The article was edited for spelling, headings, and presentation while retaining its documented enforcement phases, dates, affected applications, account scope, and break-glass guidance.
Microsoft sets November 3 deadline to replace Entra MemberOf rules
The week’s clearest operational change is Microsoft Entra ID’s scheduled retirement of the MemberOf rule operator on November 3, 2026. Organizations must replace MemberOf configurations in dynamic groups, administrative units, and entitlement policies; afterward, MemberOf-based updates will stop, affecting memberships, access, licensing, Conditional Access, and related services. Most other supplied updates are editorial, metadata, terminology, or link maintenance, with notable technical guidance for Private Access, AI-agent permissions, and External ID passkeys and SMS.
- MemberOf rule operator retires November 3, 2026
Entra ID · Conditional Access
Microsoft’s final reminder says MemberOf will be retired on November 3, 2026. Replace it in dynamic groups, administrative units, and entitlement policies; after the deadline, MemberOf-based updates will stop, affecting memberships, access, licensing, Conditional Access, and related services.
- Private Access sensor 2.2.79 adds over-the-air updates and Kerberos improvements
Private Access · General
The release history records version 2.2.79, released September 29, with over-the-air sensor updates, enhanced Kerberos security and diagnostics, SID-based service matching, and corrected wildcard matching. Upgrading from version 2.2.42 requires a one-time full-installer deployment; inbound TCP and UDP on port 1337 must be allowed, and IPv6 Kerberos traffic is blocked.
- Agent ID guidance makes delegated OAuth permissions explicit
Agent ID · General
The updated Agent Access Packages guidance states that agent identities need delegated OAuth permissions for target resources such as Microsoft Graph or an application when assisting users with API access.
- External ID passkey samples add permission and secret-handling warnings
External ID · Developer
The updated integration material adds a sample for listing and registering passkeys with delegated permissions. It warns that the deletion flow uses high-privilege application permissions and a client secret in browser code, so the sample should run only in a test tenant and never in production.
- External ID FAQ clarifies the scope of SMS restrictions
External ID · Authentication
The FAQ now states that SMS is unavailable only for first-factor authentication in external tenants. It indicates that SMS remains available for self-service password reset and for second-factor verification at additional cost.
Prioritize replacing MemberOf configurations before November 3. For Private Access sensor version 2.2.79, upgrades from version 2.2.42 require a one-time full-installer deployment to enable over-the-air updates; allow inbound TCP and UDP on port 1337, and use IPv4 for Kerberos. Assign delegated OAuth permissions to agent identities where they assist with target-resource API access, and run the External ID passkey sample only in a test tenant.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
Updates this week
Microsoft Entra ID
31 updatesThe native authentication API reference was updated with spelling corrections. The supplied examples, links, endpoints, error details, and configuration guidance remain unchanged.
The tutorial’s code comment was corrected from “Thge” to “The” and from “rquired” to “required.”
The article fixes the spelling of “OpenID Connect” and replaces an empty .NET NuGet link with an Azure Functions API link, along with other wording corrections.
Authentication Entra Passkeys On Windows
Doc updateThe page no longer includes the `ms.author: justinha` metadata entry.
The passwordless authentication documentation no longer includes the `author` and `ms.author` fields.
Sso Admin Control
Doc updateThe documentation fixes minor formatting in the scope notes and corrects the image text from `HKEY_LOCAL_MACHIEN` to `HKEY_LOCAL_MACHINE`.
The username/password token acquisition article no longer includes the author, manager, and ms.author fields.
The page no longer includes the author, manager, and ms.author metadata fields.
Removed the `manager` and `ms.author` metadata fields from the OIDC protocol documentation.
The document no longer includes the author, manager, and ms.author metadata fields.
Understand Microsoft's SSO model
Doc updateThe page no longer includes the author, manager, and ms.author metadata fields.
The single sign-on documentation no longer includes the author, manager, and ms.author metadata fields.
Assign User Or Group Access Portal
Doc updateThe enterprise application page received spelling corrections in its user, group, and app-role assignment guidance.
The page no longer includes the `manager` and `ms.author` metadata fields.
The daemon token acquisition documentation no longer includes the `manager` and `ms.author` fields.
The page no longer includes the author, manager, and ms.author metadata fields.
The tutorial received spelling and wording corrections across its SAML attribute mapping, authentication policy, testing, and account discovery sections.
Connect Version History
Doc updateThe version history page was updated with spelling fixes in existing release and feature descriptions.
Recover Objects
Doc updateChanged “cancelation” to “cancellation” in the recovery job instructions.
The page no longer includes the author, manager, and ms.author metadata fields.
Added a missing space between “authentication” and “and” in the documentation.
Microsoft Entra ID will retire the MemberOf rule operator by November 3, 2026. Organizations must replace MemberOf in dynamic groups, administrative units, and entitlement policies to avoid outdated memberships, access, and licensing issues. After this date, MemberOf-based updates will stop, impacting Conditional Access and related services.
Microsoft Entra Health
Doc updateCorrected a spelling error and updated punctuation in the Microsoft Entra Health article.
Zero Trust Ai
Doc updateThe page no longer includes the ms.author, author, or manager metadata fields.
