The article was edited for spelling, headings, and presentation while retaining its documented enforcement phases, dates, affected applications, account scope, and break-glass guidance.
Keep up with Microsoft Entra
Daily AI-generated highlights from Microsoft Learn and Message Center. Browse the archive from 15 April 2025 → About this project →
Cloud Sync supports hybrid-join device synchronization; Private Access 2.2.79 adds OTA updates
The most consequential updates clarify Cloud Sync support for Microsoft Entra hybrid join and document the Private Access Sensor 2.2.79 release, including its upgrade prerequisites. Entra administrators also get a more precise SSPR authentication-method count and stronger External ID passkey sample warnings. Most other changes were spelling, metadata, naming, or presentation edits.
- Cloud Sync migration now includes hybrid-join device synchronization
Entra ID · Provisioning
The migration decision guide now states that Cloud Sync supports device synchronization for Microsoft Entra hybrid join. Device synchronization must be enabled separately, with updated migration guidance and configuration steps. Administrators moving hybrid-joined devices should include this capability explicitly in their migration plan.
- Private Access Sensor 2.2.79 adds OTA updates and Kerberos improvements
Private Access · General
The release history records version 2.2.79, released September 29, 2026, with over-the-air sensor updates, enhanced Kerberos security and diagnostics, SID-based service matching, and corrected wildcard matching. Upgrading from version 2.2.42 requires a one-time full-installer deployment to enable OTA updates; inbound TCP and UDP port 1337 must be allowed, and IPv4 is required because IPv6 Kerberos traffic is blocked.
- SSPR counts Authenticator and OATH variants as one method
Entra ID · Authentication
The SSPR guidance now states that Microsoft Authenticator, software OATH tokens, and hardware OATH tokens count as one authentication method, regardless of Authentication methods policy migration status. Administrators should use that shared count when evaluating SSPR method requirements.
- External ID passkey samples receive explicit high-privilege warnings
External ID · Authentication
The updated guidance describes administrator-controlled passkey provisioning through the FIDO2 provisioning APIs and identifies the sample as testing-only. Its deletion flow uses high-privilege permissions and a client secret in browser code, so the sample should not be deployed in production.
- External-tenant SMS guidance distinguishes first-factor and SSPR use
External ID · Authentication
The FAQ now states that SMS is unavailable for first-factor authentication in external tenants while indicating availability for self-service password reset. SMS remains available for second-factor verification at additional cost, giving administrators a clearer basis for external-tenant SSPR planning.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
72 updates
Microsoft Entra ID
42 updatesSelf-service password reset deep dive
Doc updateThe guidance now states that Microsoft Authenticator, software OATH tokens, and hardware OATH tokens count as one authentication method for SSPR, regardless of Authentication methods policy migration status.
The native authentication API reference was updated with spelling corrections. The supplied examples, links, endpoints, error details, and configuration guidance remain unchanged.
The tutorial’s code comment was corrected from “Thge” to “The” and from “rquired” to “required.”
The article fixes the spelling of “OpenID Connect” and replaces an empty .NET NuGet link with an Azure Functions API link, along with other wording corrections.
Authentication Entra Passkeys On Windows
Doc updateThe page no longer includes the `ms.author: justinha` metadata entry.
The passwordless authentication documentation no longer includes the `author` and `ms.author` fields.
Sso Admin Control
Doc updateThe documentation fixes minor formatting in the scope notes and corrects the image text from `HKEY_LOCAL_MACHIEN` to `HKEY_LOCAL_MACHINE`.
The username/password token acquisition article no longer includes the author, manager, and ms.author fields.
Microsoft Entra Cloud Sync migration decision guide
Feature updateAction requiredThe decision guide now states that Cloud Sync supports device synchronization for Microsoft Entra hybrid join. Device synchronization must be enabled separately, with updated migration guidance and configuration steps.
Migrate to Microsoft Entra Cloud Sync
Doc updateThe guide now describes phased migration planning, including Cloud Sync device synchronization for Microsoft Entra hybrid join and prerequisite checks.
The article now helps administrators check their Microsoft Entra Connect version, evaluate Microsoft Entra Cloud Sync—including device synchronization—and find the latest upgrade guidance.
