← Previous day

Keep up with Microsoft Entra

Daily AI-generated highlights from Microsoft Learn and Message Center. Browse the archive from 15 April 2025 → About this project →

Day in brief

Cloud-to-AD provisioning guidance separates generally available groups from preview users

Microsoft Entra’s Cloud Sync material now forms an end-to-end guide for provisioning users, groups, and memberships from Entra ID to on-premises AD DS. The new overview labels group provisioning generally available and user provisioning preview; companion guidance covers groups-only, users-only, and users-and-groups scoping, limits, filters, mappings, performance, prerequisites, and on-demand testing. A separate preview procedure preserves a group’s original distinguished name with a GroupDN directory extension when its source of authority changes to Microsoft Entra ID. Elsewhere, Global Secure Access marks four versions deprecated and tells users of version 1.5.612.0 or earlier to update immediately. Cloud Sync guidance also removes the obsolete Repair-AADCloudSyncToolsAccount procedure, while Conditional Access guidance states that Android Authenticator uses Google Play Integrity for jailbreak detection and denies requests when the API is unavailable unless the policy is disabled. Most remaining changes are routine example-ID, link, and reference maintenance.

  • The new overview covers provisioning users, groups, and memberships from Microsoft Entra ID to on-premises AD, including supported scenarios, configuration options, synchronization behavior, and limitations. It explicitly states that group provisioning is generally available while user provisioning is in preview.

  • The preview guidance compares groups-only, users-only, and users-and-groups provisioning through scoping filters. It also records availability, domain and tenant configuration limits, and performance guidance to help administrators choose an appropriate scope and avoid unnecessary processing.

  • The new testing guide covers testing users or groups on demand, reviewing safeguards and notifications, enabling configurations, handling quarantines, restarting synchronization, and removing configurations. A group test can include up to five members.

  • The preview how-to explains how to create and populate a GroupDN directory extension so a group’s original distinguished name is retained when its source of authority changes to Microsoft Entra ID. The one-time setup includes Universal scope, extension creation, and attribute mapping.

  • Versions 1.5.612.0, 1.5.402.0, 1.5.132.0, and 1.5.36.0 are marked deprecated. Users of version 1.5.612.0 or earlier are instructed to update immediately.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

41 updates

12

Tutorial: Govern access to an on-premises app (Preview)

New feature

The tutorial explains how Microsoft Entra Cloud Sync provisions cloud-managed users, a security group, and group membership to Active Directory Domain Services for access to a Kerberos-based on-premises application. User provisioning is identified as being in preview.

Plan Cloud Sync Topologies

Doc update

The documentation updates diagram descriptions and the provisioning example link. It also clarifies that AD-provisioned group members must have AD accounts, including eligible cloud-managed users and cloud-created security groups; synchronized users still require onPremisesObjectIdentifier.

Microsoft Entra provisioning behavior (Preview)

Doc update

A new conceptual article describes how Cloud Sync scopes, matches, maps, and writes users, groups, and memberships from Microsoft Entra ID to AD DS, including anchor-based matching and user source-of-authority scenarios.

Microsoft Entra provisioning setup (Preview)

New feature

The article now documents provisioning users and groups from Microsoft Entra ID to on-premises AD DS, including prerequisites, deployment options, scoping filters, attribute mappings, and testing. Users-only and users-and-groups options are marked Preview.

Test Microsoft Entra provisioning (Preview)

New feature

A new guide documents testing users or groups on demand, reviewing safeguards and notifications, enabling configurations, handling quarantines, restarting sync, and removing configurations. Group tests can include up to five members.

Microsoft Entra prerequisites for AD (Preview)

Doc update

Adds an article covering prerequisites and license requirements for provisioning users and groups from Microsoft Entra ID to on-premises AD DS with Cloud Sync. It also links to configuration, testing, deployment, and agent-installation guidance.