The tutorial now refers to Zscaler instead of Zscaler Authentication Service Provisioning throughout its title, prerequisites, configuration steps, and Microsoft Entra app-gallery instructions.
The tutorial now consistently refers to Zscaler ZSNet instead of Zscaler ZNet, including the title, prerequisites, gallery search instructions, and provisioning steps.
Credential Management Api
Doc updateAction requiredThe article now links to a sample app demonstrating passkey listing and registration with delegated permissions and warns that its deletion flow uses high-privilege application permissions and a client secret in browser code.
Corrected a spelling error in the explanation of “Report-only: Failure” results for the “Require app protection policy” control.
Multi Tenant Common Considerations
Doc updateThe documentation corrects wording and spacing in guidance about cross-tenant access policies, guest self-service sign-up, Conditional Access sign-in frequency, and governance.
Troubleshoot Hybrid Join Windows Current
Doc updateThe Windows hybrid-join troubleshooting page received spelling and copy edits covering TPM errors, PRT checks, and Event Viewer guidance.
Microsoft Entra Agent ID
6 updatesAgent Access Packages
Doc updateThe documentation now states more clearly that an agent needs assigned OAuth delegated permissions to assist a user when accessing a target resource’s APIs.
Agent Access Packages
Doc updateAction requiredThe documentation now states that agent identities need delegated OAuth permissions for target resources, such as Microsoft Graph or an application, to assist users with API access.
Integrate N8n Agent
Doc updateThe n8n agent integration page no longer includes the `author` and `ms.author` metadata fields.
Call Api Azure Services
Doc updateThe documentation corrects spelling errors, including “credentials,” and adds missing punctuation to a step describing token credentials and Azure SDK clients.
The documentation now identifies the resource role as applying to an AI agent’s service principal or agent ID and adds numbered steps for selecting API permissions, permission type, required permissions, and updating the configuration.
Agent Id Governance Overview
Doc updateThe documentation now describes the linked guidance as covering delegated and application permissions for Microsoft Graph and applications.
Microsoft Entra ID Protection
1 updateIdentity Protection Unified Risk
Doc updateThe page no longer includes the `ms.author` and `author` metadata fields.
Microsoft Entra ID Governance
5 updatesCorrected spelling in the guest user licensing and governance documentation, including “governance-related.”
Externally determine the approval requirements for an access package using custom extensions
Doc updateThe entitlement management dynamic approval article received spelling corrections covering custom extensions, Logic Apps, approval setup, and HTTP trigger configuration.
Entitlement Management Catalog Create
Doc updateAdded a missing space after the bold “Prerequisite roles:” label. The linked role requirements are unchanged.
The documentation no longer includes the `author` and `ms.author` metadata fields.
The documentation updates wording across deployment scenarios, entitlement management, access reviews, separation of duties, birthright assignment, and Logic Apps guidance without changing the described capabilities or procedures.
Microsoft Entra External ID
5 updatesSign In With Passkey
Doc updateThe documentation now describes a sample where signed-in customers list and register their own passkeys. It warns that the deletion flow uses high-privilege permissions and a client secret, so the sample is for test tenants only.
Faq Customers
Feature updateThe documentation now states that SMS is unavailable only for first-factor authentication in external tenants, indicating availability for self-service password reset. SMS remains available for second-factor verification at additional cost.
The Android custom headers tutorial no longer includes the author, manager, and ms.author metadata fields.
The page now links to a sample for listing and registering passkeys and documents delegated permissions for those operations. It also warns that deletion uses high-privilege application permissions and a client secret in browser code.
The custom policy analysis article no longer includes the `author` and `ms.author` metadata fields.
Microsoft Entra Internet Access
1 updatePalo Alto Coexistence
Doc updateThe service connection link text now uses “configuring” instead of the misspelled “configurating.”
Microsoft Entra Private Access
2 updatesPrivate Access Sensor Release History
Feature updateAction requiredVersion 2.2.79, released September 29, 2026, adds over-the-air sensor updates, enhanced Kerberos security and diagnostics, SID-based service matching, and corrected wildcard matching.
The guide now consistently spells “Multi-Geo,” including correcting a typo in the Japan region limitation.
Microsoft Entra Workload ID
1 updateManaged Identities Faq
Doc updateThe FAQ now uses “towards” instead of the misspelled “torwards” in its soft-deleted objects quota guidance.
Microsoft Entra Global Secure Access
7 updatesThe page no longer includes the `author` and `ms.author` metadata fields.
The documentation no longer includes the `author` and `ms.author` fields.
2) Detect browsers via registry only
Doc updateThe PowerShell prompt now correctly refers to the `IPv4Preferred` registry key instead of `IPv4Preffered`.
The article metadata field was corrected from `ms.reviwer` to `ms.reviewer`; the topic classification remains unchanged.
Global Secure Access egress IP ranges
Doc updateThe page no longer includes the `author` and `ms.author` metadata fields.
The page’s `author` and `ms.author` metadata fields were removed.
Secure Web Ai Gateway Agents
Doc updateThe documentation corrects “Web respositories” to “Web repositories” in an example of security rules.
