πŸ“‹ Microsoft Entra Documentation Changes

Daily summary for changes since July 31st 2025, 8:38 PM PDT

Report generated on August 1st 2025, 8:38 PM PDT

πŸ“Š Summary

42
Total Commits
0
New Files
16
Modified Files
0
Deleted Files
13
Contributors

πŸ“ Modified Documentation Files

+289 / -148 lines changed
Commit: GA of app authentication
Changes:
Before
After
ms.service: entra-id
ms.topic: conceptual
ms.tgt_pltfrm: na
ms.date: 04/25/2025
ms.subservice: hybrid
ms.author: jomondi
---
 
Microsoft Entra Connect provides three options for application and certificate management:
 
- [Managed by Microsoft Entra Connect (recommended)](#managed-by-microsoft-entra-connect-recommended)
- [Bring Your Own Application (BYOA)](#bring-your-own-application)
- [Bring Your Own Certificate (BYOC)](#bring-your-own-certificate)
 
## Managed by Microsoft Entra Connect (recommended)
 
Microsoft Entra Connect manages the application and certificate, which includes creation, rotation, and deletion of the certificate. The certificate is stored in the `CURRENT_USER` store. For optimal protection of the certificate's private key, we recommend that the machine should use a Trusted Platform Module (TPM) solution to establish a hardware-based security boundary.
 
 
:::image type="content" source="media/authenticate-application-id/auth-1.png" alt-text="Diagram that shows authentication with application ID." lightbox="media/authenticate-application-id/auth-1.png":::
ms.service: entra-id
ms.topic: conceptual
ms.tgt_pltfrm: na
ms.date: 07/24/2025
ms.subservice: hybrid
ms.author: jomondi
---
 
Microsoft Entra Connect provides three options for application and certificate management:
 
- [Managed by Microsoft Entra Connect (default)](#managed-by-microsoft-entra-connect-default)
- [Bring Your Own Application (BYOA)](#bring-your-own-application)
- [Bring Your Own Certificate (BYOC)](#bring-your-own-certificate)
 
## Managed by Microsoft Entra Connect (default)
 
Microsoft Entra Connect manages the application and certificate, which includes creation, rotation, and deletion of the certificate. The certificate is stored in the `CURRENT_USER` store. For optimal protection of the certificate's private key, we recommend that the machine should use a Trusted Platform Module (TPM) solution to establish a hardware-based security boundary.
 
 
:::image type="content" source="media/authenticate-application-id/auth-1.png" alt-text="Diagram that shows authentication with application ID." lightbox="media/authenticate-application-id/auth-1.png":::
+27 / -21 lines changed
Commit: New version
Changes:
Before
After
ms.service: entra-id
manager: mwongerapk
ms.topic: reference
ms.date: 04/09/2025
ms.subservice: hybrid-connect
ms.author: jomondi
ms.custom: no-azure-ad-ps-ref, sfi-ga-nochange
---
 
# Microsoft Entra Connect: Version release history
|[2.4.27.0](#24270)|15 Jan 2026 (12 months after release of 2.4.129.0)|
|[2.4.129.0](#241290)|27 Mar 2026 (12 months after release of 2.4.131.0)|
|[2.4.131.0](#241310)|26 May 2026 (12 months after release of 2.5.3.0)|
|[2.5.3.0](#2530)||
 
**All other versions are not supported**
 
 
If you run a retired version of Microsoft Entra Connect, it might unexpectedly stop working. You also might not have the latest security fixes, performance improvements, troubleshooting and diagnostic tools, and service enhancements. If you require support, we might not be able to provide you with the level of service your organization needs.
 
ms.service: entra-id
manager: mwongerapk
ms.topic: reference
ms.date: 08/01/2025
ms.subservice: hybrid-connect
ms.author: jomondi
ms.custom: no-azure-ad-ps-ref, sfi-ga-nochange
 
#customer-intent: As a Microsoft Entra administrator, I want to learn about the latest version of Microsoft Entra Connect, so that I can keep my environment up to date.
---
 
