I like to make you aware of an important upcoming change for dynamic groups in Entra ID. In Entra ID you can create and manage dynamic groups which get devices or users as there members based on specific attributes, e.g. like department equals Marketing or else. No worries, this will still work but the “memberOf” will actually stop working after November 3rd, 2026. This could be used to nest groups, get users from one group in a dynamic group. But it was just a preview feature!
This means it was never intended for production use as a preview feature.
Although for a very long period of time because the public preview was announced on June 6, 2022. So four years. However, it ends this November 2026 and you need to take action if you were still testing or using this.
The end of the “memberOf”-preview also applies for dynamic administrative units and entitlement management.

What could you do? Hopefully you are using this just for a small amount of (test) groups which you can manually adjust to user other attributes and parameters to get the members into the dynamic group.
The better would be not to use this feature at all, also not using nested groups in Entra ID although there are options available for nesting groups. But nested groups can get quickly out of control and lose easily traceability. Better one group per purpose by utilizing a proper naming convention making the purpose visible at a glance.
Please note and read the most recent documentation thoroughly because before migrating away of the “memberOf” property Microsoft’s documentation states that you should export the group first of all. So, make a backup of all affected dynamic groups including their members etc. before you take action. Don’t forget to check the groups’ export that is readable and containing the expected content.
Conclusion, opinion and summary
Based on the current documentation I let Copilot draft a infographic providing a migration path. Please note I provide this as-is without warranty if the documentation changes or else changes it might be deprecated, not longer state-of-the-art or else.








Comment / Kommentar verfassen