The article was edited for spelling, headings, and presentation while retaining its documented enforcement phases, dates, affected applications, account scope, and break-glass guidance.
Keep up with Microsoft Entra
Daily AI-generated highlights from Microsoft Learn and Message Center. Browse the archive from 15 April 2025 → About this project →
Private Access sensor 2.2.79 adds OTA updates; passkey samples flag production risks
The period’s meaningful changes center on Private Access operations and identity-developer guidance. Sensor version 2.2.79 adds over-the-air updates and Kerberos diagnostics, while passkey documentation now covers listing and registration with an explicit warning about a high-privilege deletion flow. External ID guidance also clarifies SMS availability, and Agent ID access-package instructions better define API-permission setup. Most other updates were spelling, metadata, formatting, or wording corrections.
- Private Access Sensor 2.2.79 introduces OTA updates and Kerberos improvements
Private Access · General
The release history records version 2.2.79, released September 29, 2026, with over-the-air sensor updates, enhanced Kerberos security and diagnostics, SID-based service matching, and corrected wildcard matching. Enabling OTA updates after version 2.2.42 requires a one-time full-installer deployment; inbound TCP and UDP port 1337 must be allowed, and Kerberos uses IPv4 because IPv6 traffic is blocked.
- Passkey samples add self-service listing and registration with a dangerous deletion pattern
External ID · Authentication
The External ID guidance now describes a sample in which signed-in customers list and register their own passkeys. It explicitly warns that deletion relies on high-privilege permissions and a client secret, limiting the sample to test tenants rather than production deployments.
- External ID FAQ distinguishes SMS first-factor limits from recovery and second-factor use
External ID · Authentication
The FAQ now states that SMS is unavailable only for first-factor authentication in external tenants. SMS remains available for self-service password reset and for second-factor verification, with the latter available at additional cost.
- Agent ID access packages clarify service-principal roles and API permission setup
Agent ID · Governance
The access-package guidance now identifies the resource role as applying to an AI agent’s service principal or agent ID and provides numbered steps for selecting API permissions, permission type, required permissions, and updating the configuration.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
58 updates
Microsoft Entra ID
30 updatesThe native authentication API reference was updated with spelling corrections. The supplied examples, links, endpoints, error details, and configuration guidance remain unchanged.
The tutorial’s code comment was corrected from “Thge” to “The” and from “rquired” to “required.”
The article fixes the spelling of “OpenID Connect” and replaces an empty .NET NuGet link with an Azure Functions API link, along with other wording corrections.
Authentication Entra Passkeys On Windows
Doc updateThe page no longer includes the `ms.author: justinha` metadata entry.
The passwordless authentication documentation no longer includes the `author` and `ms.author` fields.
Sso Admin Control
Doc updateThe documentation fixes minor formatting in the scope notes and corrects the image text from `HKEY_LOCAL_MACHIEN` to `HKEY_LOCAL_MACHINE`.
The username/password token acquisition article no longer includes the author, manager, and ms.author fields.
The page no longer includes the author, manager, and ms.author metadata fields.
Removed the `manager` and `ms.author` metadata fields from the OIDC protocol documentation.
The document no longer includes the author, manager, and ms.author metadata fields.
Understand Microsoft's SSO model
Doc updateThe page no longer includes the author, manager, and ms.author metadata fields.
The single sign-on documentation no longer includes the author, manager, and ms.author metadata fields.
Assign User Or Group Access Portal
Doc updateThe enterprise application page received spelling corrections in its user, group, and app-role assignment guidance.
The page no longer includes the `manager` and `ms.author` metadata fields.
The daemon token acquisition documentation no longer includes the `manager` and `ms.author` fields.
The page no longer includes the author, manager, and ms.author metadata fields.
The tutorial received spelling and wording corrections across its SAML attribute mapping, authentication policy, testing, and account discovery sections.
Connect Version History
Doc updateThe version history page was updated with spelling fixes in existing release and feature descriptions.
Recover Objects
Doc updateChanged “cancelation” to “cancellation” in the recovery job instructions.
The page no longer includes the author, manager, and ms.author metadata fields.
Microsoft Entra Health
Doc updateCorrected a spelling error and updated punctuation in the Microsoft Entra Health article.
Zero Trust Ai
Doc updateThe page no longer includes the ms.author, author, or manager metadata fields.
The tutorial now refers to Zscaler instead of Zscaler Authentication Service Provisioning throughout its title, prerequisites, configuration steps, and Microsoft Entra app-gallery instructions.
The tutorial now consistently refers to Zscaler ZSNet instead of Zscaler ZNet, including the title, prerequisites, gallery search instructions, and provisioning steps.
