docs(architect): weekly KB update — 106 files refreshed (2026-04)
Updates across all 5 skills: ms-ai-advisor, ms-ai-engineering, ms-ai-governance, ms-ai-security, ms-ai-infrastructure. Key changes: - Language Services (Custom Text Classification, Text Analytics, QnA): retirement warning 2029-03-31, migration guides to Foundry/GPT-4o - Agentic Retrieval: 50M free reasoning tokens/month (Public Preview) - Computer Use: Claude Sonnet 4.5 (preview) + OpenAI CUA models - Agent Registry: Risks column (M365 E7), user-shared/org-published types - Declarative agents: schema v1.5 → v1.6, Store validation requirements - MLflow 3: 13 built-in LLM judges, production monitoring, Genie Code - AG-UI HITL: ApprovalRequiredAIFunction (C#) + @tool(approval_mode) (Python) - Entra ID Ignite 2025: Agent ID Admin/Developer RBAC roles, Conditional Access - Security Copilot: 400 SCU/month per 1000 M365 E5 licenses, auto-provisioned - Fast Transcription API: phrase lists, 14-language multi-lingual transcription - Azure Monitor Workbooks: Bicep support, RBAC specifics - Power Platform Copilot: data residency (Norway/Europe → EU DB, Bing → USA) - RAG security-rbac: 4-approach table (GA + 3 preview access control methods) - IaC MLOps: Well-Architected OE:05 principles, Bicep/Terraform patterns - Translator: image file batch translation Preview (JPEG/PNG/BMP/WebP) All 106 files: Last updated 2026-04 | Verified: MCP 2026-04 Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
parent
0eb30fa853
commit
6645e93205
104 changed files with 1986 additions and 520 deletions
|
|
@ -1,6 +1,6 @@
|
|||
# RAG Security - RBAC, Filtering, and Access Control
|
||||
|
||||
**Last updated:** 2026-02
|
||||
**Last updated:** 2026-04 | Verified: MCP 2026-04
|
||||
**Status:** Preview (native ACL/RBAC), GA (security filters)
|
||||
**Category:** RAG Architecture & Semantic Search
|
||||
|
||||
|
|
@ -531,3 +531,24 @@ Authorization: Bearer <user-token>
|
|||
**GA features:** Security filters (alle API-versjoner)
|
||||
|
||||
**Note:** Preview features kan endre seg. Konsulter alltid nyeste dokumentasjon før produksjon.
|
||||
|
||||
|
||||
### Dokumentnivå-tilgangskontroll — oppdatering 2026-04
|
||||
|
||||
**4 tilnærminger (oppdatert):**
|
||||
|
||||
| Tilnærming | Status | Beskrivelse |
|
||||
|-----------|--------|-------------|
|
||||
| **Security filters** | GA | String-sammenligning med `search.in()` — API-agnostisk |
|
||||
| **POSIX-like ACL/RBAC scopes** | Preview | Microsoft Entra ID-autentisering mot dokument-ACLer (ADLS Gen2) |
|
||||
| **Microsoft Purview sensitivity labels** | Preview | Entra-token + Purview policy enforced ved query-tid |
|
||||
| **SharePoint M365 ACLs** | Preview | SharePoint-tilganger ekstraheres av indexer og håndheves ved søk |
|
||||
|
||||
**ADLS Gen2 ACL/RBAC (preview):**
|
||||
- RBAC: container-nivå (grov tilgangskontroll for alle dokumenter i container)
|
||||
- ACL: fil/mappe-nivå (finkornet per-dokument tilgangskontroll)
|
||||
- ABAC: **ikke støttet** i Azure AI Search
|
||||
- Tilgangsevaluering: RBAC sjekkes først, deretter ACL. Tilgang gis om én av dem tillater det
|
||||
- Permissions synkroniseres ved: første full indexer-kjøring, nye dokumenter, eller manuell trigger via `/resync` (preview)
|
||||
|
||||
**Query-enforcement:** `x-ms-query-source-authorization`-header med Entra-token aktiverer automatisk trimming.
|
||||
Loading…
Add table
Add a link
Reference in a new issue