📋 Microsoft Entra Documentation Changes

Daily summary for changes since August 6th 2025, 8:48 PM PDT

Report generated on August 7th 2025, 8:48 PM PDT

📊 Summary

16
Total Commits
0
New Files
5
Modified Files
0
Deleted Files
6
Contributors

📝 Modified Documentation Files

+27 / -9 lines changed
Commit: fixes from feedback
Changes:
Before
After
 
:::image type="content" source="media/tutorial-group-provision/verify.png" alt-text="Screenshot of the newly provisioned group." lightbox="media/tutorial-group-provision/verify.png":::
 
## Group provision to AD behavior for SOA converted objects
 
When you convert the **Source of Authority (SOA)** to cloud for an on-premises group, that group becomes eligible for group provisioning to AD DS.
 
For example, in the following diagram, **SOATestGroup1** SOA is converted to the cloud.
As a result, it becomes available for the job scope in group provisioning to AD DS.
 
:::image type="content" border="true" source="media/tutorial-group-provision/group-scope.png" alt-text="Screenshot of job in scope." lightbox="media/tutorial-group-provision/group-scope.png":::
 
- When a job runs, the SOA-converted group is provisioned successfully.
 
- In the **Provisioning logs**, you can search for the group name and verify that the group was provisioned.
 
:::image type="content" border="true" source="media/tutorial-group-provision/provisioning-logs.png" alt-text="Screenshot of the Provisioning logs." lightbox="media/tutorial-group-provision/provisioning-logs.png":::
 
- The details show that the group was matched with an existing target group.
 
 
:::image type="content" source="media/tutorial-group-provision/verify.png" alt-text="Screenshot of the newly provisioned group." lightbox="media/tutorial-group-provision/verify.png":::
 
## Group provision to AD DS behavior for SOA converted objects
 
When you convert the Source of Authority (SOA) to cloud for an on-premises group, that group becomes eligible for group provisioning to AD DS.
 
For example, in the following diagram, the SOA or **SOATestGroup1** is converted to the cloud.
As a result, it becomes available for the job scope in group provisioning to AD DS.
 
:::image type="content" border="true" source="media/tutorial-group-provision/group-scope.png" alt-text="Screenshot of job in scope." lightbox="media/tutorial-group-provision/group-scope.png":::
 
- When a job runs, **SOATestGroup1** is provisioned successfully.
 
- In the **Provisioning logs**, you can search for **SOATestGroup1** and verify that the group was provisioned.
 
:::image type="content" border="true" source="media/tutorial-group-provision/provisioning-logs.png" alt-text="Screenshot of the Provisioning logs." lightbox="media/tutorial-group-provision/provisioning-logs.png":::
 
- The details show that **SOATestGroup1** was matched with an existing target group.
 
+1 / -17 lines changed
Commit: fixes from feedback
Changes:
Before
After
 
### Status of attributes after you convert SOA
 
The following table explains the status for **isCloudManaged** and **onPremisesSyncEnabled** attributes you convert the SOA of an object.
 
Admin step | isCloudManaged value | onPremisesSyncEnabled value | Description 
-----|----------------------|----------------------|------------
 
:::image type="content" border="true" source="media/how-to-group-source-of-authority-configure/await-export.png" alt-text="Screenshot of an object awaiting export.":::
 
## Check Cloud sync Provisioning Logs
 
If you try to edit an attribute of a group in AD while **SOA is in the cloud**, the Cloud Sync skips the object.
 
Let's say we have a group *SOAGroup3*, and we update its group name to *SOA Group3.1*.
 
:::image type="content" border="true" source="media/how-to-group-source-of-authority-configure/update-group-name.png" alt-text="Screenshot of an object name update.":::
 
In the **Provisioning Logs** of the **AD2AAD job**, you can see that **SOAGroup3 was skipped**.
 
 
### Status of attributes after you convert SOA
 
The following table explains the status for **isCloudManaged** and **onPremisesSyncEnabled** attributes after you convert the SOA of an object.
 
Admin step | isCloudManaged value | onPremisesSyncEnabled value | Description 
-----|----------------------|----------------------|------------
 
:::image type="content" border="true" source="media/how-to-group-source-of-authority-configure/await-export.png" alt-text="Screenshot of an object awaiting export.":::
 
## Limitations
 
- **No reconciliation support for local AD groups**: An AD DS admin (or an application with sufficient permissions) can directly modify an AD DS group. If Group SOA is converted for the group, or if cloud security group provisioning to AD DS is enabled, those local AD changes aren't reflected in Microsoft Entra ID. When a change to the cloud security group is made, any local AD DS changes are overwritten when group provisioning to AD DS runs.
 
 
 
 
 
 
 
Modified by Diana Richards on Aug 7, 2025 2:27 PM
📖 View on learn.microsoft.com
+7 / -7 lines changed
Commit: fixing alt text
Changes:
Before
After
 
7. On the **Set up Single Sign-On with SAML** page, In the **SAML Signing Certificate** section, select copy button to copy **App Federation Metadata Url**, open it in a new browser tab, download the content of the page as an XML file and save it on your computer.
 