# Microsoft Entra Connect: Version release history
|[2.4.27.0](#24270)|15 Jan 2026 (12 months after release of 2.4.129.0)|
|[2.4.129.0](#241290)|27 Mar 2026 (12 months after release of 2.4.131.0)|
|[2.4.131.0](#241310)|26 May 2026 (12 months after release of 2.5.3.0)|
|[2.5.3.0](#2530)|31 July 2026 (12 months after release of 2.5.76.0)|
|[2.5.76.0](#25760)||
 
**All other versions are not supported**
 
Modified by csmulligan on Aug 1, 2025 4:54 PM
πŸ“– View on learn.microsoft.com
+18 / -8 lines changed
Commit: What's new in July?.
Changes:
Before
After
 
# [External ID in external tenants](#tab/external-tenants)
 
## June 2025
 
### Updated articles
 
## March 2025
 
### New articles
 
- [Migrating users to Microsoft Entra External ID](customers/how-to-migrate-users.md)
 
 
# [External ID in workforce tenants](#tab/workforce-tenants)
 
## March 2025
 
### Updated articles
- [Add federation with SAML/WS-Fed identity providers](direct-federation.md) - Editorial updates
 
# [External ID in external tenants](#tab/external-tenants)
 
## July 2025
 
### New article
 
- [Supported features in workforce and external tenants](customers/how-to-add-enterprise-application.md)
 
### Updated articles
 
- [Register a SAML app in your external tenant](customers/how-to-register-saml-app.md) - Enterprise applications and SAML SSO are generally available
- [Supported features in workforce and external tenants](customers/concept-supported-features-customers.md) - Added enterprise applications update
 
## June 2025
 
### Updated articles
 
## March 2025
 
Modified by Martin Coetzer on Aug 1, 2025 9:13 PM
πŸ“– View on learn.microsoft.com
+12 / -13 lines changed
Commit: Update entra-delivery-guide.md
Changes:
Before
After
ms.author: martinco
#CustomerIntent: As a Microsoft Entra Suite customer, I want to deploy all components of the Microsoft Entra Suite.
---
# Microsoft Entra Suite Workshop Delivery Guide
## Overview
The [Microsoft Entra Suite Workshop](https://aka.ms/EntraSuiteWorkshop) helps customers to develop an actionable and orderly strategy for implementing the Microsoft Entra Suite. The workshop consists of five stages to help streamline all products and features in the suite. The first two stages are required to establish the correct foundation for deploying the products in the suite and should be completed before moving to the last three stages of the workshop. The following stages are available in the workshop:
- Establish a baseline
- Getting started
Customers can choose to deploy all the stages or just a subset of them depending on their priorities and resource availability. While the workshops are modular, customers are encouraged to start with Onboarding your workforce.
## Target Customer
The ideal customer for this engagement:
1. Understands and aligns to the Microsoft Identity security vision.
2. Has the intent and resources to invest in projects to deploy Microsoft Security products
## Alignment with Microsoft recommendations
The content of the Microsoft Entra Suite Workshop will be updated when the Zero Trust Workshop gets updated, most recommendations are aligned with the Zero Trust Security Deployment Guidance:
ms.author: martinco
#CustomerIntent: As a Microsoft Entra Suite customer, I want to deploy all components of the Microsoft Entra Suite.
---
# Microsoft Entra Suite workshop delivery guide
## Overview
The [Microsoft Entra Suite workshop](https://aka.ms/EntraSuiteWorkshop) helps customers to develop an actionable and orderly strategy for implementing the Microsoft Entra Suite. The workshop consists of five stages to help streamline all products and features in the suite. The first two stages are required to establish the correct foundation for deploying the products in the suite and should be completed before moving to the last three stages of the workshop. The following stages are available in the workshop:
- Establish a baseline
- Getting started
Customers can choose to deploy all the stages or just a subset of them depending on their priorities and resource availability. While the workshops are modular, customers are encouraged to start with Onboarding your workforce.
## Target customer
The ideal customer for this engagement:
- Understands and aligns to the Microsoft Identity security vision.
- Has the intent and resources to invest in projects to deploy Microsoft Security products
## Alignment with Microsoft recommendations
The content of the Microsoft Entra Suite Workshop will be updated when the Zero Trust Workshop gets updated, most recommendations are aligned with the Zero Trust Security Deployment Guidance:
+10 / -10 lines changed
Commit: fixed AD references
Changes:
Before
After
 
