Microsoft Entra ID
Fundamentals

Group Source Of Authority Guidance

In brief

The guidance now links to the Microsoft Entra ID-to-Active Directory provisioning overview and its nested group membership behavior section.

What Entra admins need to know

Administrators can use the updated links for current information about group synchronization and nested group membership.

This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

  1. Convert the Source of Authority (SOA) when ready.
  2. Use custom expressions to ensure Cloud Sync provisions groups back to AD DS with the same CN and OU values.

For more information, see Provision groups to Active Directory Domain Services by using Microsoft Entra Cloud SyncHow provisioning from Microsoft Entra ID to Active Directory works.

Transition group management

Then you start to manage group memberships in Microsoft Entra ID for the converted CloudGroupB. You provision it as a nested group within the on-premises group OnPremGroupA. If OnPremGroupA remains in-scope for sync, when the AD DS to Microsoft Entra ID sync configuration runs for OnPremGroupA, the membership reference for CloudGroupB doesn't sync. By design, the sync client doesn't recognize the cloud group membership references.

For more information about how group sync works with SOA in similar use cases, see Nested Groups and membership references handlingNested group membership behavior.

How SOA applies to nested groups

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…