![The Certificate download link](common/copy-metadataurl.png)
 
<a name='create-an-azure-ad-test-user'></a>
 
 
2. Click on the ⚙️ **Cog icon** in the top-right corner and select **Preferences**.
 
<img src="./media/dmarcian-tutorial/preferences.png" alt="The Preferences Menu" width="200" />
 
3. Click on the **SSO** tab.
 
<img src="./media/dmarcian-tutorial/sso-tab.png" alt="The SSO tab" />
 
4. Set the status to **Enabled** if it is not already set and perform the following steps:
 
<img src="./media/dmarcian-tutorial/configuration.png" alt="The Configuration Form" />
 
 
7. On the **Set up Single Sign-On with SAML** page, In the **SAML Signing Certificate** section, select copy button to copy **App Federation Metadata Url**, open it in a new browser tab, download the content of the page as an XML file and save it on your computer.
 
![Screenshot of the Certificate download link.](common/copy-metadataurl.png)
 
<a name='create-an-azure-ad-test-user'></a>
 
 
2. Click on the ⚙️ **Cog icon** in the top-right corner and select **Preferences**.
 
<img src="./media/dmarcian-tutorial/preferences.png" alt="Screenshot of the Preferences Menu." width="200" />
 
3. Click on the **SSO** tab.
 
<img src="./media/dmarcian-tutorial/sso-tab.png" alt="Screenshot of the SSO tab." />
 
4. Set the status to **Enabled** if it is not already set and perform the following steps:
 
<img src="./media/dmarcian-tutorial/configuration.png" alt="Screenshot of the Configuration Form." />
 
+3 / -3 lines changed
Commit: fixes from feedback
Changes:
Before
After
author: justinha
manager: dougeby
ms.topic: conceptual
ms.date: 08/01/2025
ms.author: justinha
ms.reviewer: dahnyahk
---
### How Group Provisioning to AD DS works with nested groups
Let's look at an example where you provision a security group named *CloudGroupB* to AD DS. It has a parent on-premises AD DS group named *OnPremGroupA*. You convert SOA for *CloudGroupB*.
 
Then you start to manage group memberships in Microsoft Entra ID for the converted *CloudGroupB*. You use provision it as a nested group within the on-premises group *OnPremGroupA*. If *OnPremGroupA* remains in-scope for sync, when the AD DS to Microsoft Entra ID sync configuration runs for *OnPremGroupA*, the membership reference for *CloudGroupB* doesn't sync. By design, the sync client doesn't recognize the cloud group membership references.
 
For more information about how group sync works with SOA in similar uses cases, see [Nested Groups and membership references handling](cloud-sync/tutorial-group-provisioning.md#nested-groups-and-membership-references-handling).
 
### How SOA applies to nested groups
 
SOA applies only to the specified direct individual group object without recursion. If you apply SOA to nested groups within the group, they continue to be managed on-premises. Because this methodology is by design, explicitly apply SOA to each group that you want to convert. You might start with the group in the lowest hierarchy, and move up the tree.
 
### Recreate dynamic group configurations from on-premises AD in the cloud
 
author: justinha
manager: dougeby
ms.topic: conceptual
ms.date: 08/07/2025
ms.author: justinha
ms.reviewer: dahnyahk
---
### How Group Provisioning to AD DS works with nested groups
Let's look at an example where you provision a security group named *CloudGroupB* to AD DS. It has a parent on-premises AD DS group named *OnPremGroupA*. You convert SOA for *CloudGroupB*.
 
Then you start to manage group memberships in Microsoft Entra ID for the converted *CloudGroupB*. You provision it as a nested group within the on-premises group *OnPremGroupA*. If *OnPremGroupA* remains in-scope for sync, when the AD DS to Microsoft Entra ID sync configuration runs for *OnPremGroupA*, the membership reference for *CloudGroupB* doesn't sync. By design, the sync client doesn't recognize the cloud group membership references.
 
For more information about how group sync works with SOA in similar uses cases, see [Nested Groups and membership references handling](cloud-sync/tutorial-group-provisioning.md#nested-groups-and-membership-references-handling).
 
### How SOA applies to nested groups
 
SOA applies only to the specified direct individual group object without recursion. If you apply SOA to nested groups within the group, they continue to be managed on-premises. Because this methodology is by design, explicitly apply SOA to each group that you want to convert. If you want to convert nested groups, you might start with the group in the lowest hierarchy, and move up the tree.
 
### Recreate dynamic group configurations from on-premises AD in the cloud
 
Modified by Diana Richards on Aug 7, 2025 2:13 PM
📖 View on learn.microsoft.com
+1 / -1 lines changed
Commit: fixing formatting to clear the build warning
Changes:
Before
After
 
a. In the **Identifier (Entity ID)** text box, type a unique identifier for your Sage Intacct company, with the following format:
 
`https://saml.intacct.com`.
 
b. In the **Reply URL** text box, add the following URLs:
 
 
a. In the **Identifier (Entity ID)** text box, type a unique identifier for your Sage Intacct company, with the following format:
 
`https://saml.intacct.com`.
 
b. In the **Reply URL** text box, add the following URLs: