Microsoft Entra ID Governance
Governance

Entitlement Management Access Package Auto Assignment Policy

In brief

The documentation now states that support for the `memberOf` rule operator ends November 3, 2026, replacing October 27, 2026. Policies using it will be quarantined and stop processing assignments from that date.

What Entra admins need to know

Find affected automatic assignment policies and rebuild their rules or plan an alternative assignment method before the updated end date.

This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

author: markwahl-msft ms.subservice: entitlement-management ms.topic: how-to ms.date: 07/28/08/05/2026 ms.reviewer: mwahl ai-usage: ai-assisted #Customer Intent: As an IT admin, I want to configure automatic assignment policies for an access package so that I can automatically assign access based on rules.

It is suggested to only use one automatic assignment policy per access package. Configuring more than one auto-assignment policy is supported ONLY if you ensure there is no overlap with users in scope for each policy. If a user matches more than one automatic assignment policy, this is not supported and there may be subsequent problems losing access should a user fall out of scope of one policy but not the other.

This article describes how to create an access package automatic assignment policy for an existing access package.

Find automatic assignment policies that use the memberOf attribute

Because support for the memberOf rule operator ends on October 27,November 3, 2026, you need to find the automatic assignment policies in your tenant whose membership rule includes memberOf, so that you can rebuild those rules or plan an alternative assignment method.

You can find those policies in PowerShell with the Microsoft Graph PowerShell Microsoft.Graph.Authentication module. An identity in an appropriate role with the delegated EntitlementManagement.Read.All permission can run the following script. The script is read only, so it doesn't change any policy.

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…