The tutorial now refers to Zscaler instead of Zscaler Authentication Service Provisioning throughout its title, prerequisites, configuration steps, and Microsoft Entra app-gallery instructions.
The tutorial now consistently refers to Zscaler ZSNet instead of Zscaler ZNet, including the title, prerequisites, gallery search instructions, and provisioning steps.
Common hybrid scenarios with Microsoft Entra ID
Feature updateThe comparison table now lists Microsoft Entra Cloud Sync as supporting Microsoft Entra hybrid join and links to Cloud Sync device synchronization instructions. The article also expands comparisons across Cloud Sync, Connect Sync, MIM, and ECMA Host.
The guide now covers configuring Microsoft Entra Cloud Sync and Connect Sync, including synchronizing Active Directory computer objects to Microsoft Entra ID for hybrid join.
Understand Microsoft Entra Connect Sync
Doc updateThe article now explains Cloud Sync as synchronizing users, groups, contacts, and devices, and links to device synchronization configuration guidance.
Tools used for synchronization
Doc updateThe comparison article now includes devices among supported synchronization scenarios and notes that Cloud Sync can synchronize computer objects for Microsoft Entra hybrid join when device sync is enabled. It also adds a comparison table and selection wizard.
The tutorial received spelling and wording corrections across its SAML attribute mapping, authentication policy, testing, and account discovery sections.
Connect Version History
Doc updateThe version history page was updated with spelling fixes in existing release and feature descriptions.
The guide now covers selecting Cloud Sync or Connect Sync and configuring Cloud Sync to synchronize Active Directory computer objects for Microsoft Entra hybrid join.
Recover Objects
Doc updateChanged “cancelation” to “cancellation” in the recovery job instructions.
The page no longer includes the author, manager, and ms.author metadata fields.
The page no longer includes the author, manager, and ms.author metadata fields.
Removed the `manager` and `ms.author` metadata fields from the OIDC protocol documentation.
The document no longer includes the author, manager, and ms.author metadata fields.
Understand Microsoft's SSO model
Doc updateThe page no longer includes the author, manager, and ms.author metadata fields.
The single sign-on documentation no longer includes the author, manager, and ms.author metadata fields.
Assign User Or Group Access Portal
Doc updateThe enterprise application page received spelling corrections in its user, group, and app-role assignment guidance.
The page no longer includes the `manager` and `ms.author` metadata fields.
The daemon token acquisition documentation no longer includes the `manager` and `ms.author` fields.
The page no longer includes the author, manager, and ms.author metadata fields.
What is Microsoft Entra Cloud Sync?
Doc updateThe article now explains that enabled device synchronization can sync Active Directory computer objects to Microsoft Entra ID so devices can become hybrid joined, and links to configuration steps.
The article now explains that Microsoft Entra Cloud Sync can synchronize Active Directory computer objects to Microsoft Entra ID for hybrid join and links to configuration guidance.
Microsoft Entra Health
Doc updateCorrected a spelling error and updated punctuation in the Microsoft Entra Health article.
Zero Trust Ai
Doc updateThe page no longer includes the ms.author, author, or manager metadata fields.
Credential Management Api
Doc updateAction requiredThe article now links to a sample app demonstrating passkey listing and registration with delegated permissions and warns that its deletion flow uses high-privilege application permissions and a client secret in browser code.
Credential Management Api
Doc updateThe Microsoft Entra External ID credential management API reference was deleted, including guidance for passkey listing and registration, delegated permissions, authentication, and sample usage.
Corrected a spelling error in the explanation of “Report-only: Failure” results for the “Require app protection policy” control.
Multi Tenant Common Considerations
Doc updateThe documentation corrects wording and spacing in guidance about cross-tenant access policies, guest self-service sign-up, Conditional Access sign-in frequency, and governance.
Added a missing space between “authentication” and “and” in the documentation.
Troubleshoot Hybrid Join Windows Current
Doc updateThe Windows hybrid-join troubleshooting page received spelling and copy edits covering TPM errors, PRT checks, and Event Viewer guidance.
Microsoft Entra Agent ID
6 updatesAgent Access Packages
Doc updateThe documentation now states more clearly that an agent needs assigned OAuth delegated permissions to assist a user when accessing a target resource’s APIs.