# Guidance for using Group Source of Authority (SOA) (Preview)
 
Managing groups across hybrid environments is essential for organizations that transition from on-premises Active Directory (AD) to the cloud. Group Source of Authority (SOA) in Microsoft Entra ID enables you to transfer group management from AD to the cloud, providing greater flexibility, modern governance, and streamlined administration. This guidance explains how to use Group SOA to manage, provision, restore, and roll back groups in hybrid and cloud environments. It explains best practices to clean up groups, convert group management, and ensure secure, efficient access control as you modernize your identity infrastructure.
 
## AD group cleanup
 
One challenge many organizations face is the proliferation of groups, particularly security groups, in their Active Directory domains. An organization might create security groups that are no longer needed after projects complete. These groups can linger unmaintained in the domain.
 
 
Microsoft Entra ID provides self-service group management through My Groups for Microsoft 365 and non-mail-enabled security groups. Microsoft Entra ID Governance enables access management through My Access, where you can manage groups with access packages. Access packages allow users to request access to groups as part of a structured governance framework. However, these solutions don't exactly replicate the self-service group management capabilities in Microsoft Identity Manager due to differences in on-premises and cloud solutions.
 
To transition self-service group management from on-premises AD groups, you can modernize applications and leverage cloud-based security groups and Microsoft 365 groups. For more information, see [Self-service group management guidance for Group Source of Authority (SOA)](how-to-source-of-authority-self-service-group-management.md).
 
### Manage on-premises apps tied to Microsoft 365 groups
 
To manage and govern AD-based apps, you can provision Microsoft 365 groups to AD with Group Writeback in Microsoft Entra Connect sync.
But you can't choose which groups to provision to AD.
 
### On-premises changes to cloud-owned security groups are overwritten
 
# Guidance for using Group Source of Authority (SOA) (Preview)
 
Managing groups across hybrid environments is essential for organizations that transition from on-premises Active Directory Domain Services (AD DS) to the cloud. Group Source of Authority (SOA) in Microsoft Entra ID enables you to transfer group management from AD DS to the cloud, providing greater flexibility, modern governance, and streamlined administration. This guidance explains how to use Group SOA to manage, provision, restore, and roll back groups in hybrid and cloud environments. It explains best practices to clean up groups, convert group management, and ensure secure, efficient access control as you modernize your identity infrastructure.
 
## AD DS group cleanup
 
One challenge many organizations face is the proliferation of groups, particularly security groups, in their Active Directory domains. An organization might create security groups that are no longer needed after projects complete. These groups can linger unmaintained in the domain.
 
 
Microsoft Entra ID provides self-service group management through My Groups for Microsoft 365 and non-mail-enabled security groups. Microsoft Entra ID Governance enables access management through My Access, where you can manage groups with access packages. Access packages allow users to request access to groups as part of a structured governance framework. However, these solutions don't exactly replicate the self-service group management capabilities in Microsoft Identity Manager due to differences in on-premises and cloud solutions.
 
To transition self-service group management from on-premises AD DS groups, you can modernize applications and leverage cloud-based security groups and Microsoft 365 groups. For more information, see [Self-service group management guidance for Group Source of Authority (SOA)](how-to-source-of-authority-self-service-group-management.md).
 
### Manage on-premises apps tied to Microsoft 365 groups
 
To manage and govern AD DS-based apps, you can provision Microsoft 365 groups to AD DS with Group Writeback in Microsoft Entra Connect sync.
But you can't choose which groups to provision to AD DS.
 
