# Guidance for using Group Source of Authority (SOA) (Preview)
Managing groups across hybrid environments is essential for organizations that transition from on-premises Active Directory (AD) to the cloud. Group Source of Authority (SOA) in Microsoft Entra ID enables you to transfer group management from AD to the cloud, providing greater flexibility, modern governance, and streamlined administration. This guidance explains how to use Group SOA to manage, provision, restore, and roll back groups in hybrid and cloud environments. It explains best practices to clean up groups, convert group management, and ensure secure, efficient access control as you modernize your identity infrastructure.
## AD group cleanup
One challenge many organizations face is the proliferation of groups, particularly security groups, in their Active Directory domains. An organization might create security groups that are no longer needed after projects complete. These groups can linger unmaintained in the domain.
Microsoft Entra ID provides self-service group management through My Groups for Microsoft 365 and non-mail-enabled security groups. Microsoft Entra ID Governance enables access management through My Access, where you can manage groups with access packages. Access packages allow users to request access to groups as part of a structured governance framework. However, these solutions don't exactly replicate the self-service group management capabilities in Microsoft Identity Manager due to differences in on-premises and cloud solutions.
To transition self-service group management from on-premises AD groups, you can modernize applications and leverage cloud-based security groups and Microsoft 365 groups. For more information, see [Self-service group management guidance for Group Source of Authority (SOA)](how-to-source-of-authority-self-service-group-management.md).
### Manage on-premises apps tied to Microsoft 365 groups
To manage and govern AD-based apps, you can provision Microsoft 365 groups to AD with Group Writeback in Microsoft Entra Connect sync.
But you can't choose which groups to provision to AD.
### On-premises changes to cloud-owned security groups are overwritten
# Guidance for using Group Source of Authority (SOA) (Preview)
Managing groups across hybrid environments is essential for organizations that transition from on-premises Active Directory Domain Services (AD DS) to the cloud. Group Source of Authority (SOA) in Microsoft Entra ID enables you to transfer group management from AD DS to the cloud, providing greater flexibility, modern governance, and streamlined administration. This guidance explains how to use Group SOA to manage, provision, restore, and roll back groups in hybrid and cloud environments. It explains best practices to clean up groups, convert group management, and ensure secure, efficient access control as you modernize your identity infrastructure.
## AD DS group cleanup
One challenge many organizations face is the proliferation of groups, particularly security groups, in their Active Directory domains. An organization might create security groups that are no longer needed after projects complete. These groups can linger unmaintained in the domain.
Microsoft Entra ID provides self-service group management through My Groups for Microsoft 365 and non-mail-enabled security groups. Microsoft Entra ID Governance enables access management through My Access, where you can manage groups with access packages. Access packages allow users to request access to groups as part of a structured governance framework. However, these solutions don't exactly replicate the self-service group management capabilities in Microsoft Identity Manager due to differences in on-premises and cloud solutions.
To transition self-service group management from on-premises AD DS groups, you can modernize applications and leverage cloud-based security groups and Microsoft 365 groups. For more information, see [Self-service group management guidance for Group Source of Authority (SOA)](how-to-source-of-authority-self-service-group-management.md).
### Manage on-premises apps tied to Microsoft 365 groups
To manage and govern AD DS-based apps, you can provision Microsoft 365 groups to AD DS with Group Writeback in Microsoft Entra Connect sync.
But you can't choose which groups to provision to AD DS.
### On-premises changes to cloud-owned security groups are overwritten