Microsoft Entra ID
Architecture

Protect M365 From On Premises Attacks

In brief

The guidance for controlling access to on-premises applications now links to the updated Microsoft Entra Cloud Sync documentation for provisioning groups to Active Directory.

What Entra admins need to know

Administrators following this guidance will be directed to the current setup documentation; no configuration changes are indicated.

This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Cloud groups allow you to decouple your collaboration and access from your on-premises infrastructure.

Consider owners of groups used for access as privileged identities to avoid membership takeover in an on-premises compromise. Takeovers include direct on-premises group membership manipulation or on-premises attribute manipulation that can affect Microsoft 365 dynamic group membership.

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…