On-demand provisioning - Microsoft Entra ID to Active Directory

Feature update

The guidance now describes testing Entra ID-to-Active Directory changes on a single user or group before enabling them broadly. It adds separate workflows, retains the five-member group limit, and explains result statuses, retries, and testing another object.

On Demand Provision

Doc update

The article now states that it covers provisioning from Active Directory to Microsoft Entra ID and links to the separate article for provisioning from Microsoft Entra ID to Active Directory.

Tutorial Group Provisioning

Doc update

The tutorial covering group provisioning to on-premises AD DS, scoping recommendations, and group/user SOA scenarios was deleted.

5

What If Tool

Doc update

The Conditional Access What If tool table now uses a different sample UserId in all four examples.

Manage App Consent Policies

Doc update

The consent policy documentation now lists revised application IDs for Apple Mail, Spark Email, eM Client, Android-Samsung, Android-Mail, and Thunderbird.

Manage App Consent Policies

Doc update

The consent-policy documentation now lists new application IDs for Apple Mail, Spark Email, eM Client, Android-Samsung, Android-Mail, and Thunderbird.

Grant Admin Consent

Doc update

The documentation examples now show revised object IDs for Microsoft Graph and other resource APIs while retaining the same consent scenarios and permissions.

Grant Admin Consent

Doc update

The guide now uses different Microsoft Graph resource API object IDs in delegated- and application-permission consent examples; the documented permissions and consent type remain unchanged.

4

Preserve a group's organizational unit (Preview)

New featureAction required

A new how-to explains how to create and populate a GroupDN directory extension so a group's original distinguished name is retained when its Source of Authority changes to Microsoft Entra ID.

Group Source Of Authority Configure

Doc update

The page now links to guidance on how provisioning from Microsoft Entra ID to Active Directory works and to a tutorial for governing access to an on-premises app.

Sap Netweaver Tutorial

Doc update

Two SAP Principal Propagation with Azure API Management references in the tutorial now use updated links; the surrounding guidance remains unchanged.

Sap Netweaver Tutorial

Doc update

The tutorial updates two references to Azure API Management guidance for SAP Principal Propagation, including associated learning links.

3

Microsoft Entra provisioning options (Preview)

Doc update

A new article compares groups-only, users-only, and users-and-groups provisioning through scoping filters. It also documents availability, domain and tenant configuration limits, and performance guidance.

Provision Microsoft Entra ID objects to AD

New feature

A new overview explains how Cloud Sync provisions users, groups, and memberships from Microsoft Entra ID to on-premises AD, including supported scenarios, configuration options, synchronization behavior, and limitations. User provisioning is in preview; group provisioning is generally available.

Group Source Of Authority Guidance

Doc update

The guidance now links to the Microsoft Entra ID-to-Active Directory provisioning overview and its nested group membership behavior section.

3
2

Assignment Network

Doc update

The Conditional Access documentation now describes Android Microsoft Authenticator’s use of the Google Play Integrity API for jailbreak detection and the resulting access denial if the API is unavailable.

Assignment Network

Doc update

The updated Conditional Access documentation states that Microsoft Authenticator on Android uses Google Play Integrity API for jailbreak detection. If the API is unavailable, requests are denied unless the policy is disabled.

1

Protect M365 From On Premises Attacks

Doc update

The guidance for controlling access to on-premises applications now links to the updated Microsoft Entra Cloud Sync documentation for provisioning groups to Active Directory.

2
1

Road To The Cloud Implement

Doc update

The guidance now links to a different Microsoft Entra Cloud Sync article for provisioning groups to Active Directory Domain Services.

1

Source Of Authority Overview

Doc update

The documentation now describes creating new cloud security groups in Microsoft Entra ID, provisioning them to AD DS as Universal groups, and updating applications to use the new group security identifiers.

2
2
2
1

Version History

RetirementAction required

The version history marks versions 1.5.612.0, 1.5.402.0, 1.5.132.0, and 1.5.36.0 as deprecated and instructs users of 1.5.612.0 or earlier to update immediately.

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…