The tutorial explains how Microsoft Entra Cloud Sync provisions cloud-managed users, a security group, and group membership to Active Directory Domain Services for access to a Kerberos-based on-premises application. User provisioning is identified as being in preview.
Keep up with Microsoft Entra
Daily AI-generated highlights from Microsoft Learn and Message Center. Browse the archive from 15 April 2025 → About this project →
Cloud-to-AD provisioning guidance separates generally available groups from preview users
Microsoft Entra’s Cloud Sync material now forms an end-to-end guide for provisioning users, groups, and memberships from Entra ID to on-premises AD DS. The new overview labels group provisioning generally available and user provisioning preview; companion guidance covers groups-only, users-only, and users-and-groups scoping, limits, filters, mappings, performance, prerequisites, and on-demand testing. A separate preview procedure preserves a group’s original distinguished name with a GroupDN directory extension when its source of authority changes to Microsoft Entra ID. Elsewhere, Global Secure Access marks four versions deprecated and tells users of version 1.5.612.0 or earlier to update immediately. Cloud Sync guidance also removes the obsolete Repair-AADCloudSyncToolsAccount procedure, while Conditional Access guidance states that Android Authenticator uses Google Play Integrity for jailbreak detection and denies requests when the API is unavailable unless the policy is disabled. Most remaining changes are routine example-ID, link, and reference maintenance.
- Cloud Sync overview sets group GA and user preview boundaries
Entra ID · Fundamentals
The new overview covers provisioning users, groups, and memberships from Microsoft Entra ID to on-premises AD, including supported scenarios, configuration options, synchronization behavior, and limitations. It explicitly states that group provisioning is generally available while user provisioning is in preview.
- Three provisioning scopes are documented with filters and limits
Entra ID · Fundamentals
The preview guidance compares groups-only, users-only, and users-and-groups provisioning through scoping filters. It also records availability, domain and tenant configuration limits, and performance guidance to help administrators choose an appropriate scope and avoid unnecessary processing.
- On-demand testing can validate objects before broad synchronization
Entra ID · Provisioning
The new testing guide covers testing users or groups on demand, reviewing safeguards and notifications, enabling configurations, handling quarantines, restarting synchronization, and removing configurations. A group test can include up to five members.
The preview how-to explains how to create and populate a GroupDN directory extension so a group’s original distinguished name is retained when its source of authority changes to Microsoft Entra ID. The one-time setup includes Universal scope, extension creation, and attribute mapping.
- Global Secure Access version history marks four versions deprecated
Global Secure Access · General
Versions 1.5.612.0, 1.5.402.0, 1.5.132.0, and 1.5.36.0 are marked deprecated. Users of version 1.5.612.0 or earlier are instructed to update immediately.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
41 updates
Microsoft Entra ID
30 updatesPlan Cloud Sync Topologies
Doc updateThe documentation updates diagram descriptions and the provisioning example link. It also clarifies that AD-provisioned group members must have AD accounts, including eligible cloud-managed users and cloud-created security groups; synchronized users still require onPremisesObjectIdentifier.
A new conceptual article describes how Cloud Sync scopes, matches, maps, and writes users, groups, and memberships from Microsoft Entra ID to AD DS, including anchor-based matching and user source-of-authority scenarios.
Microsoft Entra provisioning setup (Preview)
New featureThe article now documents provisioning users and groups from Microsoft Entra ID to on-premises AD DS, including prerequisites, deployment options, scoping filters, attribute mappings, and testing. Users-only and users-and-groups options are marked Preview.
Test Microsoft Entra provisioning (Preview)
New featureA new guide documents testing users or groups on demand, reviewing safeguards and notifications, enabling configurations, handling quarantines, restarting sync, and removing configurations. Group tests can include up to five members.
Adds an article covering prerequisites and license requirements for provisioning users and groups from Microsoft Entra ID to on-premises AD DS with Cloud Sync. It also links to configuration, testing, deployment, and agent-installation guidance.
The article now explains using directory extensions to filter groups for provisioning and to map attribute values to Active Directory users. It adds separate Groups and Users examples, prerequisites, and related guidance.
The guidance now describes testing Entra ID-to-Active Directory changes on a single user or group before enabling them broadly. It adds separate workflows, retains the five-member group limit, and explains result statuses, retries, and testing another object.
The article now covers directory extensions for users and groups when provisioning from Microsoft Entra ID to Active Directory, with updated examples, prerequisite wording, links, and related content.
The documentation removed the Repair-AADCloudSyncToolsAccount section because the cmdlet is obsolete.
On Demand Provision
Doc updateThe article now states that it covers provisioning from Active Directory to Microsoft Entra ID and links to the separate article for provisioning from Microsoft Entra ID to Active Directory.
