The tutorial now refers to Zscaler instead of Zscaler Authentication Service Provisioning throughout its title, prerequisites, configuration steps, and Microsoft Entra app-gallery instructions.
MemberOf retirement deadline leads Microsoft Entra’s October administrator briefing
The week’s consequential change is the November 3, 2026 retirement of the MemberOf rule operator, which will stop MemberOf-based updates in dynamic groups, administrative units, and entitlement policies. The other updates are primarily documentation changes covering Private Access sensor 2.2.79, External ID passkey samples, and corrected Zscaler provisioning terminology.
- MemberOf rule operator retirement reaches its final reminder
Entra ID · Conditional Access
Microsoft Entra ID will retire the MemberOf operator on November 3, 2026. MemberOf-based updates will stop in dynamic groups, administrative units, and entitlement policies, creating risks for memberships, access, licensing, Conditional Access, and related services.
- Private Access sensor 2.2.79 adds OTA updates with migration prerequisites
Private Access · General
The September 29 release adds over-the-air sensor updates, enhanced Kerberos security and diagnostics, SID-based service matching, and corrected wildcard matching. Upgrading from version 2.2.42 requires a one-time full-installer deployment to enable OTA updates, with inbound TCP and UDP port 1337 allowed.
- External ID passkey sample adds delegated permissions and deletion warning
External ID · Developer
The guidance now links to a sample for listing and registering passkeys and documents the delegated permissions required. Its deletion flow uses high-privilege application permissions and a client secret in browser code, so the sample is for test tenants only.
- Zscaler ZSNet naming now matches the Entra gallery entry
Entra ID · Provisioning
The provisioning tutorial replaces “Zscaler ZNet” with “Zscaler ZSNet” in the title, prerequisites, gallery search instructions, and provisioning steps. Administrators should search for and select Zscaler ZSNet in the Microsoft Entra application gallery.
- Zscaler provisioning tutorial adopts the current app name
Entra ID · Provisioning
A separate provisioning tutorial now consistently uses “Zscaler” instead of “Zscaler Authentication Service” across its title, prerequisites, configuration steps, and Microsoft Entra app-gallery instructions.
Replace MemberOf configurations before November 3, 2026. For Private Access, upgrades from version 2.2.42 require a one-time full-installer deployment; allow inbound TCP and UDP on port 1337, and use IPv4 for Kerberos because IPv6 Kerberos traffic is blocked. Treat the passkey deletion sample as test-tenant-only and use the corrected Zscaler app names when following provisioning guides.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
Updates this week
Microsoft Entra ID
4 updatesThe tutorial now consistently refers to Zscaler ZSNet instead of Zscaler ZNet, including the title, prerequisites, gallery search instructions, and provisioning steps.
Microsoft Entra ID will retire the MemberOf rule operator by November 3, 2026. Organizations must replace MemberOf in dynamic groups, administrative units, and entitlement policies to avoid outdated memberships, access, and licensing issues. After this date, MemberOf-based updates will stop, impacting Conditional Access and related services.
Credential Management Api
Doc updateAction requiredThe article now links to a sample app demonstrating passkey listing and registration with delegated permissions and warns that its deletion flow uses high-privilege application permissions and a client secret in browser code.
Microsoft Entra External ID
2 updatesSign In With Passkey
Doc updateThe documentation now describes a sample where signed-in customers list and register their own passkeys. It warns that the deletion flow uses high-privilege permissions and a client secret, so the sample is for test tenants only.
The page now links to a sample for listing and registering passkeys and documents delegated permissions for those operations. It also warns that deletion uses high-privilege application permissions and a client secret in browser code.
Microsoft Entra Private Access
1 updatePrivate Access Sensor Release History
Feature updateAction requiredVersion 2.2.79, released September 29, 2026, adds over-the-air sensor updates, enhanced Kerberos security and diagnostics, SID-based service matching, and corrected wildcard matching.
