← Previous week
Week in brief

Microsoft sets November 3 deadline to replace Entra MemberOf rules

The week’s clearest operational change is Microsoft Entra ID’s scheduled retirement of the MemberOf rule operator on November 3, 2026. Organizations must replace MemberOf configurations in dynamic groups, administrative units, and entitlement policies; afterward, MemberOf-based updates will stop, affecting memberships, access, licensing, Conditional Access, and related services. Most other supplied updates are editorial, metadata, terminology, or link maintenance, with notable technical guidance for Private Access, AI-agent permissions, and External ID passkeys and SMS.

  • Microsoft’s final reminder says MemberOf will be retired on November 3, 2026. Replace it in dynamic groups, administrative units, and entitlement policies; after the deadline, MemberOf-based updates will stop, affecting memberships, access, licensing, Conditional Access, and related services.

  • The release history records version 2.2.79, released September 29, with over-the-air sensor updates, enhanced Kerberos security and diagnostics, SID-based service matching, and corrected wildcard matching. Upgrading from version 2.2.42 requires a one-time full-installer deployment; inbound TCP and UDP on port 1337 must be allowed, and IPv6 Kerberos traffic is blocked.

  • The updated Agent Access Packages guidance states that agent identities need delegated OAuth permissions for target resources such as Microsoft Graph or an application when assisting users with API access.

  • The updated integration material adds a sample for listing and registering passkeys with delegated permissions. It warns that the deletion flow uses high-privilege application permissions and a client secret in browser code, so the sample should run only in a test tenant and never in production.

  • The FAQ now states that SMS is unavailable only for first-factor authentication in external tenants. It indicates that SMS remains available for self-service password reset and for second-factor verification at additional cost.

For Entra administrators

Prioritize replacing MemberOf configurations before November 3. For Private Access sensor version 2.2.79, upgrades from version 2.2.42 require a one-time full-installer deployment to enable over-the-air updates; allow inbound TCP and UDP on port 1337, and use IPv4 for Kerberos. Assign delegated OAuth permissions to agent identities where they assist with target-resource API access, and run the External ID passkey sample only in a test tenant.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

Updates this week

8

Native authentication API reference documentation

Doc update

The native authentication API reference was updated with spelling corrections. The supplied examples, links, endpoints, error details, and configuration guidance remain unchanged.

6 October 2026

Sso Admin Control

Doc update

The documentation fixes minor formatting in the scope notes and corrects the image text from `HKEY_LOCAL_MACHIEN` to `HKEY_LOCAL_MACHINE`.

6 October 2026
5
4

Assign User Or Group Access Portal

Doc update

The enterprise application page received spelling corrections in its user, group, and app-role assignment guidance.

6 October 2026
4

Connect Version History

Doc update

The version history page was updated with spelling fixes in existing release and feature descriptions.

6 October 2026

Recover Objects

Doc update

Changed “cancelation” to “cancellation” in the recovery job instructions.

6 October 2026
2

Microsoft Entra ID: Final reminder to replace MemberOf rule operator configurations by November 3, 2026

New

Microsoft Entra ID will retire the MemberOf rule operator by November 3, 2026. Organizations must replace MemberOf in dynamic groups, administrative units, and entitlement policies to avoid outdated memberships, access, and licensing issues. After this date, MemberOf-based updates will stop, impacting Conditional Access and related services.

5 October 2026
Message CenterMC1488834 on mc.merill.net ↗Plan for change
2

Microsoft Entra Health

Doc update

Corrected a spelling error and updated punctuation in the Microsoft Entra Health article.

6 October 2026

Zero Trust Ai

Doc update

The page no longer includes the ms.author, author, or manager metadata fields.

6 October 2026
2
2

Credential Management Api

Doc updateAction required

The article now links to a sample app demonstrating passkey listing and registration with delegated permissions and warns that its deletion flow uses high-privilege application permissions and a client secret in browser code.

6 October 2026
1

Multi Tenant Common Considerations

Doc update

The documentation corrects wording and spacing in guidance about cross-tenant access policies, guest self-service sign-up, Conditional Access sign-in frequency, and governance.

6 October 2026
1

Troubleshoot Hybrid Join Windows Current

Doc update

The Windows hybrid-join troubleshooting page received spelling and copy edits covering TPM errors, PRT checks, and Event Viewer guidance.

6 October 2026
3

Agent Access Packages

Doc update

The documentation now states more clearly that an agent needs assigned OAuth delegated permissions to assist a user when accessing a target resource’s APIs.

6 October 2026

Agent Access Packages

Doc updateAction required

The documentation now states that agent identities need delegated OAuth permissions for target resources, such as Microsoft Graph or an application, to assist users with API access.

6 October 2026

Integrate N8n Agent

Doc update

The n8n agent integration page no longer includes the `author` and `ms.author` metadata fields.

6 October 2026
1

Call Api Azure Services

Doc update

The documentation corrects spelling errors, including “credentials,” and adds missing punctuation to a step describing token credentials and Azure SDK clients.

6 October 2026
1

Entitlement Management Access Package Resources

Doc update

The documentation now identifies the resource role as applying to an AI agent’s service principal or agent ID and adds numbered steps for selecting API permissions, permission type, required permissions, and updating the configuration.

6 October 2026
1

Agent Id Governance Overview

Doc update

The documentation now describes the linked guidance as covering delegated and application permissions for Microsoft Graph and applications.

6 October 2026
1
4
1
3

Sign In With Passkey

Doc update

The documentation now describes a sample where signed-in customers list and register their own passkeys. It warns that the deletion flow uses high-privilege permissions and a client secret, so the sample is for test tenants only.

6 October 2026

Faq Customers

Feature update

The documentation now states that SMS is unavailable only for first-factor authentication in external tenants, indicating availability for self-service password reset. SMS remains available for second-factor verification at additional cost.

6 October 2026
1

Samples and guides for integrating apps with External ID

Doc update

The page now links to a sample for listing and registering passkeys and documents delegated permissions for those operations. It also warns that deletion uses high-privilege application permissions and a client secret in browser code.

6 October 2026
1
1

Palo Alto Coexistence

Doc update

The service connection link text now uses “configuring” instead of the misspelled “configurating.”

6 October 2026
2

Private Access Sensor Release History

Feature updateAction required

Version 2.2.79, released September 29, 2026, adds over-the-air sensor updates, enhanced Kerberos security and diagnostics, SID-based service matching, and corrected wildcard matching.

6 October 2026
1

Managed Identities Faq

Doc update

The FAQ now uses “towards” instead of the misspelled “torwards” in its soft-deleted objects quota guidance.

6 October 2026
4
1
1
1

Secure Web Ai Gateway Agents

Doc update

The documentation corrects “Web respositories” to “Web repositories” in an example of security rules.

6 October 2026
Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…