selectNamedNetworksTitle": "Select locations", "servicePrincipalBladeExcludedSelectorTitle": "Select excluded service principals", "servicePrincipalBladeIncludedSelectorTitle": "Select service principals", "servicePrincipalDataGridAria": "List of available service principals", "servicePrincipalDropDownLabel": "What does this policy apply to?", "servicePrincipalInfoBox": "Some conditions are not available due to '{0}' selection in policy assignment", "servicePrincipalRadioAll": "All owned service principals", "servicePrincipalRadioSelect": "Select service principals", "servicePrincipals": "Service principals", "servicePrincipalSelectionsAria": "Selected service principals grid", "servicePrincipalSelectorAria": "List of chosen service principals", "servicePrincipalSelectorMultiple": "{0} service principals selected", "servicePrincipalSelectorSingle": "1 service principal selected", "servicePrincipalSpecificExc": "Specific service principals excluded", "servicePrincipalSpecificInc": "Specific service principals included", "sessionControlBladeTitle": "Session", "sessionControlDescriptionContent": "Control access based on session controls to enable limited experiences within specific cloud applications.", "sessionControlDisableInfo": "This control only works with supported apps. Currently, Office 365, Exchange Online, and SharePoint Online are the only cloud apps that support app enforced restrictions. Click here to learn more.", "sessionControlInfoBallonText": "Session controls enable limited experience within a cloud app.", "sessionControls": "Session controls", "sessionControlsAppEnforcedLabel": "Use app enforced restrictions", "sessionControlsCasLabel": "Use Conditional Access App Control", "sessionControlsSecureSignInLabel": "Require token binding", "SessionLifetime": { "mainOption": "Modify session lifetime", "mainOptionHelp": "Configure how often users will get prompted and whether browser sessions will be persisted. Applications that don't support modern authentication protocols might not honor these policies. In such cases please contact the application developer.", "PersistentBrowser": { "Error": { "notAllApps": "Persistent browser session policy only works correctly when \"All cloud apps\" is selected. Please update your cloud apps selection." }, "Option": { "always": "Always persistent", "help": "A persistent browser session allows users to remain signed in after closing and reopening their browser window.
\n