### On-premises changes to cloud-owned security groups are overwritten
+5 / -5 lines changed
Commit: acrolinx fixes
Changes:
Before
After
---
title: Configure Group Source of Authority (SOA) in Microsoft Entra ID (Preview)
description: Learn how to convert group management from Active Directory Domain Services (AD DS) to Microsoft Entra ID by using Group Source of Authority (SOA), including prerequisites, setup, validation, and how to rollback.
author: Justinha
manager: dougeby
ms.topic: how-to
 
## Limitations
 
- **No reconciliation support for local AD groups**: An AD admin (or an application with sufficient permissions) can directly modify an AD group. If SOA is applied to the object or if cloud security group provisioning to AD is enabled, those local AD changes aren't reflected in Microsoft Entra ID. When a change to the cloud security group is made, any local AD changes are overwritten if group provisioning to AD is enabled.
 
- **No dual write allowed**: After you start to manage the memberships for the converted group (say cloud group A) from Microsoft Entra ID, and you provision this group to AD using **Group Provision to AD** as a nested group under another AD group (OnPremGroupB) that's in scope for AD to Entra ID sync, the membership reference of group A won't be synced when sync happens for OnPremGroupB. They won't be synced because the sync client doesn't know the cloud group membership references. This behavior is by design.
 
- **No SOA conversion of nested groups**: If there are nested groups in AD and want to convert the SOA of the parent or top group from AD to Microsoft Entra ID, only the parent group’s SOA is converted. Nested groups in the parent group continue to be AD groups. You need to convert the SOA of any nested groups one-by-one. We recommend you start with the group that is lowest hierarchy, and move up the tree.
 
- **Extension Attributes (1-15)**: Extension attributes 1 – 15 aren't supported on cloud security groups and aren't supported after SOA is converted.
 
## Related content
 
---
title: Configure Group Source of Authority (SOA) in Microsoft Entra ID (Preview)
description: Learn how to convert group management from Active Directory Domain Services (AD DS) to Microsoft Entra ID by using Group Source of Authority (SOA), including prerequisites, setup, validation, and how to roll back.
author: Justinha
manager: dougeby
ms.topic: how-to
 
## Limitations
 
- **No reconciliation support for local AD groups**: An AD DS admin (or an application with sufficient permissions) can directly modify an AD DS group. If Group SOA is converted for the group, or if cloud security group provisioning to AD DS is enabled, those local AD changes aren't reflected in Microsoft Entra ID. When a change to the cloud security group is made, any local AD DS changes are overwritten when group provisioning to AD DS runs.
 
- **No dual write allowed**: After you start to manage the memberships for the converted group (say cloud group A) from Microsoft Entra ID, and you provision this group to AD as a nested group under another AD DS group (OnPremGroupB) that's in scope for sync to Microsoft Entra ID, the membership references of group A aren't synced when sync happens for OnPremGroupB. The membership references aren't synced because the sync client doesn't know the cloud group membership references. This behavior is by design.
 
- **No SOA conversion of nested groups**: If there are nested groups in AD DS, and you want to convert the SOA of the parent group or top group to Microsoft Entra ID, only the parent group SOA is converted. Nested groups in the parent group continue to be AD DS groups. You need to convert the SOA of any nested groups one-by-one. We recommend you start with the group that is lowest in the hierarchy, and move up the tree.
 
- **No support for extension attributes (1-15)**: Extension attributes 1–15 aren't supported on cloud security groups and aren't supported after SOA is converted.
 
## Related content
 
+4 / -4 lines changed
Commit: spell check
Changes:
Before
After
author: justinha
ms.service: entra-id-governance
ms.topic: include
ms.date: 07/31/2025
ms.author: justinha
# Used by articles entra governance
---
 
## Prerequisites
 
The following prerequisites are required to implement this scenario.
 