Credential Management Api
Doc updateAction requiredThe article now links to a sample app demonstrating passkey listing and registration with delegated permissions and warns that its deletion flow uses high-privilege application permissions and a client secret in browser code.
Corrected a spelling error in the explanation of “Report-only: Failure” results for the “Require app protection policy” control.
Multi Tenant Common Considerations
Doc updateThe documentation corrects wording and spacing in guidance about cross-tenant access policies, guest self-service sign-up, Conditional Access sign-in frequency, and governance.
Added a missing space between “authentication” and “and” in the documentation.
Troubleshoot Hybrid Join Windows Current
Doc updateThe Windows hybrid-join troubleshooting page received spelling and copy edits covering TPM errors, PRT checks, and Event Viewer guidance.
Microsoft Entra Agent ID
6 updatesAgent Access Packages
Doc updateThe documentation now states more clearly that an agent needs assigned OAuth delegated permissions to assist a user when accessing a target resource’s APIs.
Agent Access Packages
Doc updateAction requiredThe documentation now states that agent identities need delegated OAuth permissions for target resources, such as Microsoft Graph or an application, to assist users with API access.
Integrate N8n Agent
Doc updateThe n8n agent integration page no longer includes the `author` and `ms.author` metadata fields.
Call Api Azure Services
Doc updateThe documentation corrects spelling errors, including “credentials,” and adds missing punctuation to a step describing token credentials and Azure SDK clients.
The documentation now identifies the resource role as applying to an AI agent’s service principal or agent ID and adds numbered steps for selecting API permissions, permission type, required permissions, and updating the configuration.
Agent Id Governance Overview
Doc updateThe documentation now describes the linked guidance as covering delegated and application permissions for Microsoft Graph and applications.
Microsoft Entra ID Protection
1 updateIdentity Protection Unified Risk
Doc updateThe page no longer includes the `ms.author` and `author` metadata fields.
Microsoft Entra ID Governance
5 updatesCorrected spelling in the guest user licensing and governance documentation, including “governance-related.”
Externally determine the approval requirements for an access package using custom extensions
Doc updateThe entitlement management dynamic approval article received spelling corrections covering custom extensions, Logic Apps, approval setup, and HTTP trigger configuration.
Entitlement Management Catalog Create
Doc updateAdded a missing space after the bold “Prerequisite roles:” label. The linked role requirements are unchanged.
The documentation no longer includes the `author` and `ms.author` metadata fields.
The documentation updates wording across deployment scenarios, entitlement management, access reviews, separation of duties, birthright assignment, and Logic Apps guidance without changing the described capabilities or procedures.
Microsoft Entra External ID
5 updatesSign In With Passkey
Doc updateThe documentation now describes a sample where signed-in customers list and register their own passkeys. It warns that the deletion flow uses high-privilege permissions and a client secret, so the sample is for test tenants only.
Faq Customers
Feature updateThe documentation now states that SMS is unavailable only for first-factor authentication in external tenants, indicating availability for self-service password reset. SMS remains available for second-factor verification at additional cost.
The Android custom headers tutorial no longer includes the author, manager, and ms.author metadata fields.
The page now links to a sample for listing and registering passkeys and documents delegated permissions for those operations. It also warns that deletion uses high-privilege application permissions and a client secret in browser code.
The custom policy analysis article no longer includes the `author` and `ms.author` metadata fields.
Microsoft Entra Internet Access
1 updatePalo Alto Coexistence
Doc updateThe service connection link text now uses “configuring” instead of the misspelled “configurating.”
Microsoft Entra Private Access
2 updatesPrivate Access Sensor Release History
Feature updateAction requiredVersion 2.2.79, released September 29, 2026, adds over-the-air sensor updates, enhanced Kerberos security and diagnostics, SID-based service matching, and corrected wildcard matching.
The guide now consistently spells “Multi-Geo,” including correcting a typo in the Japan region limitation.
Microsoft Entra Workload ID
1 updateManaged Identities Faq
Doc updateThe FAQ now uses “towards” instead of the misspelled “torwards” in its soft-deleted objects quota guidance.
Microsoft Entra Global Secure Access
7 updatesThe page no longer includes the `author` and `ms.author` metadata fields.
The documentation no longer includes the `author` and `ms.author` fields.
2) Detect browsers via registry only
Doc updateThe PowerShell prompt now correctly refers to the `IPv4Preferred` registry key instead of `IPv4Preffered`.
The article metadata field was corrected from `ms.reviwer` to `ms.reviewer`; the topic classification remains unchanged.
Global Secure Access egress IP ranges
Doc updateThe page no longer includes the `author` and `ms.author` metadata fields.
The page’s `author` and `ms.author` metadata fields were removed.
Secure Web Ai Gateway Agents
Doc updateThe documentation corrects “Web respositories” to “Web repositories” in an example of security rules.
