Microsoft Warns Entra ID MemberOf Rules Will Stop Working


entra id sspr
Image credit: Microsoft

Microsoft will retire the MemberOf rule operator in Microsoft Entra ID on November 3, 2026, forcing administrators to redesign dynamic groups and policies that rely on nested group membership.

The company announced the change in the Microsoft 365 Message Center notice MC1448379. After the deadline, Entra ID configurations that still use the operator will stop processing membership changes in the background.

Existing group memberships will become frozen

Microsoft will not immediately delete groups or policies that use MemberOf. Instead, their membership data will remain frozen at the last successfully processed state.

This could leave Microsoft 365 group memberships outdated as users change roles, departments, or access requirements. Conditional Access rules tied to affected groups may also stop reflecting current organizational structures.

Licensing assignments present another concern. Users could retain licenses they no longer need, while others might fail to receive required licenses because their group membership no longer updates.

Dynamic administrative units and entitlement management policies that depend on nested groups could face similar problems.

Microsoft says MemberOf does not scale efficiently

Microsoft says it is removing the operator because its underlying processing model does not scale well in large environments.

A single MemberOf rule can reportedly slow membership calculations across an entire tenant, including dynamic groups that do not use the operator. Microsoft decided to retire the feature rather than expand its availability or continue supporting its performance limitations.

The decision has frustrated some administrators because Microsoft has not provided a direct replacement that reproduces the same nested group logic.

Administrators must rebuild affected rules

Identity and Access Management teams will need to identify every dynamic group, administrative unit, and entitlement policy that contains MemberOf conditions.

Microsoft Graph PowerShell can help administrators search dynamic membership rules across a tenant. The Entra Admin Center export tools can also help locate affected configurations.

Microsoft recommends replacing nested group checks with direct user or device attribute filters wherever possible. For example, administrators could build rules around department, job title, office location, device ownership, or another synchronized directory attribute.

Organizations that cannot reproduce their existing logic with attributes may need to replace dynamic groups with manually maintained static groups.

This migration could require significant work in tenants that use nested group structures for access control, licensing, application assignments, and entitlement management. Administrators should complete the transition before November 3, 2026, to reduce the risk of security gaps and inconsistent licensing.

In other news, Microsoft urges Windows 10 LTSC users to upgrade before support ends. Experts also speculate that Windows 11 26H2 might release between September and October.

Lastly, the company has reportedly installed the OneDrive Photos app on enterprise PCs without prior notice.

Via Neowin

More about the topics: microsoft, microsoft entra

Readers help support Windows Report. We may get a commission if you buy through our links. Tooltip Icon

Read our disclosure page to find out how can you help Windows Report sustain the editorial team. Read more

User forum

0 messages