- Microsoft Entra account with at least a [Hybrid Identity Administrator](~/identity/role-based-access-control/permissions-reference.md#hybrid-identity-administrator) role.
 
> These permissions aren't applied to AdminSDHolder objects by default by the [Microsoft Entra provisioning agent gMSA PowerShell cmdlets](~/identity/hybrid/cloud-sync/how-to-gmsa-cmdlets.md#grant-permissions-to-a-specific-domain).
 
 
- The provisioning agent must be able to communicate with one or more domain controllers on the port TCP/389 for Lightweight Directory Access Protocol (LDAP) and TCP/3268 for global catalog.
- Required for global catalog lookup to filter out invalid membership references.
 
author: justinha
ms.service: entra-id-governance
ms.topic: include
ms.date: 08/01/2025
ms.author: justinha
# Used by articles entra governance
---
 
## Prerequisites
 
The following prerequisites are required to implement this scenario:
 
- Microsoft Entra account with at least a [Hybrid Identity Administrator](~/identity/role-based-access-control/permissions-reference.md#hybrid-identity-administrator) role.
 
> These permissions aren't applied to AdminSDHolder objects by default by the [Microsoft Entra provisioning agent gMSA PowerShell cmdlets](~/identity/hybrid/cloud-sync/how-to-gmsa-cmdlets.md#grant-permissions-to-a-specific-domain).
 
 
- The provisioning agent must be able to communicate with one or more domain controllers on the port TCP/389 for Lightweight Directory Access Protocol (LDAP) and TCP/3268 for Global Catalog.
- Required for Global Catalog lookup to filter out invalid membership references.
 
+3 / -3 lines changed
Commit: spell check
Changes:
Before
After
author: Justinha
manager: dougeby
ms.topic: how-to
ms.date: 07/31/2025
ms.author: justinha
ms.reviewer: justinha
---
 
- This article focuses on Security and Distribution List (DL) groups in
an AD DS topology, with a single forest, single domain.
Multiforest, non-AD DS environments, and local groups on domain-joined
computers, are outside the scope of this version of the article.
 
- This article focuses on groups whose members are users and other
groups that are in scope for sync to Microsoft Entra.
author: Justinha
manager: dougeby
ms.topic: how-to
ms.date: 08/01/2025
ms.author: justinha
ms.reviewer: justinha
---
 
- This article focuses on Security and Distribution List (DL) groups in
an AD DS topology, with a single forest, single domain.
Multiforest environments, workgroups, local groups on domain-joined
computers, or other environments are outside the scope of this article.
 
- This article focuses on groups whose members are users and other
groups that are in scope for sync to Microsoft Entra.
+2 / -2 lines changed
Commit: spell check
Changes:
Before
After
author: Justinha
manager: dougeby
ms.topic: concept-article
ms.date: 07/30/2025
ms.author: justinha
ms.reviewer: dhanyak
---
```
 
 
You can also store the OU information in some other attribute also like *info* or any other custom attribute. For more information about how to sync custom attributes, see [Custom attribute mapping](/entra/identity/hybrid/cloud-sync/tutorial-directory-extension-group-provisioning).
 
## Step 2: Enable sync for extensionAttribute13 in Microsoft Entra Cloud Sync or Connect Sync
 
author: Justinha
manager: dougeby
ms.topic: concept-article
ms.date: 08/01/2025
ms.author: justinha
ms.reviewer: dhanyak
---
```
 
 
You can also store the OU information in some other attribute like *info* or any other custom attribute. For more information about how to sync custom attributes, see [Custom attribute mapping](/entra/identity/hybrid/cloud-sync/tutorial-directory-extension-group-provisioning).
 