Tutorial Group Provisioning
Doc updateThe tutorial covering group provisioning to on-premises AD DS, scoping recommendations, and group/user SOA scenarios was deleted.
What If Tool
Doc updateThe Conditional Access What If tool table now uses a different sample UserId in all four examples.
Manage App Consent Policies
Doc updateThe consent policy documentation now lists revised application IDs for Apple Mail, Spark Email, eM Client, Android-Samsung, Android-Mail, and Thunderbird.
Manage App Consent Policies
Doc updateThe consent-policy documentation now lists new application IDs for Apple Mail, Spark Email, eM Client, Android-Samsung, Android-Mail, and Thunderbird.
Grant Admin Consent
Doc updateThe documentation examples now show revised object IDs for Microsoft Graph and other resource APIs while retaining the same consent scenarios and permissions.
Grant Admin Consent
Doc updateThe guide now uses different Microsoft Graph resource API object IDs in delegated- and application-permission consent examples; the documented permissions and consent type remain unchanged.
Preserve a group's organizational unit (Preview)
New featureAction requiredA new how-to explains how to create and populate a GroupDN directory extension so a group's original distinguished name is retained when its Source of Authority changes to Microsoft Entra ID.
Group Source Of Authority Configure
Doc updateThe page now links to guidance on how provisioning from Microsoft Entra ID to Active Directory works and to a tutorial for governing access to an on-premises app.
Sap Netweaver Tutorial
Doc updateTwo SAP Principal Propagation with Azure API Management references in the tutorial now use updated links; the surrounding guidance remains unchanged.
Sap Netweaver Tutorial
Doc updateThe tutorial updates two references to Azure API Management guidance for SAP Principal Propagation, including associated learning links.
A new article compares groups-only, users-only, and users-and-groups provisioning through scoping filters. It also documents availability, domain and tenant configuration limits, and performance guidance.
Provision Microsoft Entra ID objects to AD
New featureA new overview explains how Cloud Sync provisions users, groups, and memberships from Microsoft Entra ID to on-premises AD, including supported scenarios, configuration options, synchronization behavior, and limitations. User provisioning is in preview; group provisioning is generally available.
Group Source Of Authority Guidance
Doc updateThe guidance now links to the Microsoft Entra ID-to-Active Directory provisioning overview and its nested group membership behavior section.
The AzureActiveDirectoryInvalidCredential and AzureActiveDirectoryExpiredCredentials entries no longer reference the cloud service-account repair cmdlet.
The troubleshooting article no longer documents the Repair-AADCloudSyncToolsAccount cmdlet or its usage steps.
The Linux device registration troubleshooting documentation now shows a different tenant ID in its example output.
Assignment Network
Doc updateThe Conditional Access documentation now describes Android Microsoft Authenticator’s use of the Google Play Integrity API for jailbreak detection and the resulting access denial if the API is unavailable.
Assignment Network
Doc updateThe updated Conditional Access documentation states that Microsoft Authenticator on Android uses Google Play Integrity API for jailbreak detection. If the API is unavailable, requests are denied unless the policy is disabled.
Protect M365 From On Premises Attacks
Doc updateThe guidance for controlling access to on-premises applications now links to the updated Microsoft Entra Cloud Sync documentation for provisioning groups to Active Directory.
Microsoft Entra ID Governance
4 updatesThe documentation now consistently uses a different application client ID in the endpoint URI, calling application claim, and `resourceId` examples.
The documentation now uses revised Application (client) ID examples in the endpoint URI and `resourceId` configuration sample.
Road To The Cloud Implement
Doc updateThe guidance now links to a different Microsoft Entra Cloud Sync article for provisioning groups to Active Directory Domain Services.
Source Of Authority Overview
Doc updateThe documentation now describes creating new cloud security groups in Microsoft Entra ID, provisioning them to AD DS as Universal groups, and updating applications to use the new group security identifiers.
Microsoft Entra Workload ID
6 updatesThe PowerShell example now uses a different Subject value for the managed identity federated credential.
The documentation changes the example `-Subject` value in the `New-AzADAppFederatedCredential` command.
How Managed Identities Work Vm
Doc updateThe curl example now uses client_id `00001111-aaaa-2222-bbbb-3333cccc4444` instead of the previous value.
How Managed Identities Work Vm
Doc updateThe VM managed identity documentation changes the client_id value in its curl token-request example.
The documentation updates the name or identifier of the dedicated first-party service principal used to synchronize Active Directory with Microsoft Entra ID.
The documentation wording about the dedicated first-party application and service principal used for synchronization between Active Directory and Microsoft Entra ID was revised.
Version History
RetirementAction requiredThe version history marks versions 1.5.612.0, 1.5.402.0, 1.5.132.0, and 1.5.36.0 as deprecated and instructs users of 1.5.612.0 or earlier to update immediately.
