← Previous day

Keep up with Microsoft Entra

Daily AI-generated highlights from Microsoft Learn and Message Center. Browse the archive from 15 April 2025 → About this project →

Day in brief

Cloud Sync supports hybrid-join device synchronization; Private Access 2.2.79 adds OTA updates

The most consequential updates clarify Cloud Sync support for Microsoft Entra hybrid join and document the Private Access Sensor 2.2.79 release, including its upgrade prerequisites. Entra administrators also get a more precise SSPR authentication-method count and stronger External ID passkey sample warnings. Most other changes were spelling, metadata, naming, or presentation edits.

  • The migration decision guide now states that Cloud Sync supports device synchronization for Microsoft Entra hybrid join. Device synchronization must be enabled separately, with updated migration guidance and configuration steps. Administrators moving hybrid-joined devices should include this capability explicitly in their migration plan.

  • The release history records version 2.2.79, released September 29, 2026, with over-the-air sensor updates, enhanced Kerberos security and diagnostics, SID-based service matching, and corrected wildcard matching. Upgrading from version 2.2.42 requires a one-time full-installer deployment to enable OTA updates; inbound TCP and UDP port 1337 must be allowed, and IPv4 is required because IPv6 Kerberos traffic is blocked.

  • The SSPR guidance now states that Microsoft Authenticator, software OATH tokens, and hardware OATH tokens count as one authentication method, regardless of Authentication methods policy migration status. Administrators should use that shared count when evaluating SSPR method requirements.

  • The updated guidance describes administrator-controlled passkey provisioning through the FIDO2 provisioning APIs and identifies the sample as testing-only. Its deletion flow uses high-privilege permissions and a client secret in browser code, so the sample should not be deployed in production.

  • The FAQ now states that SMS is unavailable for first-factor authentication in external tenants while indicating availability for self-service password reset. SMS remains available for second-factor verification at additional cost, giving administrators a clearer basis for external-tenant SSPR planning.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

72 updates

9

Self-service password reset deep dive

Doc update

The guidance now states that Microsoft Authenticator, software OATH tokens, and hardware OATH tokens count as one authentication method for SSPR, regardless of Authentication methods policy migration status.

Sso Admin Control

Doc update

The documentation fixes minor formatting in the scope notes and corrects the image text from `HKEY_LOCAL_MACHIEN` to `HKEY_LOCAL_MACHINE`.

9

Microsoft Entra Cloud Sync migration decision guide

Feature updateAction required

The decision guide now states that Cloud Sync supports device synchronization for Microsoft Entra hybrid join. Device synchronization must be enabled separately, with updated migration guidance and configuration steps.

Migrate to Microsoft Entra Cloud Sync

Doc update

The guide now describes phased migration planning, including Cloud Sync device synchronization for Microsoft Entra hybrid join and prerequisite checks.

Common hybrid scenarios with Microsoft Entra ID

Feature update

The comparison table now lists Microsoft Entra Cloud Sync as supporting Microsoft Entra hybrid join and links to Cloud Sync device synchronization instructions. The article also expands comparisons across Cloud Sync, Connect Sync, MIM, and ECMA Host.

Understand Microsoft Entra Connect Sync

Doc update

The article now explains Cloud Sync as synchronizing users, groups, contacts, and devices, and links to device synchronization configuration guidance.

Tools used for synchronization

Doc update

The comparison article now includes devices among supported synchronization scenarios and notes that Cloud Sync can synchronize computer objects for Microsoft Entra hybrid join when device sync is enabled. It also adds a comparison table and selection wizard.

5

Connect Version History

Doc update

The version history page was updated with spelling fixes in existing release and feature descriptions.

Recover Objects

Doc update

Changed “cancelation” to “cancellation” in the recovery job instructions.

5
4
4

What is Microsoft Entra Cloud Sync?

Doc update

The article now explains that enabled device synchronization can sync Active Directory computer objects to Microsoft Entra ID so devices can become hybrid joined, and links to configuration steps.

What is a Microsoft Entra hybrid joined device?

Doc update

The article now explains that Microsoft Entra Cloud Sync can synchronize Active Directory computer objects to Microsoft Entra ID for hybrid join and links to configuration guidance.

Microsoft Entra Health

Doc update

Corrected a spelling error and updated punctuation in the Microsoft Entra Health article.

Zero Trust Ai

Doc update

The page no longer includes the ms.author, author, or manager metadata fields.

3

Credential Management Api

Doc updateAction required

The article now links to a sample app demonstrating passkey listing and registration with delegated permissions and warns that its deletion flow uses high-privilege application permissions and a client secret in browser code.

Credential Management Api

Doc update

The Microsoft Entra External ID credential management API reference was deleted, including guidance for passkey listing and registration, delegated permissions, authentication, and sample usage.

1

Multi Tenant Common Considerations

Doc update

The documentation corrects wording and spacing in guidance about cross-tenant access policies, guest self-service sign-up, Conditional Access sign-in frequency, and governance.

1
1
3

Agent Access Packages

Doc update

The documentation now states more clearly that an agent needs assigned OAuth delegated permissions to assist a user when accessing a target resource’s APIs.

Agent Access Packages

Doc updateAction required

The documentation now states that agent identities need delegated OAuth permissions for target resources, such as Microsoft Graph or an application, to assist users with API access.

Integrate N8n Agent

Doc update

The n8n agent integration page no longer includes the `author` and `ms.author` metadata fields.

1

Call Api Azure Services

Doc update

The documentation corrects spelling errors, including “credentials,” and adds missing punctuation to a step describing token credentials and Azure SDK clients.

1

Entitlement Management Access Package Resources

Doc update

The documentation now identifies the resource role as applying to an AI agent’s service principal or agent ID and adds numbered steps for selecting API permissions, permission type, required permissions, and updating the configuration.

1

Agent Id Governance Overview

Doc update

The documentation now describes the linked guidance as covering delegated and application permissions for Microsoft Graph and applications.

1
4
1
5

Microsoft Entra External ID app samples and guides

Doc update

The page title and description now use Microsoft Entra External ID terminology. Passkey sample links were updated from listing and registration to sign-in and management, and the sample table was revised.

Sign In With Passkey

Doc update

The documentation now describes a sample where signed-in customers list and register their own passkeys. It warns that the deletion flow uses high-privilege permissions and a client secret, so the sample is for test tenants only.

Faq Customers

Feature update

The documentation now states that SMS is unavailable only for first-factor authentication in external tenants, indicating availability for self-service password reset. SMS remains available for second-factor verification at additional cost.

1

Samples and guides for integrating apps with External ID

Doc update

The page now links to a sample for listing and registering passkeys and documents delegated permissions for those operations. It also warns that deletion uses high-privilege application permissions and a client secret in browser code.

1
1

Palo Alto Coexistence

Doc update

The service connection link text now uses “configuring” instead of the misspelled “configurating.”

2

Private Access Sensor Release History

Feature updateAction required

Version 2.2.79, released September 29, 2026, adds over-the-air sensor updates, enhanced Kerberos security and diagnostics, SID-based service matching, and corrected wildcard matching.

1

Managed Identities Faq

Doc update

The FAQ now uses “towards” instead of the misspelled “torwards” in its soft-deleted objects quota guidance.

4
1
1
1

Secure Web Ai Gateway Agents

Doc update

The documentation corrects “Web respositories” to “Web repositories” in an example of security rules.

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…