## Step 2: Enable sync for extensionAttribute13 in Microsoft Entra Cloud Sync or Connect Sync
 
+2 / -2 lines changed
Commit: spell check
Changes:
Before
After
manager: mwongerapk
ms.service: entra-id
ms.topic: how-to
ms.date: 07/25/2025
ms.subservice: hybrid-cloud-sync
ms.author: jomondi
ms.custom: no-azure-ad-ps-ref, sfi-image-nochange
 
# Tutorial - Provision groups to Active Directory Domain Services by using Microsoft Entra Cloud Sync
 
This tutorial walks you through how to confifure Cloud Sync to sync groups to on-premises Active Directory Domain Services (AD DS).
 
> [!IMPORTANT]
> We recommend using **Selected security groups** as the default scoping filter when you configure group provisioning to AD DS. This default scoping filter helps prevent any performance issues when you provision groups.
manager: mwongerapk
ms.service: entra-id
ms.topic: how-to
ms.date: 08/01/2025
ms.subservice: hybrid-cloud-sync
ms.author: jomondi
ms.custom: no-azure-ad-ps-ref, sfi-image-nochange
 
# Tutorial - Provision groups to Active Directory Domain Services by using Microsoft Entra Cloud Sync
 
This tutorial walks you through how to configure Cloud Sync to sync groups to on-premises Active Directory Domain Services (AD DS).
 
> [!IMPORTANT]
> We recommend using **Selected security groups** as the default scoping filter when you configure group provisioning to AD DS. This default scoping filter helps prevent any performance issues when you provision groups.
+2 / -2 lines changed
Commit: spell check
Changes:
Before
After
author: justinha
manager: dougeby
ms.topic: conceptual
ms.date: 07/31/2025
ms.author: justinha
ms.reviewer: dahnyahk
---
 
## Seamless integration with security group provisioning to AD DS
 
To provision a security group cloud that's not mail-enabled back to AD DS and sync it with Microsoft Entra ID, add the group to the scoping configuration when you provision groups to AD DS. Use **Selected Groups** or **All groups** with attribute value scoping. Provision dynamic security groups to AD DS. Cloud security groups are provisioned as Universal groups.
 
When Microsoft Entra Cloud Sync provisions a security group to AD DS, it recognizes when existing domain groups previously had SOA applied and are provisioned from Microsoft Entra ID to AD DS. The security identifier (SID) value correlates them together. Therefore, provisioning the cloud security group to AD DS does so to the original AD group (if it exists). If it doesn’t find a match in AD DS, it creates a new on-premises security group.
 
author: justinha
manager: dougeby
ms.topic: conceptual
ms.date: 08/01/2025
ms.author: justinha
ms.reviewer: dahnyahk
---
 
## Seamless integration with security group provisioning to AD DS
 
To provision a cloud security group that's not mail-enabled back to AD DS and sync it with Microsoft Entra ID, add the group to the scoping configuration when you provision groups to AD DS. Use **Selected Groups** or **All groups** with attribute value scoping. Provision dynamic security groups to AD DS. Cloud security groups are provisioned as Universal groups.
 
When Microsoft Entra Cloud Sync provisions a security group to AD DS, it recognizes when existing domain groups previously had SOA applied and are provisioned from Microsoft Entra ID to AD DS. The security identifier (SID) value correlates them together. Therefore, provisioning the cloud security group to AD DS does so to the original AD group (if it exists). If it doesn’t find a match in AD DS, it creates a new on-premises security group.
 
+2 / -2 lines changed
Commit: spell check
Changes:
Before
After
description: Learn about Source of Authority (SOA), including prerequisites, supported scenarios, and step-by-step guidance for IT Architects and Administrators.
author: Justinha
ms.topic: conceptual
ms.date: 07/30/2025
ms.author: justinha
ms.reviewer: justinha
---
 
## Group SOA scenarios
 
The next sections exaplin more details about the scenarios that Group SOA supports.
 
### Govern access with Microsoft Entra ID Governance
 
description: Learn about Source of Authority (SOA), including prerequisites, supported scenarios, and step-by-step guidance for IT Architects and Administrators.
author: Justinha
ms.topic: conceptual
ms.date: 08/01/2025
ms.author: justinha
ms.reviewer: justinha
---
 
## Group SOA scenarios
 
The next sections explain more details about the scenarios that Group SOA supports.
 