Agent Access Packages
Doc updateAction requiredThe documentation now states that agent identities need delegated OAuth permissions for target resources, such as Microsoft Graph or an application, to assist users with API access.
Integrate N8n Agent
Doc updateThe n8n agent integration page no longer includes the `author` and `ms.author` metadata fields.
Call Api Azure Services
Doc updateThe documentation corrects spelling errors, including “credentials,” and adds missing punctuation to a step describing token credentials and Azure SDK clients.
The documentation now identifies the resource role as applying to an AI agent’s service principal or agent ID and adds numbered steps for selecting API permissions, permission type, required permissions, and updating the configuration.
Agent Id Governance Overview
Doc updateThe documentation now describes the linked guidance as covering delegated and application permissions for Microsoft Graph and applications.
Microsoft Entra ID Protection
1 updateIdentity Protection Unified Risk
Doc updateThe page no longer includes the `ms.author` and `author` metadata fields.
Microsoft Entra ID Governance
5 updatesCorrected spelling in the guest user licensing and governance documentation, including “governance-related.”
Externally determine the approval requirements for an access package using custom extensions
Doc updateThe entitlement management dynamic approval article received spelling corrections covering custom extensions, Logic Apps, approval setup, and HTTP trigger configuration.
Entitlement Management Catalog Create
Doc updateAdded a missing space after the bold “Prerequisite roles:” label. The linked role requirements are unchanged.
The documentation no longer includes the `author` and `ms.author` metadata fields.
The documentation updates wording across deployment scenarios, entitlement management, access reviews, separation of duties, birthright assignment, and Logic Apps guidance without changing the described capabilities or procedures.
Microsoft Entra External ID
7 updatesThe page title and description now use Microsoft Entra External ID terminology. Passkey sample links were updated from listing and registration to sign-in and management, and the sample table was revised.
The page now describes administrator-controlled passkey provisioning with the FIDO2 provisioning APIs and identifies the sample as testing-only with high-privilege permissions.
Sign In With Passkey
Doc updateThe documentation now describes a sample where signed-in customers list and register their own passkeys. It warns that the deletion flow uses high-privilege permissions and a client secret, so the sample is for test tenants only.
Faq Customers
Feature updateThe documentation now states that SMS is unavailable only for first-factor authentication in external tenants, indicating availability for self-service password reset. SMS remains available for second-factor verification at additional cost.
The Android custom headers tutorial no longer includes the author, manager, and ms.author metadata fields.
The page now links to a sample for listing and registering passkeys and documents delegated permissions for those operations. It also warns that deletion uses high-privilege application permissions and a client secret in browser code.
The custom policy analysis article no longer includes the `author` and `ms.author` metadata fields.
Microsoft Entra Internet Access
1 updatePalo Alto Coexistence
Doc updateThe service connection link text now uses “configuring” instead of the misspelled “configurating.”
Microsoft Entra Private Access
2 updatesPrivate Access Sensor Release History
Feature updateAction requiredVersion 2.2.79, released September 29, 2026, adds over-the-air sensor updates, enhanced Kerberos security and diagnostics, SID-based service matching, and corrected wildcard matching.
The guide now consistently spells “Multi-Geo,” including correcting a typo in the Japan region limitation.
Microsoft Entra Workload ID
1 updateManaged Identities Faq
Doc updateThe FAQ now uses “towards” instead of the misspelled “torwards” in its soft-deleted objects quota guidance.
Microsoft Entra Global Secure Access
7 updatesThe page no longer includes the `author` and `ms.author` metadata fields.
The documentation no longer includes the `author` and `ms.author` fields.
2) Detect browsers via registry only
Doc updateThe PowerShell prompt now correctly refers to the `IPv4Preferred` registry key instead of `IPv4Preffered`.
The article metadata field was corrected from `ms.reviwer` to `ms.reviewer`; the topic classification remains unchanged.
Global Secure Access egress IP ranges
Doc updateThe page no longer includes the `author` and `ms.author` metadata fields.
The page’s `author` and `ms.author` metadata fields were removed.
Secure Web Ai Gateway Agents
Doc updateThe documentation corrects “Web respositories” to “Web repositories” in an example of security rules.
