The article was edited for spelling, headings, and presentation while retaining its documented enforcement phases, dates, affected applications, account scope, and break-glass guidance.
Keep up with Microsoft Entra
Daily AI-generated highlights from Microsoft Learn and Message Center. Browse the archive from 15 April 2025 → About this project →
Private Access sensor 2.2.79 adds OTA updates; passkey sample is test-only
This was a documentation-heavy day: all 31 recorded items were updates, with no new or removed entries and no Message Center notices. Most changes were spelling, formatting, metadata, or wording corrections. The meaningful exceptions were a Private Access sensor release-history update, new External ID passkey sample guidance, an SMS availability clarification, and corrected Zscaler ZSNet onboarding terminology.
- Private Access sensor 2.2.79 documents OTA updates and deployment requirements
Private Access · General
The release history records version 2.2.79, released September 29, 2026, as adding over-the-air sensor updates, enhanced Kerberos security and diagnostics, SID-based service matching, and corrected wildcard matching. Upgrading from version 2.2.42 requires a one-time full-installer deployment to enable OTA updates; inbound TCP and UDP port 1337 must be allowed, and IPv6 Kerberos traffic is blocked, so IPv4 is required.
- External ID passkey sample adds delegated-permission guidance and a security warning
External ID · Developer
The updated material links to a sample for listing and registering passkeys and documents the delegated permissions for those operations. Its deletion flow uses high-privilege application permissions and a client secret in browser code, so the sample is intended only for a test tenant and should not be deployed to production.
- External tenants can use SMS for password reset and second-factor verification
External ID · Authentication
The customer FAQ now specifies that SMS is unavailable only for first-factor authentication in external tenants. SMS remains available for self-service password reset and for second-factor verification at additional cost.
- Zscaler provisioning guidance now points administrators to Zscaler ZSNet
Entra ID · Provisioning
The tutorial consistently replaces “Zscaler ZNet” with “Zscaler ZSNet” in its title, prerequisites, gallery search instructions, and provisioning steps. Administrators following the procedure should search for and select Zscaler ZSNet in the Microsoft Entra application gallery.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
31 updates
Microsoft Entra ID
17 updatesThe native authentication API reference was updated with spelling corrections. The supplied examples, links, endpoints, error details, and configuration guidance remain unchanged.
The tutorial’s code comment was corrected from “Thge” to “The” and from “rquired” to “required.”
The article fixes the spelling of “OpenID Connect” and replaces an empty .NET NuGet link with an Azure Functions API link, along with other wording corrections.
Sso Admin Control
Doc updateThe documentation fixes minor formatting in the scope notes and corrects the image text from `HKEY_LOCAL_MACHIEN` to `HKEY_LOCAL_MACHINE`.
The tutorial received spelling and wording corrections across its SAML attribute mapping, authentication policy, testing, and account discovery sections.
Connect Version History
Doc updateThe version history page was updated with spelling fixes in existing release and feature descriptions.
Recover Objects
Doc updateChanged “cancelation” to “cancellation” in the recovery job instructions.
The tutorial now refers to Zscaler instead of Zscaler Authentication Service Provisioning throughout its title, prerequisites, configuration steps, and Microsoft Entra app-gallery instructions.
The tutorial now consistently refers to Zscaler ZSNet instead of Zscaler ZNet, including the title, prerequisites, gallery search instructions, and provisioning steps.
Credential Management Api
Doc updateAction requiredThe article now links to a sample app demonstrating passkey listing and registration with delegated permissions and warns that its deletion flow uses high-privilege application permissions and a client secret in browser code.
Corrected a spelling error in the explanation of “Report-only: Failure” results for the “Require app protection policy” control.
Multi Tenant Common Considerations
Doc updateThe documentation corrects wording and spacing in guidance about cross-tenant access policies, guest self-service sign-up, Conditional Access sign-in frequency, and governance.
Added a missing space between “authentication” and “and” in the documentation.
Assign User Or Group Access Portal
Doc updateThe enterprise application page received spelling corrections in its user, group, and app-role assignment guidance.
Microsoft Entra Health
Doc updateCorrected a spelling error and updated punctuation in the Microsoft Entra Health article.
Troubleshoot Hybrid Join Windows Current
Doc updateThe Windows hybrid-join troubleshooting page received spelling and copy edits covering TPM errors, PRT checks, and Event Viewer guidance.
Microsoft Entra Agent ID
1 updateCall Api Azure Services
Doc updateThe documentation corrects spelling errors, including “credentials,” and adds missing punctuation to a step describing token credentials and Azure SDK clients.
Microsoft Entra ID Governance
3 updatesCorrected spelling in the guest user licensing and governance documentation, including “governance-related.”
Externally determine the approval requirements for an access package using custom extensions
Doc updateThe entitlement management dynamic approval article received spelling corrections covering custom extensions, Logic Apps, approval setup, and HTTP trigger configuration.
The documentation updates wording across deployment scenarios, entitlement management, access reviews, separation of duties, birthright assignment, and Logic Apps guidance without changing the described capabilities or procedures.
Microsoft Entra External ID
3 updatesSign In With Passkey
Doc updateThe documentation now describes a sample where signed-in customers list and register their own passkeys. It warns that the deletion flow uses high-privilege permissions and a client secret, so the sample is for test tenants only.
Faq Customers
Feature updateThe documentation now states that SMS is unavailable only for first-factor authentication in external tenants, indicating availability for self-service password reset. SMS remains available for second-factor verification at additional cost.
The page now links to a sample for listing and registering passkeys and documents delegated permissions for those operations. It also warns that deletion uses high-privilege application permissions and a client secret in browser code.
Microsoft Entra Internet Access
1 updatePalo Alto Coexistence
Doc updateThe service connection link text now uses “configuring” instead of the misspelled “configurating.”
Microsoft Entra Private Access
2 updatesPrivate Access Sensor Release History
Feature updateAction requiredVersion 2.2.79, released September 29, 2026, adds over-the-air sensor updates, enhanced Kerberos security and diagnostics, SID-based service matching, and corrected wildcard matching.
The guide now consistently spells “Multi-Geo,” including correcting a typo in the Japan region limitation.
Microsoft Entra Workload ID
1 updateManaged Identities Faq
Doc updateThe FAQ now uses “towards” instead of the misspelled “torwards” in its soft-deleted objects quota guidance.
Microsoft Entra Global Secure Access
3 updates2) Detect browsers via registry only
Doc updateThe PowerShell prompt now correctly refers to the `IPv4Preferred` registry key instead of `IPv4Preffered`.
The article metadata field was corrected from `ms.reviwer` to `ms.reviewer`; the topic classification remains unchanged.
Secure Web Ai Gateway Agents
Doc updateThe documentation corrects “Web respositories” to “Web repositories” in an example of security rules.