### Govern access with Microsoft Entra ID Governance
 
+2 / -2 lines changed
Commit: spell check
Changes:
Before
After
author: Justinha
manager: dougeby
ms.topic: concept-article
ms.date: 07/31/2025
ms.author: justinha
ms.reviewer: dhanyak
---
 
You can access Audit Logs in the Azure portal. They retain a record of SOA changes for the last 30 days.
 
1. Sign in to the [Azure portal](https://portal.azure.com) as at least a [Reports Reader](/entra/identity/role-based-access-control/permissions-reference#cloud-application-administrator).
 
1. Select **Manage Microsoft Entra ID** > **Monitoring** > **Audit logs** or search for **audit logs** in the search bar.
 
author: Justinha
manager: dougeby
ms.topic: concept-article
ms.date: 08/01/2025
ms.author: justinha
ms.reviewer: dhanyak
---
 
You can access Audit Logs in the Azure portal. They retain a record of SOA changes for the last 30 days.
 
1. Sign in to the [Azure portal](https://portal.azure.com) as at least a [Reports Reader](/entra/identity/role-based-access-control/permissions-reference#reports-reader).
 
1. Select **Manage Microsoft Entra ID** > **Monitoring** > **Audit logs** or search for **audit logs** in the search bar.
 
+2 / -2 lines changed
Commit: spell check
Changes:
Before
After
description: Configure self-service group management in Microsoft Entra for security groups, mail-enabled security groups, and distribution groups after SOA conversion.
author: Justinha
ms.topic: how-to
ms.date: 07/31/2025
ms.author: justinha
manager: dougeby
ms.reviewer: mbhargav
 
### Limitations
- Cloud distribution groups can't be managed by using **My Groups**.
- Self-service management is only possible through Exchange’s end user self-service portal (link).
- Nested distribution groups aren't supported for direct conversion to Microsoft 365 Groups.
 
### Governance integration
description: Configure self-service group management in Microsoft Entra for security groups, mail-enabled security groups, and distribution groups after SOA conversion.
author: Justinha
ms.topic: how-to
ms.date: 08/01/2025
ms.author: justinha
manager: dougeby
ms.reviewer: mbhargav
 
### Limitations
- Cloud distribution groups can't be managed by using **My Groups**.
- Self-service management is only possible through Exchange’s end user self-service portal.
- Nested distribution groups aren't supported for direct conversion to Microsoft 365 Groups.
 
### Governance integration
Modified by Justinha on Aug 1, 2025 4:29 AM
πŸ“– View on learn.microsoft.com
+2 / -2 lines changed
Commit: spell check
Changes:
Before
After
author: omondiatieno
ms.service: entra-id
ms.topic: Include
ms.date: 07/30/2025
ms.author: jomondi
ms.custom: Include file
---
 
- Microsoft Entra account with at least a [Hybrid Identity Administrator](../../role-based-access-control/permissions-reference.md#hybrid-identity-administrator) role.
- On-premises AD DS environment with Windows Server 2016 operating system or later.
- Required for AD DS schema attribute - msDS-ExternalDirectoryObjectId
- Provisioning agent with build version [1.1.3730.0](../cloud-sync/reference-version-history.md#1113730) or later.
 
> [!NOTE]
author: omondiatieno
ms.service: entra-id
ms.topic: Include
ms.date: 08/01/2025
ms.author: jomondi
ms.custom: Include file
---
 
- Microsoft Entra account with at least a [Hybrid Identity Administrator](../../role-based-access-control/permissions-reference.md#hybrid-identity-administrator) role.
- On-premises AD DS environment with Windows Server 2016 operating system or later.
- Required for AD DS schema attribute - msDS-ExternalDirectoryObjectId
- Provisioning agent with build version [1.1.3730.0](../cloud-sync/reference-version-history.md#1113730) or later.
 
> [!NOTE]